TOS II Attachment 7 PWS (3_26 excerpt).pdf
PDF 1 MB Posted
- Attached to
- Test Operations and Sustainment (TOS) II Federal contract opportunity
- Solicitation number
- FA9101-22-R-B001
View the file
Other files for this federal contract opportunity
Show all 50
Test Operations and Sustainment (TOS) II has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
3.26 INDUSTRIAL SECURITY, TEST SECURITY, AND SECURITY MANAGEMENT
SUPPORT
At Arnold AFB, the TOS II Contractor will be designated as an “Independent Visitor Group” per DODM5220.22V2_AFMAN16-1406V2 and will have a facility located on Arnold AFB cleared under the provisions under DoD / USAF regulations, instructions, and guidance. The Chief of Information Protection has been designated by the Installation Commander to provide security oversight and the Information Protection Office (AEDC/IP) will be the Servicing Security Activity (SSA).
As the Prime Security Contractor, the TOS II Contractor will be responsible for establishing all physical security requirements for all Arnold AFB physical space as listed in Appendix F and all other spaces determined by the SSA requiring additional safeguards. In addition, the TOS II Contractor is required to meet all PWS 3.26 requirements identified for the NFAC. The Contractor is responsible for establishing standard security practices and procedures for classified and commercial test areas as well as supporting the SAP Security Program under the direction of the Government SAP Security Officer (GSSO). In order to fully implement AEDC Information Protection Program objectives, the Contractor will need o work with and perform security support functions in coordination with the Chief of Information Protection, the AEDC Government SAP Security Officer, AEDC Security M nagers, respective program / project manager(s), and other Contractors performing work at AEDC.
In addition to requirements identified in the DD Form 254, th effort must ensure compliance with a variety of specialized security directives, regu tions and guides, including DoD Regulations, AFIs, and related AEDC policies / Operating Instructions. Contractor personnel must also have knowledge of DoDM 5 05.07, Volumes 1-4 and the JSIG, Foreign Disclosure, DoD regulations, pertinent Depar ment of Navy regulations, SAF/AQ Policy Documents, and pertinent Executive Orders. The Co tract personnel must be familiar with protecting Automated Information Systems The Contractor must be aware and adhere to revised publications listed in PWS 3.26.8 ensu proper compliance.
3.26.1. The Contractor hall implement an effective Information Protection and Industrial Security Program IAW DoDM 5220.22 Volume 2_AFMAN16-1406V2_AFMCSUP, National Industrial Security Program: Industrial Security Procedures for Government Activities and 32 CFR Part 117, National Industrial Security Program Operating Manual (NISPOM), requirements of the solicitation as noted on the DD Form 254, DoD Contract Security Classification Specification and AEDC Notification of Security Policies.
Performance Standards:
a) STD: No loss of classified and no security violations that result in a compromise
b) STD: Achieve no less than a Satisfactory rating on all security reviews, inspections, audits, and vulnerability assessments
3.26.1.1. The Contractor shall ensure all Contractor employees, including those outside the United States, are briefed on their individual responsibility for safeguarding classified information.
DRAFT
Initial briefings, refresher briefings, and debriefings provided as required, commensurate with their involvement with classified information.
3.26.1.2. The Contractor shall assist the Government to provide security control of classified, competition sensitive, proprietary operations, and other CUI as required by the installation INFOSEC program.
3.26.1.3. The Contractor shall assign personnel and operate “Secure” areas IAW with DoD and AF Instructions.
Procedures must be followed to ensure the structural integrity of secured areas above false ceilings and below raised floors. Coordinate the purchase, installation, and repair of physical barriers used for security purposes (doors, fences, gates, alarms, automated access control systems, etc.), stand-alone security systems (cameras, Automated Entry Control Systems, and Balanced Magnetic Switches), security signs / notices and security-lock hardware / keys.
Secured areas shall be constructed, and access controlled to preclude unauthorized access.
3.26.1.4. The Contractor shall accomplish administrative tasks and coordinate a daily schedule of activities and general correspondence required to support security program requirements, and in the administration of day-to-day security req irements.
3.26.1.5. The Contractor shall nominate an approp iate number of qualified personnel, as defined by applicable DoD / AF requirements, to serve as Derivative Classifiers / Declassifiers and UNCI Reviewing Officials IAW the applicable DoD / AF requirements.
3.26.2. Security, Facility Clearance Level (FCL), a d Personal Clearance (PCL) Management
3.26.2.1. The Contractor shall have a alid Top Secret FCL and maintain an industrial security program compliant with 32 CFR Part 117, National Industrial Security Program Operating Manual (NISPOM), and other mandatory directives listed in the solicitation to protect informat n and operations critical to the successful accomplishment of AEDC’s miss n. Additional mandatory directives are listed in Section 3.26.8.
