FSS_II_Draft_Exhibit_B_Data_Item_Descriptions.pdf
PDF 1 MB Posted
- Attached to
- Facility Support Services Federal contract opportunity
- Solicitation number
- FA9101-18-R-1000
View the file
Other files for this federal contract opportunity
Show all 50
Facility Support Services has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Exhibit B
Data Item Descriptions
DRAFT
DATA ITEM DESCRIPTION
Title: SPECIAL ACCESS PROGRAM (SAP) ACCREDITED AREA STANDARD OPERATING
PROCEDURE (SOP)
Number: OT-2018- Approval Date: 2018MMDD
AMSC Number: N/A Limitation: FA9101-18-R-1000
DTIC Applicable: No GIDEP Applicable: No
Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A
Applicable Forms: N/A
Use/relationship: A written security SOP, prepared for the AEDC Government Special Access Program Security Officer (GSSO), provides instructions for proper protection, use, and dissemination of classified material by enforcing information, personnel, physical, communications, industrial, and IA security standards identified in the reference documents. The SAP Accredited Area SOP is a living document that will require periodic updates throughout the life of the accredited area.
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).
Requirements:
1. Reference Documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2. Format. The SAP Accredited Area SOP shall be prepared in electronic format and available to authorized users via electronic and hardcopy forms. The format shall comply with reference documents.
3. Content. The SAP Accredited Area SOP content shall comply with all reference documents.
End of OT-2018-
DISTRIBUTION STATEMENT A. Approved for public release. Distribution is unlimited.
Title: SPECIAL ACCESS PROGRAM (SAP) CERTIFICATION AND ACCREDITATION
PACKAGE
Number: OT-2018- Approval Date: 2018MMDD
AMSC Number: N/A Limitation: FA9101-18-R-1000
DTIC Applicable: No GIDEP Applicable: No
Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A
Applicable Forms: N/A
Use/relationship: An accreditation package, prepared for the AEDC Government Special Security Officer (GSSO), includes physical security and TEMPEST documentation for the establishment and accreditation of the accredited area. The accreditation package includes information to ensure the facility meets prescribed physical, technical, and personnel security standards identified in the reference documents. The accreditation package is a living document that will require periodic updates throughout the life of the accredited area.
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).
Requirements:
1. Reference Documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2. Format. The accreditation package shall be prepared in electronic form and available to authorized users via electronic and hardcopy forms. The format shall comply with reference documents.
3. Content. The accreditation content shall comply with all reference documents.
End of OT-2018-
Title: JOINT SPECIAL ACCESS PROGRAM IMPLEMENTATION GUIDE (JSIG) SYSTEM
AUTHORIZATION PACKAGE (SAP)
Number: DI-ADMN-81969 Approved Date: 20140807 AMSC Number: F9488 Limitation: N/A DTIC Applicable: No GIDEP Applicable: No Office of Primary Responsibility: 20 (AFRL/RYS) Applicable Forms: N/A Use/Relationship: The JSIG SAP is used to identify, control, and authorize a contractor’s proposed stand-alone computer systems and/or networks created and used during the performance of this contract. The contract Information System Security Officer (ISSO) or Information System Security Manager (ISSM) must submit the SAP documentation for a proposed system or network to the Authorizing Official (AO), Delegated Authorizing Official (DAO), or the Program Security Officer (PSO). The AO, DAO, or the PSO must provide written approval of any new information system or network before processing can begin.
a. The SAP describes the methods to: (1) identify systems, security responsibilities and requirements; (2) define overall security standard practice guidance and procedures; (3) identify potential problem areas and determine solutions; and (4) develop security awareness inputs into the overall system security process.
b. This Data Item Description (DID) defines the data required to obtain information systems authorization in accordance with the JSIG. A copy of the JSIG can be obtained from the government program office.
c. This DID contains the format and content preparation instructions for the data product generated by the specific and discrete task requirements delineated in the contract.
Requirements:
1. Reference documents: The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as cited in the ASSIST at the time of the solicitation or contract.
a. Department of Defense (DoD) JSIG
b. DoD JSIG Template Handbook.
c. Government Program Office Guidance.
(Copies of these documents are available from the Government Agency awarding the contract.)
2. Format: The JSIG SAP Documentation shall be presented in Microsoft Word formats outlined by the DoD JSIG, DoD JSIG Template Handbook and the Government Information Assurance Officer (IAO). The initially used format arrangement shall be used for all subsequent submissions.
3. Content: A JSIG system/network authorization package typically consists of:
a. Authorization Package Cover Letter.
DISTRIBUTION STATEMENT A. Approved for public release; distribution is unlimited.
Source: https://assist.dla.mil -- Downloaded: 2018-04-23T16:54Z
Check the source to verify that this is the current version before use.
DI-ADMN-81969
b. Authorization to Operate (ATO) Letter.
c. Security Assessment Report (SAR).
d. Risk Assessment Report (RAR).
e. System Security Plan (SSP).
f. Security Control Traceability Matrix (SCTM).
g. Plan of Action and Milestones (POA&M).
h. ISSO/ISSM Appointment Letter.
i. ISSO/ISSM 8570 Certification (per DoD 8570.01-M, Information Assurance Workforce Improvement Program).