There are inherently governm tal functions and activities that cannot be outsourced to a contractor. Inherently governmental activities and functions include those that require either the exercise of substantial discretion in applying United States Government authority, or value judgments when making decisions for the Government. Although the Contractor will be tasked to support assigned Government Program Security Manager(s) with respective security program requirements and to assist in providing centralized security services, the Government security manager has the lead and is the decision maker. The Contractor is only providing support in this capacity to perform administrative security functions under the direction of the activity security manager.
Activity security management shall ensure that Contractors who are involved in security administration and support duties are clearly identified in their capacities, roles, and functions, to ensure there is no possible confusion regarding inherently governmental authorities. The Contractor should contact the CO for clarification in the event of any conflict.
Inherently governmental Security Functions that the Contractor shall not perform include, but are not limited to:
(a) Approving and issuing security policies and procedures
(b) Making original classification decisions or rendering classification determinations regarding classified information that is improperly or incompletely marked.
(Correcting improper markings when the appropriate classification is not in question is not considered rendering a classification determination.)
(c) Deciding to downgrade or declassify information. (Adhering to security markings on information or to guidance stated in an appropriate security classification or declassification guide is not considered a downgrading or declassification decision.)
(d) Deciding challenges to classification and any appeals
(e) Making foreign disclosure decisions
(f) Making public release decisions
(g) Committing to expenditure of Government funds
(h) Conducting investigations of, or determining fault i security incidents involving Government or other Contractor personne (Contractors shall also conduct preliminary inquiries to determine if a security incident is a violation or an infraction.)
(i) Giving final approval or xecuting documents for filing in litigation if documents assert an official position of the DoD, any DoD Component, or any other Federal agency
3.26.2.2. The Contrac or shall ob ain and maintain an FCL at the classification level of Top Secret prior to performing any classified work on the contract.
Performance Standards:
a) STD: No Security Violations that result in a loss or compromise of classified information.
b) STD: Score / Achieve no less than a Satisfactory rating on all internal and external security reviews, inspections, audits, and / or vulnerability assessments.
3.26.2.3. The Contractor shall designate a full time Facility Security Officer (FSO) with independent authority to support the Information Protection office and enforce all aspects of security program requirements for their company and all personnel located at Arnold AFB and the NFAC.
FSO Requirements are:
(a) Security training through the Defense Counterintelligence and Security Agency (DCSA)- FSO Program Management for Possessing Facilities Curriculum (IS030.CU)
(approximately 17 courses) shall be obtained prior to contract start date. Additional courses or curriculum may be needed to obtain applicable certifications.
(b) DCSA Professional Certifications must be obtained through Security Professional Education Development Program (SPēD) within 1 year of contract start date and maintain recertification every two years.
For more information on training and SPēD Certification: www.dss.mil, www.cdse.edu/documents/sped/SPeD_Candidate_Handbook_4-1-14.pdf. The FSO Tool Kit is available at: http://www.cdse.edu/toolkits/fsos/new-fso.html.
or
(c) Acquire ASIS International Professional Certifications prior to contract start date:
For more information on training and ASIS International Certification:
https://www.asisonline.org/Certification/Board-certifications/Pages/default.aspx.
Performance Standards:
a) STD: The designated FSO, or those otherwise perf rming security duties, shall complete required security training and briefings considered appropr ate by the SSA; obtain and maintain required DSS professional certificati ns or ASIS In rnational professional certifications.
b) STD: The FSO must obtain a Top Secret PCL prior to contract start date and maintain during contract execution.
3.26.2.3.1. The Contractor shall ensure all events that have an impact on the status of the FCL, that impact the status o n employee’s PCL, that affect proper safeguarding of classified information or that in icate classified information has been lost or compromised are promptly repor ed.
Internal procedures establish d as necessary to ensure that cleared employees are aware of their responsibilities for reporting pertinent information to the FSO, the Federal Bureau of Investigation (FBI), the SSA, or other Federal authorities as required by the terms of a classified contract, and United States law. Adverse information or other National Industrial Security Program (NISP) reporting obligations reports submitted in a timely manner and recorded, if appropriate, as an incident report in the Defense Information Security system (DISS) and maintain a disciplinary action database regarding adverse information reporting.
3.26.2.3.2. The FSO and support staff, to include staff located at the NFAC, shall be trained IAW the NISPOM, for a possessing facility, and cleared commensurate with and concurrent with the issuance of the FCL IAW 32 CFR Part 117.
Performance Standard:
STD: Training must meet NISPOM and DCSA requirements and curriculum for FSO Program Management for Possessing Facilities.
3.26.2.3.3. The Contractor shall ensure the FSO is physically located at Arnold AFB to monitor and facilitate all security requirements.
Work schedules for security support are non-standard and dependent upon test schedules, inspections schedules, and emergency situations. The core operational hours of the security personnel are from 0730-1630 hours, Monday through Friday, not including opening or closing times, which may extend one or more hour(s) before or after the core hours for security support, including any visitor control or required customer assistance.
Performance Standards:
a) STD: FSO shall be available to meet with the Government on urgent security issues within two hours of initial request.
b) STD: No test or programmatic impacts occur as a result of the absence of responsible security personnel.
3.26.2.3.4. The Contractor shall ensure all subcontractors are provided a copy of the Notifications of Security Policies, as determined by the SSA I W DODM5220.22V2_AFMAN16-1406V2. The Notifications of Securi Policies must be provided to required parties and must address all security requirements before any classified work begins.
The Notifications of Security Policies will outli responsibil ties in the following areas:
Contractor security supervision; Standard Practice P o dures (SPP); access, accountability, storage, and transmission of classified material; marking requirements; security education;
personnel security clearances; reports; s curity checks; security guidance; emergency protection; protection of Govern ent resources; DD Forms 254; periodic security reviews; and other responsibilities, as required.
3.26.2.3.5. The Contractor shal suppo t the Information Protection self-inspection program and is respo sible to pe form semi-annual self-inspections at Arnold AFB and the NFAC. The Contrac or will p ovide answers and source documentation in the COR provided communicator(s) within the MICT and / or the Enterprise Risk Management (EPRM) program as appropriate.
The Contractor shall ensure accurate, reliable, and critical assessments are performed. The Government COR will validate Contractor responses to applicable communicators and source documentation within MICT or EPRM.
Deliverable:
A087 MICT Self-Assessment Report
3.26.2.3.5.1. The Contractor shall provide the Government with written corrective action plans for all identified deficiencies at Arnold AFB and the NFAC to determine primary and contributing root causes within 30 days of deficiency discovery. If the first response does not close all deficiencies, the Contractor will provide updates every 30 days thereafter until all deficiencies are resolved or closed.
Performance Standard:
STD: Air Force Smart Operations for the 21st Century (AFSO21) processes or similar tool shall be used to determine efficiencies or improve processes and procedures.
3.26.2.4. The Contractor shall provide SAP security management support for Arnold AFB. Under the direction of the GSSO, the Contractor shall assist with management, administration, and sustainment of all aspects of a SAP security program compliant with all applicable DoD and AF requirements.
The Contractor shall assist the GSSO in providing SAP security management for test security, physical security, personnel security, INFOSEC, OPSEC, and SAP security education and training.
Performance Standard:
STD: Receive no less than a Satisfactory rating from external inspections.
3.26.2.4.1. Under the direction of the GSSO, the Contractor shall establish and maintain SAP Facilities as required to support mission requirements in compliance with DoDM 5205.07, Volumes 1-4 and the JSIG and Program ecurity Officer (PSO) guidance.
Access shall be limited to authorized persons who have an ppropriate security clearance, need- to-know, and documented formal access to the informa ion within the area.
Performance Standard:
STD: No security compromises or test / rogrammatic delays as a result of ineffective or inadequate SAP security planning and execution.
3.26.2.4.2. The Contractor hall identify, obtain, and maintain United States Postal Service procedures approved by the PSO.
3.26.2.4.3. The Contrac or shall appoint a full-time Program Security Representative (PSR) cleared at least equal to the highest level of classified information for which they require access and possess ac ess to all SAPs assigned to the facility(s) for which he / she is responsible. The PSR shall have the position, responsibility, and authority as directed by the GSSO to effectively enforce all SAP security requirements based upon guidance provided by the PSO.
The Contractor shall ensure the PSR, or an appointed alternate, is physically located at Arnold AFB to monitor and facilitate all SAP security requirements.
Work schedules for SAP security support are non-standard and dependent upon test schedules, inspections schedules, and emergency situations. The core operational hours of the security personnel are from 0730-1630 hours, Monday through Friday, not including opening or closing times, which may extend one or more hour(s) before or after the core hours for security support including any visitor control or required customer assistance.
Performance Standards:
a) STD: The designated PSR, or those otherwise performing SAP security duties, shall complete required security training and briefings considered appropriate by the GSSO/PSO.
b) STD: The PSR shall be available to meet with the Government within two hours on all urgent security issues upon request.
c) STD: No test or programmatic impacts occur as a result of the absence of responsible security personnel.
d) STD: Score / Achieve no less than a Satisfactory rating on the SAP related security inspections.