(Copies of this document are available online at http://www.dtic.mil/whs/directives/index.html.)
j. General User’s Guide (GUG).
k. Privileged User’s Guide (PUG).
l. Software List.
m. Software Approval Forms for High-Risk.
n. Hardware List.
o. Any other supporting documentation required via above documentation (facility accreditation, etc.)
3.1. An SSP will be developed and maintained for each proposed stand-alone system or network.
3.2. If an approved Interagency Standing Operating Procedure (IASOP) exists for previously authorized systems/networks, and will apply to the proposed system/network, submit a copy of the IASOP in addition to the items a through o, above.
3.3. The SAP documentation will be revised when any modifications are made to any portion of the system, network, personnel, or documentation.
3.4. Classification of documentation will be applied in accordance with security classification guides or classification tables. “Distribution Statement F. Further dissemination only as directed by (inserting controlling DoD office) (date of determination) or higher DoD authority.”
applies to this package.
4. End of DI-ADMN-81969.
Source: https://assist.dla.mil -- Downloaded: 2018-04-23T16:54Z
Check the source to verify that this is the current version before use.
http://www.dtic.mil/whs/directives/index.html
Title: DOD Information Assurance Certification and Accreditation Process (DIACAP) and
Risk Management Framework (RMF) Deliverable Data
Number: DI-MGMT-82000 Approval Date: 20151014
AMSC Number: 9594 Limitation:
DTIC Applicable: GIDEP Applicable:
Office of Primary Responsibility: AS Project Number: MGMT-2015-021
Applicable Forms:
Use/relationship: The DIACAP and RMF Deliverable Data will be used to satisfy the requirements of the DIACAP and/or RMF process.
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described by the contract.
Requirements:
1. Format. The DIACAP and/or RMF artifacts shall be delivered in a format approved by the
Government’s Designated Accrediting Authority (DAA), Authorizing Official (AO), or Information
Systems Security Manager (ISSM).
2. Content. The content of the DIACAP and/or RMF artifacts shall contain the necessary artifacts required by the DAA, AO, or ISSM to successfully achieve Platform IT Risk Approval (PRA), Interim Authority to Test (IATT), Interim Authority to Operate (IATO), or Authority to Operate
(ATO).
2.1 Introduction. This section shall contain a narrative of the DIACAP/RMF package content.
2.1.1 IATT Request. The IATT Request shall use the approved DAA, AO, or ISSM format. The
IATT Request shall identify the ‘who’, ‘what’, ‘why’, ‘where’, ‘when’, and ‘how’ of the requested
Test event. IATT Request shall be delivered not less than 30 days prior to the start of the Test
Event.
2.1.2 Certification and Accreditation (C&A) or Security Plan. The C&A or Security Plan shall use the approved DAA, AO, or ISSM format. The C&A Plan shall contain at a minimum, System
Information, Mission Description, Concept of Operations (CONOPS), Environment, Operating and
Computing Environment, Physical Security Measures, Facilities Descriptions, Threat Analysis, System Architecture Description, Components, Configurations, Accreditation Boundaries, Connection Process Guide (CPG) Compliant Network Diagrams, External Interfaces and Data Flow, Internal Data Flow, Contingency Plan, Incident Response Plan, User Descriptions and Clearances, Security Roles, Hardware Lists, Software Lists, Ports, Protocols, and Services (PPS), Configuration
Management Plan, Information Assurance Vulnerability Management (IAVM) Plan, and C&A Tasks and Milestones. The C&A Plan shall be approved and signed by the ISSM, User Rep, Program
Manager (PM), and DAA or AO.
Source: https://assist.dla.mil -- Downloaded: 2018-04-23T17:18Z
DI-MGMT-82000
2.1.3 C&A Project Plan. The C&A Project Plan shall use the approved DAA, AO, or ISSM format.
The C&A Project Plan shall be approved and signed by the ISSM, Echelon II Representative, and
PM. The C&A Project Plan shall define the various C&A Tasks and Milestones needed to achieve
PRA, IATT, IATO, or ATO.
2.1.4 Collaboration Brief. The Collaboration Brief shall use the approved DAA, AO, or ISSM format. The Collaboration Brief is submitted with the DIACAP/RMF package and is used to describe the System and System Risk during the Collaboration meeting.
2.1.5 DIACAP Implementation Plan (DIP). The DIP shall use the approved DAA, AO, or ISSM format. The DIP shall be used during the DIP Concurrence meeting with the Echelon II, Navy CA, and ODAA. The DIP shall define which IA Controls (IACs) will be ‘Implemented’, ‘Inherited’, ‘Non-Compliant’, or ‘Not Applicable’. The DIP shall be approved by the DAA, AO, and ISSM prior to execution of the IA Test Plan.
2.1.6 PIT Implementation Plan (PIP). The PIP shall use the approved DAA, AO, or ISSM format.
The PIP shall be used during the PIT Concurrence meeting with the Echelon II, Navy CA, and
ODAA. The PIP shall define which IACs will be ‘Implemented’, ‘Inherited’, ‘Non-Compliant’, or
‘Not Applicable’. The PIP shall be approved by the DAA, AO, and ISSM prior to execution of the
IA Test Plan.