3.26.2.4.4. The Contractor shall provide Top Secret accountability for all Top Secret SAP information utilizing a PSO-approved document control accountability system.
3.26.2.4.5. The Contractor shall appoint a full-time ISSM, ISSO(s), and sufficient System Administrator(s) cleared at least equal to the highest level of classified information for which they require access and possess access to all SAPs assign d to the facility(s) for which they are assigned.
The Contractor shall ensure the ISSM, ISSO, and Sys m Administrators are physically located at Arnold AFB.
3.26.2.4.6. The Contractor shall ensure com liance with s paration of duties as identified in JSIG Section 3.1.6.
3.26.2.4.7. The Contractor shall ensure that SAP Information Systems are operated, maintained, and disposed of IAW SAP security policies.
Performance Standard:
STD: No security compromises o test / p ogrammatic delays as a result of ineffective or inadequate SAP security planning a d execution.
3.26.2.4.8. The Contractor shall develop and maintain a formal information systems security program and implement all information systems security policy, establish and maintain accreditation documentation and procedures for all SAP systems, ensure the development and accuracy of accreditation documentation, and recommend action to the approval authority.
Performance Standard:
STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.
Deliverables:
A117 SAP Accredited Area SOP
A118 SAP Certification and Accreditation Package
A119 JSIG System Authorization Package
A120 DIACAP and RMF Deliverable Data
3.26.2.4.9. The ISSM shall coordinate, translate, and communicate test security requirements with the Information System Security Engineer (ISSE) and applicable ISSO(s), review plans to meet these requirements, and validate implementation of plans.
The ISSM shall provide a properly documented recommendation to the Government that ISSE solutions are effectively integrated into information systems and, pending approval, transmit documentation to appropriate approval authority.
In cases where the Contractor is serving as the ISSO, the Contractor shall execute the ISSE solution.
Performance Standard:
STD: No security compromises or test / programmatic delays a a result of ineffective or inadequate SAP security planning and execution.
Deliverables:
A117 SAP Accredited Area SOP
A118 SAP Certification and Accreditation Package
A119 JSIG System Authorization Package
A120 DIACAP and RMF Deliverable D ta
3.26.2.4.10. The Contractor shal use h Joint Access Database Environment, or any successor, for personnel security management functions for all AF SAPs IAW the AFADs Policy Directive dated 22 Jan 2008.
3.26.2.4.11. The Contr ctor shall provide IA support for test requirements, CM, lifecycle sustainment, budgeting, a d system accreditation. For systems that the Contractor serves as ISSO, the Contractor shal provide day-to-day system administration including hardware and software requisition, installation, and maintenance as required for all SAP requirements.
Performance Standard:
STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.
Deliverables:
A117 SAP Accredited Area SOP
A118 SAP Certification and Accreditation Package
A119 JSIG System Authorization Package
A120 DIACAP and RMF Deliverable Data
A121 Test Security Plan for Collateral Classified, SAP, and Commercial Tests
3.26.2.4.11.1. The Contractor shall perform IA support IAW DoDM 5205.07, Volumes 1- 4, and the JSIG, 9 October 2013, DoD Joint SAP Implementation Guide (DJSIG, 9 Oct 2013).
Performance Standards:
a) STD: Receive a satisfactory rating from all internal and external inspections.
b) STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.
Deliverables:
A117 SAP Accredited Area SOP
A118 SAP Certification and Accreditation Package
A119 JSIG System Authorization Package
A120 DIACAP and RMF Deliverable Data
3.26.2.4.11.2. The Contractor shall ensure qualif d and experienced IA personnel meeting DoD 8570 certification requirements are available to meet the day-to-day AEDC SAP system administration quirements to include after-duty hours as required.
Performance Standards:
a) STD: The designated SAP ISSM, ISSO(s), and System Administrator(s), or those otherwise preforming S P IA dutie shall complete required technical training, security training, and briefings con idered appropriate by the PSO.
b) STD: The SAP ISSM, or designated and qualified alternate, shall be available to meet with the Government on all urgent security issues within two hours of initial notification.
c) STD: No test or programmatic impacts occur as a result of the absence of responsible SAP IA personnel.
d) STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate SAP security planning and execution.
3.26.2.4.12. The Contractor shall ensure all systems required for SAP support obtain Authority to Operate (ATO) to meet test requirements to include:
Collecting and providing IA artifacts, and maintaining updated Certification and Accreditation packages for SAP Information Systems
Maintaining a continuous monitoring program to ensure the state of the systems’ environments do not change from the accredited configurations
a) STD: 100% of systems must have an approved ATO prior to testing.
b) STD: All SAP ATO packages must be renewed within 1 month of their expiration.