2.1.7 IA Test Plan. The IA Test Plan shall use the approved DAA, AO, or ISSM format. The IA
Test Plan shall define all required Vulnerability Scans, Security Technical Implementation Guides
(STIGs), Security Readiness Guides (SRGs), Secure Content Automation Protocol (SCAP) benchmarks, and IA Controls or Security Overlays to be applied to the System. The IA Test Plan shall be approved by the DAA, AO, and ISSM during the DIP or PIP Concurrence Meeting.
2.1.8 PIT Designation Request. The PIT Designation Request shall use the approved DAA, AO, or
ISSM format. The PIT Designation Request is the formal request to the DAA or AO that the System shall be designated as Platform IT (versus an Information System (IS)). The PIT Designation
Request shall be approved and a PIT Designation Letter shall be signed by the DAA or AO prior to the execution of the IA Test Plan.
2.1.9 PIT Determination Brief. The PIT Determination Brief shall use the approved DAA, AO, or
ISSM format. The PIT Determination Brief shall be used in conjunction with the PIT Designation
Request to formally request the System be designated Platform IT (versus and Information System).
2.1.10 Plan of Action and Milestones (POA&M). The POA&M shall use the approved DAA, AO, or ISSM format. The POA&M shall be considered a ‘living’ document and shall regularly be updated throughout the entire lifecycle of the System through Decommission. The POA&M shall contain all Not Applicable IA Controls, All Non-Compliant IA Controls, and all Non-Compliant
Vulnerability Findings as identified in the Vulnerability Scans, STIGs, SRGs, and SCAP
Benchmarks. At a minimum, the POA&M shall be updated monthly.
2.1.11 Privacy Impact Assessment (PIA). The PIA shall use the approved DAA, AO, or ISSM format. The PIA shall be approved and signed by the ISSM, PM, and the Command PIA Officer.
2.1.12 Vulnerability Scans. In accordance with the approved IA Test Plan, the System shall be scanned using the approved vulnerability scanning tools as identified by the DAA, AO, or ISSM.
Source: https://assist.dla.mil -- Downloaded: 2018-04-23T17:18Z
DI-MGMT-82000
The vulnerability scanner shall be updated with the latest signatures and scanning engines prior to the execution of each vulnerability scan. At a minimum, vulnerability scans shall be conducted monthly against the System. Non-compliant findings shall be documented in the System POA&M on a minimum monthly basis. At a minimum, vulnerability scans shall be submitted electronically to the
ISSM or uploaded into the DIACAP/RMF package. Vulnerability scans shall be handled in accordance with the System’s classification level. Vulnerability reports shall be in a format approved by the DAA, AO, or ISSM.
2.1.13 STIGs, SRGs, SCAP Benchmarks. In accordance with the approved IA Test Plan, the
System shall be hardened using the required and approved STIGs, SRGs, and SCAP Benchmarks.
Non-compliant STIG, SRG, and SCAP Benchmark findings shall be documented in the System
POA&M on a minimum monthly basis. Updates to the STIGs, SRGs, and SCAP Benchmarks are released on a monthly, quarterly, and yearly basis. Updates to the STIGs, SRGs, and SCAP
Benchmarks shall be implemented into the System as they are released. Non-compliant STIG, SRG, and SCAP Benchmark findings shall be documented in the System POA&M on a minimum monthly basis. STIG, SRG, and SCAP Benchmark artifacts shall be provided in a format approved by the
DAA, AO, or ISSM. STIG, SRG, and SCAP Benchmark artifacts shall be handled in accordance with the System’s classification level. At a minimum, STIG, SRG, and SCAP Benchmarks shall be submitted electronically to the ISSM or uploaded into the DIACAP/RMF Package on a minimum monthly basis.
2.1.14 Scorecard. The Scorecard shall use the approved DAA, AO, or ISSM format. The
Scorecard shall be maintained and updated on a minimum monthly basis.
2.1.15 Contingency Plan. The Contingency Plan shall use the approved DAA, AO, or ISSM format.
The Contingency Plan shall be submitted in conjunction with the System’s C&A Plan. The
Contingency Plan shall be approved and signed by the PM, ISSM, and DAA or AO.
2.1.16 IAVM Plan. The IAVM Plan shall use the approved DAA, AO, or ISSM format. The IAVM
Plan shall be submitted in conjunction with the System’s C&A Plan. The IAVM Plan shall be approved and signed by the PM, ISSM, and DAA or AO.
2.1.17 Cyber Security Waivers. Cyber Security Waivers shall use the approved DAA, AO, or ISSM format. All Cyber Security Waivers shall be approved and signed by the ISSM, PM, and First Flag or Equivalent prior to submission to the DAA or AO.
END OF: DI-MGMT-82000
Source: https://assist.dla.mil -- Downloaded: 2018-04-23T17:18Z
Title: TEST SECURITY PLAN FOR COLLATERAL, SAP, CLASSIFIED AND COMMERCIAL
TEST
Number: OT-2018- Approval Date: 2018MMDD
AMSC Number: N/A Limitation: FA9101-18-R-1000
DTIC Applicable: No GIDEP Applicable: No
Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A
Applicable Forms: N/A
Use/relationship: Test security plans will be prepared for all commercial, unclassified, and collateral classified research, development, test and evaluation (RDT&E) test programs conducted at Arnold Engineering Development Complex (AEDC). This plan will be used by all associated test team members and identifies all security requirements related to specific test efforts. The test security plan provides all employees supporting a test with test-specific security guidance and procedures. If necessary, it also contains a Foreign National Visitor Control Plan as an annex.