Deliverables:
A117 SAP Accredited Area SOP
A118 SAP Certification and Accreditation Package
A119 JSIG System Authorization Package
A120 DIACAP and RMF Deliverable Data
A121 Test Security Plan for Collateral Classified, SAP, and Comm rcial Tests
3.26.2.4.13. The Contractor shall prepare SOPs necessary for the implementation of SAP requirements. SOPs shall be developed and c ordin ted in compliance with DoDM 5205.07, Volumes 1-4, and the JSIG.
Deliverable:
A117 SAP Accredited Area SOP
3.26.2.5. The Contractor shall provid security support for all phases of unclassified, classified, and commercial testi g and related test activities performed at Arnold AFB and the NFAC.
The Contractor shall establish and mplement a security program compliant with DoD, service, and local directives an make recommendations for improvements to security test procedures;
integrate cost effective an threat-based security processes, plans, and procedures. Test phases include planning, design, fab ication, installation, execution, removal, reporting, and analysis.
The protection / security of tes articles or systems and data is required.
Performance Standards:
a) STD: No Security Violations that result in a loss or compromise of classified information.
b) STD: Score / Achieve no less than a Satisfactory rating on all internal and external security reviews, inspections, audits, and / or vulnerability assessments.
3.26.2.5.1. The Contractor shall use specific Program Security Classification Guides (SCG) for all classification management decisions, and retain a copy of all program SCGs and verify they are current IAW 32 CFR Part 117, DoDM5200.01 Volume 1_AFMAN 16- 1404 Volume 1, DoDM5200.01 Volume 2_AFMAN 16-1404 Volume 2, DoDM5200.01 Volume 3_AFMAN 16-1404 Volume 3, DoDI5200.48_DAFI16-1403, DODM5220.22V2_AFMAN16-1406V2, and supplements.
STD: Maintain 100% of applicable test related SCGs on site.
3.26.2.5.2. The Contractor shall provide analytical, technical, and administrative security support services to Information Protection, Industrial Security, and SAP Security programs managed by the Government.
Technical and administrative support from qualified security personnel is required to ensure core programs are successfully executed IAW applicable DoD and AFIs. Support will be provided "on-site” to the Government at Arnold AFB and includes security reviews, evaluations, initial surveys, and assessments. The Contractor shall be required to visit the NFAC at least once per year to conduct a Staff Assistance Visit or inspection. Programs include but are not limited to: Industrial Security, Personnel Security, INFOSEC, OPSEC, Test Security, and Physical Security for the protection of controlled information.
The Contractor should anticipate supporting 5-10 security reviews evaluations, initial surveys, and assessments annually; however, this may fluctuate depending pon mission needs.
Performance Standard:
STD: No security compromises or test / programmatic d lays as a result of ineffective or inadequate technical security planning support.
3.26.2.5.2.1. The Contractor shall provide High D finition (HD) photography equipment and support of photography requirements within the AEDC test mission area regardless of its security classification.
The Contractor should anticipate Arnold AFB personnel and / or Test Customers to request photography services within the test mission area. The Contractor shall provide policy, procedures, and control of all HD photography equipment to support test mission and infrastructure / maintenance related photography. The Contractor will be responsible for the screening and review of ll photogr phs before release to ensure required protection and markings are applied. HD p otography equipment shall meet the following minimum requirements: 1080p, JPEG-ba eline compliant, SD and UHS-I compliant media, SDHC and SDXC memory cards, autofocus lens.
Performance Standards:
a) STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate photography quality or support.
b) STD: Maintain 100% accountability of equipment and media review to ensure proper marking and release.
3.26.2.5.2.2. The Contractor shall provide Portable Electronic Device (PED) approval / disapproval services and procedures for Arnold AFB and the NFAC personnel and test customers.
The Contractor shall provide specific policy / procedures to the workforce when a PED is required within secured areas. The Contractor must be able to evaluate the risk associated with each PED based on its capabilities to transmit data or inadvertently compromise sensitive information. PEDs may include but are not limited to hearing aids, medical devices, laptops, Electronic Notebooks, FitBits, Keyfobs, etc.
Performance Standard:
STD: No security compromises resulting from ineffective security policy, procedures and / or controls.
3.26.2.5.3. The Contractor shall assist the Government to develop security requirements for contractual commitments IAW DODM5220.22V2_AFMAN16-1406V2 and supplements.
Examples include coordination of the DD Form 254, DoD Contract Security Classification Specification, Notifications of Security Policies, and Security C uses.
3.26.3. OPSEC / Foreign Government Protection
3.26.3.1. The Contractor shall assist the Governm nt to develop, coordinate, and execute all OPSEC program requirements and Foreign Government Protection requirements for Arnold AFB and the NFAC.