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for AEDC solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).
Requirements:
1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2. Format. The test security plan shall be prepared in electronic form and available to authorized users via electronic and hardcopy forms. The format shall comply with reference documents.
3. Content. As a minimum, the plan shall:
a. Identify the test program and provide an overview of the test
b. Identify the customer/sponsor and test facility
c. Identify classification, specific local or customer guidance, related Security Classification Guides, and any Technical Assistance Agreements, Technology Control Plans
d. Identify Baseline Protection Requirements for Data and the test areas (Physical Space)
e. Identify the Risk Assessment Authorization (RAA), if required:
i. Identify any foreign national involvement and subsequent visitor control procedures
ii. Identify any CUI and specific guidance
iii. Identify any OPSEC concerns and provides and specific measures and/or guidance
iv. Identify any Critical Program Information (CPI) and specific Program Protection Plan requirements or guidance
Title: OPERATIONS SECURITY (OPSEC) PLAN
Number: DI-MGMT-80934C Approval Date: 20101213 AMSC Number: 9178 Limitation: N/A DTIC Applicable: No GIDEP Applicable: No Office of Primary Responsibility: NS/I925 Applicable forms: N/A
Use/Relationship: The OPSEC Plan is used to identify and monitor a contractor’s OPSEC activities during the performance of a contract. It is intended to be a living document that will require periodic updates throughout the life of the contract. The OPSEC plan; (1) Describes the OPSEC environment to include identification of critical information, the OPSEC threat and vulnerabilities an adversary might exploit to acquire critical information, (2) Documents the OPSEC risk analysis, (3) Identifies proposed and actual OPSEC measures, (4) Defines and assigns specific OPSEC responsibilities and ties the OPSEC Plan to the contractor’s corporate OPSEC Program, and (5) Serves as a repository of the OPSEC history of the contract.
a. This Data Item Description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirements delineated in the contract.
b. This DID is applicable only when the contracting activity determines that the sensitivity of the contracted effort warrants OPSEC protections.
c. The contractor’s implementation of the OPSEC Plan, approved by the contracting activity, is subject to joint audit and/or inspection by the Defense Security Service and the contracting activity.
d. This DID supersedes DI-MGMT 80934B.
Requirements:
1. Reference documents: The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices and revisions, shall be as specified in the contract.
a. “Applying OPSEC to U.S. Government Acquisitions and Contracts”. This document is available from the Interagency OPSEC Support Staff (IOSS) at the following web address:
www.ioss.gov.
b. Department of Defense Manual (DODM) 5205.02M, DOD Operations Security (OPSEC) Program Manual, dated November 3, 2008.
Source: https://assist.dla.mil -- Downloaded: 2014-07-02T18:58Z http://www.ioss.gov/
DI-MGMT-80934C
c. Department of Defense Contract Security Classification Specification (DD 254). This document is included as a part of all Request for Proposals (RFP) and Contracts involving classified data.
d. Contract Data Requirements List (CDRL). This document is included as a part of all RFP and contracts containing data deliverable requirements.
e. National Industrial Security Program Operating Manual (NISPOM) 5220.22M, dated February 28. 2006.
2. Format: The OPSEC Plans shall be submitted in contractor determined format and, at a minimum, consist of the following sections listed in the Content Section below.
3. Content:
3.1 COVER PAGE
The cover page for an OPSEC Plan shall clearly present, at a minimum, the following information:
1. Title of the Acquisition Program
2. Title of the Document (i.e. “Operations Security Plan”)
3. Reference to the government contract number
4. Date of latest revision
5. Name, signature and title of the preparer of the OPSEC Plan
6. Name, signature and title of the approver of the OPSEC Plan.
7. Reference for whom the document was prepared (Contracting activity)
8. Reference by whom the document was prepared (Corporation)
9. All appropriate distribution or classification statements
3.2 TABLE OF CONTENTS PAGE
The Table of Contents for an OPSEC Plan shall outline each section contained in the OPSEC Plan.
3.3 PREFACE PAGE
The purpose of the Preface is to provide a brief, unclassified, overview of the program and the need for OPSEC measures. The specific objectives of the contracted effort shall be introduced with reference to all strategic participants and partnerships required to make the program a success. The anticipated development of any innovative concepts or technologies shall also be introduced in the Preface.
The Preface shall reference all links between the OPSEC Plan and any corporate OPSEC Program(s). The Preface may conclude by referencing requirement documents such as the contract number, Contract Security Classification Specification (DD254), Contract Data
Source: https://assist.dla.mil -- Downloaded: 2014-07-02T18:58Z
Requirements List (DD1423) and any other pertinent guidance provided by the contracting activity. It shall also provide an OPSEC point of contact, with contact information, for additional guidance or assistance such as the OPSEC program manager or contractor program manager.
3.4 OPSEC PLAN INTRODUCTION
3.4.1 Purpose and Scope: The purpose of the OPSEC Plan shall be effectively communicated in this section and include a description of the scope of the OPSEC Plan (unique physical locations, subcontractors, suppliers, period of performance, etc.).
3.4.2 Authorities: The requirement to protect critical information shall be documented within this section. Documenting the requirement can be achieved by referencing the Corporate OPSEC Program (Policy) and Plan, DODM 5205.-2M, specific contract documents including the DD254 for contracts involving classified data, or other contracting activity specific guidance.
3.4.3 OPSEC Plan Major Activity Timeline: This section shall include a list of all major OPSEC Plan activities such as quarterly OPSEC Working Group Meetings, Annual Assessments, scheduled OPSEC awareness training, Sub-contractor OPSEC Assessments and Surveys, Threat and Vulnerability Reviews, etc. This section shall also include scheduled OPSEC Plan reviews.
3.4.4 Responsibilities: The OPSEC Plan shall identify whom is responsible for the major activities described in the Plan. For example (not intended as an inclusive list):
The OPSEC Manager shall be identified by name and include a list of duties that may include:
1. Coordinate all OPSEC policy responsibilities/ procedures within the program.
2. Revise the Program OPSEC Plan as necessary.
3. Convene and coordinate the annual Program OPSEC Assessment.
4. Disseminate updated threat information to program personnel.
5. Assist in the review of contract requirements for OPSEC considerations.
6. Conduct OPSEC briefing(s) upon customer approval of the plan.
7. Principal advisor to the Contractor Program Manager on all OPSEC matters.
8. Develop/Disseminate Program Critical Information List (CIL).
9. Promote OPSEC awareness within the program.
The Contractor Program Manager shall be identified by name and include a list of duties that may include:
1. Responsible for the overall implementation of the program/contract.
2. Ensure proper OPSEC procedures are implemented by program personnel.
3. Ensure all subcontractors and suppliers supporting the program develop and implement procedures in compliance with the Program OPSEC Plan.
Source: https://assist.dla.mil -- Downloaded: 2014-07-02T18:58Z
4. Remain cognizant of emerging OPSEC threats and vulnerabilities that may adversely impact upon the success of the program.
5. Actively participate in periodic Program OPSEC assessments.
6. Remain cognizant of any changes in critical information and communicate them to the Program OPSEC Manager.
7. Promote OPSEC awareness within the program.
A short description of the expectations and responsibilities of all program personnel (including subcontractors and suppliers) shall be provided and may typically include:
1. Remain compliant with all applicable OPSEC Plans.
2. Maintain an awareness of all applicable CIL.
3. Attend all OPSEC program briefings.
4. Timely reporting of any OPSEC concerns to the Contractor Program Manager and/or the Program OPSEC Manager.
5. Generation of OPSEC Plans (sub-contractors or suppliers only).
3.4.5 Organizational OPSEC Communications and Interfaces: A description as to how the OPSEC Plan will be communicated to all personnel supporting the program (hardcopy, via a webpage, briefings, etc.).
3.4.5.1 Internal: In this section the OPSEC Plan shall identify all anticipated OPSEC interfaces internal to the corporation such as the senior corporate leadership, corporate OPSEC Working Group, OPSEC coordinators, program personnel, etc.
3.4.5.2 External: In this section the OPSEC Plan shall identify all anticipated external points of contact such as the contracting activity, Defense Contract Management Agency (DCMA), The Defense Security Service (DSS), Federal Bureau of Investigation (FBI) and local law enforcement and their primary role within the OPSEC program (i.e. DCMA audits acquisition management practices, DSS provides security oversight, FBI and law enforcement may provide threat data). Subcontractor and supplier OPSEC points of contact shall be similarly identified.
3.4.6 Marking, Handling and Distribution of Documents: This section shall provide a description of marking, handling, storage, access and transmission authorizations and procedures for any critical information provided to, or generated by, the contractor.
Reference to the program classification guide, Freedom of Information Act and any additional guidance provided by the contracting activity may be cited as applicable.
3.5 THREAT
3.5.1 General Threat: This section shall identify and demonstrate an understanding of the overall threat to program critical information throughout the anticipated duration of the contract/program. For example, an information systems program might note the following:
Source: https://assist.dla.mil -- Downloaded: 2014-07-02T18:58Z
DSS analysis of 2008 threat data shows, “Information systems, especially C4ISR related systems remained the primary sought-after technology for East Asia and Pacific Region countries. Direct requests (often via the Internet) and other suspicious Internet activity continued to be the preferred method of collection. Information systems are primary targets for Near East adversaries of the United States. Near East commercial entity activity indicates a growing collusion between commercial entities and government associated entities such as universities, public agencies and research and development centers. Adversaries using HUMINT and OSINT collection methods represent a significant threat to program critical information. i
The section shall conclude with a brief description of all identified intelligence collection methods that may be expected to be used by an adversary to acquire critical information.
Note: A general description of intelligence collection methods may be found in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov.
3.5.2 Program Detailed Threat: This section shall be similar to section 3.5.1 above referencing any known direct threats to acquisition specific elements of critical information within the program/contract. As complete a description of each threat as possible shall be provided while maintaining the overall plan classification at the unclassified level. Since detailed threat information may derive from classified sources, reference to source documents as provided by the government contracting activity or other reputable source is permitted.