3.26.3.2. The Contractor shall develop an OPSEC program plan to address how the Contractor will protect critical and sensitive contracted information IAW AFI 10-701 and Arnold AFB Critical Informati and Indicator List IAW AFI 10-701, para 8.2.5.1.
Upon acceptance by the Governm t, the Contractor shall implement the OPSEC program plan for Arnold AFB and the NFAC.
Deliverable:
A122 OPSEC Program Pl
3.26.3.3. The Contractor sha l conduct OPSEC Foreign National Vulnerability Assessments and Audits for visiting foreign guests and / or customers visiting Arnold AFB and the NFAC, IAW DODM5220.22V2_AFMAN16-1406V2, AFI 10-701, and supplements.
The Contractor should anticipate several foreign visitors throughout the year. All foreign guests or visitors shall be coordinated with the AEDC Public Affairs office and the Foreign Disclosure office.
Performance Standard:
STD: No security compromises or test delays resulting from ineffective vulnerability assessments and audits.
3.26.3.4. The Contractor shall appoint an OPSEC trained person as a POC with overall OPSEC responsibilities to maintain awareness of foreign intelligence collection capabilities, limitations, methods, and practices.
The Contractor shall familiarize all new Contractor employees and conduct refresher sessions as needed in the areas of Counterintelligence (DoDI 5240.6, Counterintelligence (CI) Awareness and Briefing Program, paragraph 6.2, Awareness and Briefing Requirements), Operations Security (DLAI 5200.13, DLA Operations Security (OPSEC) Program, Enclosure 3, OPSEC Planning Guidance), and Classified Material / Clearance (DLAI 5200.12, Information Security Program, Chapter 11, Standards for Storage and Handling Classified Material).
The OPSEC POC shall at a minimum successfully complete the OPSEC Analysis and Program Management Course (OPSE-2380 and OPSE-2390): The focus of this course is on the basic skill and knowledge needed to conduct an OPSEC risk analysis (apply the five steps) and to implement an OPSEC program. This course is intended for use by the DoD and other Government personnel and Contractors within the NISP.
For course registration and information refer to: https://www iad ov/ioss/.
Performance Standard:
STD: Fully integrated OPSEC Support Staff training c mpleted within 30 days of contract start date.
3.26.3.5. The Contractor shall assist the Go nment program manager in the development and implementation of the Commande ’s OPSEC policy and Critical Information and Indicator List IAW AFI 10-701 and supplements.
Performance Standard:
STD: Fully integrated OPSEC progr m execution within 30 days of contract start date.
3.26.3.6. The Contractor shall co duct OPSEC training IAW AFI 10-701 and locally- developed training.
The Contractor shall familiar ze new employees for awareness and conduct refresher sessions needed in the areas of OPSEC and Critical Information.
3.26.3.7. The Contractor shall integrate and include OPSEC into all acquisition programs and Contractor support documents IAW AFI 10-701.
Performance Standard:
STD: Integrate OPSEC into all acquisition programs and contractor documentation.
3.26.3.8. The Contractor shall coordinate with the Government to resolve / mitigate Web Risk Assessment, Telecommunications Monitoring Assessment Program, Vulnerability Assessment, and other OPSEC assessment findings as required IAW
AFI 10-701.
STD: Conduct OPSEC Web Risk and Vulnerability Assessments monthly.
3.26.3.9. The Contractor shall assist the Government to conduct Staff Assistance Visits with the Government as required or requested IAW AFI 10-701.
The Contractor should anticipate supporting 5-10 Staff Assistance Visits annually, however this may fluctuate depending upon mission needs.
3.26.3.10. The Contractor shall conduct and document OPSEC in all self-assessments and implement required changes when required.
Performance Standard:
STD: Include all OPSEC requirements in mid-term self-assessments.
3.26.3.11. The Contractor shall integrate OPSEC into all organization planning, operational processes, acquisition programs, and Contractor support documents.
Recognizing that sub-Contractors vary in size, resources, and length of subcontract, OPSEC programs implemented for subcontractors should be designed to afford at least a minimum level of OPSEC protection and understanding for all subco tracts with increasing levels of OPSEC protection and understanding for more sensitive subcon racts.
Performance Standard:
STD: Integrate OPSEC into all acquisition programs and contractor documentation.
Deliverable:
A124 IP SOP for Secured Areas
3.26.3.12. The Contractor sha l comp y with the OPSEC measures imposed by any program supported.
Organizations and personn l suppo ting customers may have OPSEC requirements associated with their activities and suppo t The following standard expectations are included in all work:
(a) Specific event-oriented activities are supported when directed by the supported program or comply with the program's OPSEC Plan / Annex.