3.5.3 Threat Analysis: Each threat identified in sections 3.5.1 and 3.5.2 shall be analyzed to determine the level of threat to the corresponding critical information. The results of this analysis shall be presented in this section. A description of the specific threat analysis method used by the contractor to quantify each threat shall be included in this section.
Note: For additional guidance and a sample threat analysis methodology see, “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.02.
3.5.4 Changes Within Threat Environment: The Threat section shall conclude with a statement that addresses how new threat data is to be received and incorporated into the OPSEC Plan to ensure OPSEC risk remains in compliance with all applicable guidance.
3.6 CRITICAL INFORMATION
3.6.1 General: Critical information shall be identified within this section of the plan and a comprehensive program Critical Information List (CIL) shall be included.
3.6.2 Critical Information List: Guidance on the creation of a CIL is contained within “Applying OPSEC to Government Acquisitions and Contracts,” available at www.ioss.gov, DODM 5205.02M, or may be provided by the contracting activity. Ideally the CIL shall remain unclassified to facilitate wide internal distribution, but may provide reference to classified information as applicable.
DRAFT
http://www.ioss.gov/
3.7 VULNERABILITY
3.7.1 General: The Vulnerability section of the OPSEC Plan shall describe the analysis of activities (indicators) that point to OPSEC vulnerabilities an adversary can exploit to acquire critical information. This section shall contain a list of all identified OPSEC vulnerabilities.
3.7.2 List of OPSEC Vulnerabilities: Each vulnerability shall be described in sufficient detail as to communicate to the contracting activity the extent of the vulnerability. The Vulnerability List shall remain unclassified, but may provide reference to classified information if applicable. Reference to classified reports and other information shall include an unclassified description of the documentation (report title, number, etc.) and the source responsible for publication of the information.
Note: A list of typical OPSEC vulnerabilities which may require OPSEC measures may be found within “Applying OPSEC to Government Acquisitions and Contracts”, available at www.ioss.gov or may be provided by the contracting activity. These sample vulnerabilities are not all inclusive and the submitted vulnerability list shall be tailored to the specific acquisition or contract.
3.7.3 Vulnerability Analysis: Once potential program vulnerabilities have been identified, the magnitude of each vulnerability shall be determined using a consistent methodology identified and documented in this section of the OPSEC Plan. The results of this analysis shall also be described in this section.
Note: For additional guidance and a sample vulnerability methodology see, “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.0-2M.
3.8 RISK ASSESSMENT
3.8.1 General: The OPSEC risk of a program represents the probability of compromise of critical information and the impact to the program/contract taking into account the threat and vulnerabilities. The acceptable level of OPSEC risk (as determined by senior leadership, or the contracting activity) shall be described in this section in terms consistent with the selected OPSEC methodology.
3.8.2 Risk Assessment: The specific OPSEC risk shall be described in terms consistent with the OPSEC methodology selected for determining OPSEC threat and vulnerability.
The method, and the results of the assessment, shall be presented in this section. The conclusion of the risk assessment shall result in an ordinal ranking of OPSEC risk (highest to lowest).
Note: Additional guidance and a sample risk methodology are available in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.0-2M.
3.9 OPSEC MEASURES
3.9.1 General: This section of the OPSEC Plan shall identify specific OPSEC
Source: https://assist.dla.mil -- Downloaded: 2014-07-02T18:58Z Check the source to verify that this is the current version before use.
DRAFT
http://www.ioss.gov/
Measures proposed for mitigating OPSEC risk to acceptable levels including the cost to implement each measure. A sampling of common OPSEC measures is available in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov . This list is not to be considered exhaustive and is provided as guidance for the development of the program/contract specific list of potential OPSEC measures.
3.9.2 Residual Risk: This section shall contain an analysis of residual OPSEC risk, in terms consistent with the OPSEC methodology selected, as a result of implementation of each OPSEC measure presented in section 3.9.1. This section shall identify which OPSEC measures will be implemented and the rationale for those that will not.
3.10 OPSEC Program Chronology: This section shall document significant program OSPEC events throughout the lifecycle of the program. Significant events may include changes to the CIL, changes in program leadership or results of program assessments and surveys (including subcontractors). At a minimum, this section shall include a brief description of the event, date of occurrence, actions taken by the contractor and final disposition. A known compromise of critical information need only be referenced in keeping with the intended classification of this document.
Note: The history contained herein may be used by the government as a part of an OPSEC or security audit conducted by the contracting activity, DSS or other authorized agency.
3.11 ACRONYMS: This section shall include a complete list of acronyms used in the Program OPSEC Plan (i.e., CDRL – Contract Data Requirements List, DID – Data Item Description, etc.).
3.12 REFERENCES: This section shall include a complete list of all references cited in the Program OPSEC Plan (i.e. DoD Manual 5205.02-M, dated November 3, 2008, Contract Number, Corporate OPSEC Plan(s)/Program(s), etc.).
i The specific example provided derives from annual documentation produced by the Defense Security Service, Counterintelligence Office in 2009. Current assessments may be found at https://www.dss.mil/isp/count_intell/count_intell.html.