(b) OPSEC Awareness Education and Duty-Related Training as deemed necessary by the Government or program supported are provided to personnel assigned.
(c) OPSEC protective measures (countermeasures) are applied as directed by Government or program sponsors.
Performance Standard:
STD: No more than one validated complaint per quarter.
3.26.4. Security Administrative Support
3.26.4.1. The Contractor shall provide security support sufficient to ensure full compliance with DoD, service, and local directives at Arnold AFB and the NFAC.
3.26.4.2. The Contractor shall request security clearance investigations for their personnel located at Arnold AFB and the NFAC when the Contractor determines that access to classified is essential in the performance of tasks or services related to the fulfillment of the contract.
Requests for Contractor security clearances shall be kept to an absolute minimum necessary to perform contract requirements. The Contractor shall ensure that sufficient personnel have the appropriate security clearance to accomplish all tasks specified in this PWS prior to the performance start date.
Performance Standard:
STD: 100% of all security investigations shall be reviewed for quality and completeness prior to submission to minimize delays with processing.
3.26.4.2.1. The Contractor shall ensure potential candidates for hire have been properly vetted prior to submitting a federal investigation or offering them a osition at Arnold AFB or the NFAC to ensure the candidate can obtain and maintain access to classified, CUI, and / or base access.
The Government’s intent is to reduce the amoun of costly investigations for those who could not likely acquire or maintain access to Government fa ilities / information and to ensure only the highest quality of personnel are admitted onto AEDC based on their behavioral / criminal history.
Performance Standard:
STD: 100% of potential candida s shal be sufficiently pre-vetted to ensure the candidate can obtain and maintain ac ess to poten ial classified, CUI, and base access.
3.26.4.2.2. The Contractor shall review DISS daily to obtain relevant security clearance and investigation informatio pertaining to present and future AEDC affiliated personnel performing classified work at Arnold AFB, the NFAC, and other personnel in whom the AEDC has a security interest.
Performance Standard:
STD: 100% of personnel security clearances shall be reviewed prior to gaining access to classified secured areas.
3.26.4.2.3. The Contractor shall process Homeland Security Policy Directive 12 and other “Position of Trust” investigative requests for all Arnold AFB and the NFAC Government Contractor personnel through the AEDC Government Personnel Security Program Manager IAW AFMAN 16-1405.
The Contractor should anticipate processing ~125 Tier 1 investigative requests annually.
Investigative requests and supporting documentation (Standard Form 85) are required for any new AEDC Contractor personnel without a security clearance or other required background investigation for base / facility access and / or access to unclassified Government computers.
Performance Standard:
STD: 100% of all security investigations shall be reviewed for quality and completeness prior to submission to minimize delays with processing.
3.26.4.2.3.1. The Contractor shall process required documentation through the AEDC Information Protection Office for background checks and interim approval for access to unclassified Government computers. This documentation is required for all new AEDC contractor personnel who do not have a security clearance or other required background investigation and is required to support test customers who work for uncleared companies.
3.26.4.2.4. The Contractor shall provide electronic fingerprint services, required for official Government business, to all Government Contractor located at Arnold AFB requiring a background investigation. The Contractor will ens re Government Contractors located at the NFAC can obtain fingerprint services t or near the immediate area.
The Contractor should anticipate processing ~300 fingerp ints annually. Contractor fingerprint services shall be provided to the Government in the rare eve t the Government’s fingerprinting equipment fails to operate. Fingerprinting equipm nt will be provided as GFP.
Performance Standard:
STD: Zero Rejection Rate. (All f ngerp ints submitted must be deemed classifiable and acceptable by Office of Personnel Manag ent (OPM), FBI, etc.). Exceptions would be evaluated on a case-by-case basis, e.g mechanical, or physical disfigurations.
AQL: No more than a % rejection rate. (95% of all fingerprints submitted must be deemed classifiable and acceptab by OPM FBI, etc.)
3.26.4.2.5. The Contractor shall provide a copy of all adverse information reports submitted to DCSA to the installation Commander via the SSA. Incident reports shall also be entered in the DISS. Reports required to be submitted to the FBI shall also be reported to the local detachment of the AF Office of Special Investigations (OSI). The Contractor shall report all adverse information concerning SAP-briefed personnel to the PSO IAW DoDM 5205.07, Volumes 1-3 and the JSIG. Report all adverse information concerning SCI indoctrinated personnel to the AEDC Special Security Officer.
Performance Standards:
a) STD: No programmatic impacts from adverse personnel suitability issues.
b) STD: Score / Achieve no less than a Satisfactory rating on Inspections.