4. END OF DI-MGMT-80934C.
Check the source to verify that this is the current version before use.
f. Provide data marking guidance, including distribution limitations, export control, and/or any dissemination markings to be included with classification marking
g. Provide all physical security and AIS requirements and a checklist on how to implement them; including detailed diagrams or drawings
h. Provide standard requirements for each test program (test photography, etc.).
i. Identify other Test, Industrial, Information, Personnel or Physical Security requirements
j. Provide a list of definitions, abbreviations, acronyms, terms, symbols, and notations used
k. Contain signature approval blocks (or electronic equivalent) for the Government Project Manager, Information Systems Security Officer, FSS Facility Security Officer and Servicing Security Activity (TSD-IP).
End of OT-2018-XXXXX
Title: STANDARD PRACTICE PROCEDURE (SPP)
Number: OT-2018- Approval Date: 2018MMDD
AMSC Number: N/A Limitation: FA9101-18-R-1000
DTIC Applicable: No GIDEP Applicable: No
Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A
Applicable Forms: N/A
Use/relationship: SPP will be used to ensure effective implementation of the requirements of DOD 5220.22-M, National Industrial Security Operating Manual (NISPOM). The SPP will contain specific guidance for the contractor's operations and involvement with classified information at the contractor's facility/areas located at Arnold Engineering Development Complex (AEDC). The Contractor shall implement all applicable terms of the NISPOM at each of its established areas.
This DID contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for AEDC solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).
Requirements:
1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2. Format. The SPP shall be prepared in electronic form and available to authorized users via electronic and hardcopy forms. The format shall comply with reference documents.
3. Content. The SPP content shall comply with all reference documents including NISPOM, be consistent with the required level of detail, consistent with task delineation, and address all security requirements in accordance with Government direction and applicable standards. The SPP shall contain signature approval blocks for all FSS “Key Management Personnel” and Servicing Security Activity (TSD-IP).
End of OT-2018-
Title: INFORMATION PROTECTION (IP) STANDARD OPERATING INSTRUCTION (SOI) /
STANDARD OPERATING PROCEDURE (SOP)
Number: OT-2018- Approval Date: 2018MMDD
AMSC Number: N/A Limitation: FA9101-18-R-1000
DTIC Applicable: No GIDEP Applicable: No
Preparing Activity: 10 (AEDC/TSD-IP) Project Number: N/A
Applicable Forms: N/A
Use/relationship: A written SOI/SOP provides instructions and guidance to ensure compliance with requirements contained in applicable National Industrial Security Program Operating Manual (NISPOM), Air Force, program, and other cognizant security agency directives for “Closed and Restricted” and Commercial Test Areas. The IP SOIs/SOPs are living documents that will require periodic updates throughout the life of the area.
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).
Requirements:
1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2. Format. The SPP shall be prepared in electronic form and available to authorized users via electronic and hardcopy forms. The format shall comply with reference documents.
3. Content. The security SOI/SOP content shall:
a. Comply with all reference documents
b. Be consistent with the required level of detail, consistent with task delineation
c. Address all security requirements in accordance with Government direction and applicable standards
d. Include Entry / Exit Control procedures for use by owner / users or area custodians of established controlled or restricted areas
e. Include procedures for Installation Random Antiterrorism Measures (IRAMs) procedures within established controlled or restricted areas
f. Contain signature approval blocks for FSS Facility Security Officer and Servicing Security Activity (TSD-IP)
Title: BLOOD BORNE PATHOGENS (BPP)/EXPOSURE CONTROL PLAN
Number: OT-2018- Approval Date: 201806
AMSC Number: N/A Limitation: F A9101-18-R-1000
DTIC Applicable: No GIDEP Applicable: No
Preparing Activity: 10 (AEDC/TSD-SF) Project Number: N/A
Applicable Forms: N/A
Use/Relationship: The BPP/Exposure Control Plan will be used to outline the mandatory requirements for all security guards with the potential for exposure to BPP during the performance of their assigned duties.
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).
Requirements:
1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2. Format. The contractor’s electronic format is acceptable.
3. Content. The plan shall be made readily available to all security guards and contain the exposure determination of personnel (those reasonably anticipated, as a result of performing their day-to-day duties, to have potential skin, eye, mucous membrane contact with blood or other potentially infectious fluids or materials). This determination includes:
a. A list of all duty positions in which personnel are likely to be exposed to contaminated material.
b. A list of all tasks and procedures, or groups of closely-related tasks and procedures, in which exposure may occur; tasks and procedures will be performed by personnel who handle contaminated material.
c. The methods available to prevent contact with blood and other potentially infectious fluids or materials.
d. Procedures for those who reasonably believe they have contacted a potentially infectious fluid or material.
e. Procedures for placing warning labels on containers or plastic bags containing blood or other potentially infectious material. Labels must comply with Occupational Safety and Health Agency (OSHA) Standard 1910.1030, Bloodborne Pathogens.
(Copies of this document are available online at https://www.osha.gov/law-regs.html.)
f. Procedures for keeping records of all incidents and occupational exposures per OSHA Standard 1910.1030.
g. Procedures for evaluating circumstances surrounding exposure incidents.
Title: HAZARDOUS COMMUNICATION PLAN
Number: OT-2018- Approval Date: 2018MMDD
AMSC Number: N/A Limitation: FA9101-18-R-1000
DTIC Applicable: No GIDEP Applicable: No
Preparing Activity: 10 (AEDC/TSD-SF) Project Number: N/A
Applicable Forms: N/A
Use/relationship: During execution of the contract, the contractor shall provide and maintain a Hazardous Communication Plan. This plan shall ensure supervisors and employees who handle, use, or are potentially exposed to hazardous chemicals in the course of official duties are provided information and training on the Air Force Hazardous Communication Program and the specific hazards in their work areas according to paragraph.
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).
Requirements:
1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2. Format. The plan shall be prepared in .xls or .xlsx format.
3. Content. The content hall comply with the requirements for a Hazardous Communication Plan per AFI 90-821, Hazard Communication, and shall include the following data:
a. AEDC Safety, Health, and Environmental Standard A9, Hazard Communication.
b. Authorized Use List
c. Safety Data Sheets (SDS)
(Copies of the above are available online at http://www.e-publishing.af.mil/ and by email from AEDC/SE at aedc.se.workflow@us.af.mil respectively.)
Title: FSS SECURITY SERVICES WORK INSTRUCTIONS
Number: OT-2018- Approval Date: 2018MMDD
AMSC Number: N/A Limitation: FA9101-18-R-1000
DTIC Applicable: No GIDEP Applicable: No
Preparing Activity: 10 (AEDC/TSD-SF) Project Number: N/A
Applicable Forms: N/A
Use/relationship: During execution of the contract, the contractor shall develop internal Work Instructions to cover day-to-day operations and responsibilities accounting for special contingencies and higher Force Protection Conditions (FPCONs). The Government shall be afforded the opportunity to review and comment prior to each update and/or publication of Work Instructions.
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).
Requirements:
1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2. Format. Format will be in electronic .xls or .xlsx compatible format.
3. Content. The content shall comply with the requirements for Security Services work instructions per the Arnold AFB Integrated Defense Plan (AAFB IDP 31-101), and shall include the elements listed below.
(Copies of this document are available by email from AEDC/TSD-SF at: aedc.tsd-sf.workflow@us.af.mil.)
a. Document Number and Topic
b. Approval Authority
c. Revision and Effective Date
d. Purpose
e. Scope of Application
f. References
g. Definitions
h. Introduction
i. Description of Revisions
j. Process (Step, Responsibility and Action)
k. Record
l. Flowcharts
m. Attachments
Title: FENCE LINE CHECK REPORT
Number: OT-2018- Approval Date: 2018MMDD
AMSC Number: N/A Limitation: FA9101-18-R-1000
DTIC Applicable: No GIDEP Applicable: No
Preparing Activity: 10 (AEDC/TSD-SF) Project Number: N/A
Applicable Forms: N/A
Use/relationship: During execution of the contract, the contractor shall provide a Mission Area (MA) Fence Line Check Report. The MA perimeter fence line shall be physically inspected in order to document and track all issues or concerns that could jeopardize the integrity of the structure.
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AEDC Facility Support Services (FSS).
Requirements:
1. Reference documents. The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as specified in the contract.
2. Format. Format shall be in electronic .xls or .xlsx compatible format.
3. Content. The content shall comply with the Arnold AFB Integrated Defense Plan (AAFB IDP 31-101) para C-7-1, 4, and shall include the elements listed below.
(Copies of this document are available by email from AEDC/TSD-SF at: aedc.tsd-sf.workflow@us.af.mil.)
a. Date/Time Check Conducted
b. Personnel Conducting Check
c. Map Depicting Concerns/Issues with Location Identified
d. Photos of Breaks/Openings, Vegetation Overgrowth, Erosion and Down Tress
e. Description of Concerns/Issues
f. Signage Condition and Placement
g. Any Signs of Attempted Intrusion
h. Any Information as Deemed Necessary
Title: QUICK REACTION CHECKLIST (QRC) NOTIFICATIONS
Number: OT-2018- Approval Date: 2018MMDD
AMSC Number: N/A Limitation: FA9101-18-R-1000
DTIC Applicable: No GIDEP Applicable: No
Preparing Activity: 10 (AEDC/TSD) Project Number: N/A
Applicable Forms: N/A
Use/relationship: QRC Checklist Notifications are used to provide the Government with information about activities/events/accidents/incidents/and etc. occurring on/off base that are affiliated with the base, personnel, equipment, etc. as reported to the Operations Center.
This Data Item Description (DID) contains the format, content, and intended use information for the data product resulting from the work task described in the contract Performance Work Statement (PWS). This DID is for one-time use for Arnold Engineering Development Complex (AEDC) solicitation FA9101-18-R-1000, AED Facility Support Services (FSS).
Requirements:
1. Reference documents: None
2. Format: The Contractor’s electronic format is acceptable.
3. Content: The report shall contain the following:
a. Time of activities/events
b. Summary of the activities/events
Title: DAILY EVENTS LOG
Number: OT-2018- Approval Date: 201806
AMSC Number: N/A Limitation: FA9101-18-R-1000
DTIC Applicable: No GIDEP Applicable: No
Preparing Activity: 10 (AEDC/TSD) Project Number: N/A
Applicable Forms: N/A
Use/Relationship: The Daily Events Log will be used to…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.