3.26.4.2.6. The Contractor shall use DISS for transmitting / receiving visit requests and to properly identify the security clearance level of visitors (to include test customers) performing at Arnold AFB and the NFAC, IAW 32 CFR Part 117, DoDM5200.01 Volume 1_AFMAN 16-1404 Volume 1, DoDM5200.01 Volume 2_AFMAN 16-1404 Volume 2, DoDM5200.01 Volume 3_AFMAN 16-1404 Volume 3, DoDI5200.48_DAFI16-1403, DODM5220.22V2_AFMAN16-1406V2, and supplements.
3.26.4.3. The Contractor shall implement an Insider Threat program at Arnold AFB and the NFAC, IAW guidance and standards developed by the Insider Threat Task Force established in section 6 of EO 13587, DoDI 5240.26, and AFI 16- 1402. The Program shall be designed to identify employees that have access to secured areas, displaying potential espionage indicators. Adverse behavior which might indicate a potential threat to national security shall be reported as required IAW DoDI 5240.26 and AFI 16-1402 and supplements.
For the purposes of the NISPOM, insider threat refers to the threat of an insider using his or her authorized access, wittingly or unwittingly, to do harm to the security of the United States. This threat can include damage to the United Sates. through espionage, terrorism, unauthorized disclosure of national security information, or through the loss or degradation of Government, company, contract or program information, resources, or capabilities
Performance Standards:
a) STD: No programmatic impacts from personnel suita ility issues.
b) STD: Score / Achieve no less than a Satisfact y rating on Inspections.
3.26.4.3.1. The Contractor shall establish and foster a CI-focused culture at Arnold AFB and the NFAC, for all personnel havi g access within secured areas in order to detect, deter, and expeditiously report uspicious activ ties.
Performance Standards:
a) STD: No security ompromise or test delays resulting from ineffective security.
b) STD: Instructions will e available to all personnel within these areas that describe the proper way to mark, log, and ontrol all classified and CUI.
3.26.4.3.2. The Contractor shall control media and information located at Arnold AFB and the NFAC, IAW the respective classification level and SCGs.
Performance Standard:
STD: All controlled media shall be located and retrieved within 24 hours or as required.
3.26.4.3.3. The Contractor shall provide the Government vault / safe inspections and schedule periodic maintenance as required IAW AFI 16-1404 and 32 CFR Part 117.
3.26.4.3.4. The Contractor shall establish liaison with local CI and law enforcement organizations to determine the status of the local threat to the facility, personnel, and supported programs. Inform the Government of threats or any other information required IAW 32 CFR Part 117, AFI 10-701, AFI 16-1404, AFMAN 16-1405, The Contractor shall engage with local CI and law enforcement organizations located at or near the NFAC and provide feedback and advice to the acting Government director.
3.26.4.3.5. The Contractor shall support Government security managers with conducting and documenting specialized security initiatives, training, and briefings IAW 32 CFR Part 117, AFI 10-701, AFI 16-1404, AFMAN 16-1405, DODM5220.22V2_AFMAN16- 1406V2, and supplements.
Performance Standard:
STD: Assist with at least one security initiative per quarter.
3.26.4.3.6. The Contractor shall operate and maintain a classified and controlled material destruction capability for Arnold AFB and the NFAC. The Contractor shall ensure classified destruction capabilities meet or exceed NSA classified destruction standards.
The Contractor should anticipate providing destructio capabilities for all types of media, e.g., paper, CD/DVDs, hard drives, film, etc.
Performance Standard:
STD: Zero security violations due to compromise of clas ified or CUI material.
3.26.4.3.7. The Contractor shall prov de bulk destruction and disposal capability for all classified and controlled unclassified material generated at Arnold AFB and the NFAC.
The Contractor should anticip te providing bulk destruction and disposal capability for approximately 3 to 5 tons of classi ied ma erial and approximately 25 tons of CUI annually.
Performance Standard:
STD: Zero security violations due to compromise of classified or CUI material.
3.26.4.3.8. The Contractor shall control, track, and issue all accountable security materials such as classified storage equipment, containers, vaults, and combination locks used in the AEDC Information Protection / Industrial Security Programs IAW 32 CFR Part 117, DoDM5200.01 Volume 1_AFMAN 16-1404 Volume 1, DoDM5200.01 Volume 2_AFMAN 16-1404 Volume 2, DoDM5200.01 Volume 3_AFMAN 16-1404 Volume 3, DoDI5200.48_DAFI16-1403, DODM5220.22V2_AFMAN16-1406V2, and supplements.
3.26.4.3.9. The Contractor shall ensure required security briefings are conducted to visitors and escort officials accessing all secured areas located at Arnold AFB and the
NFAC.
STD: No security compromises or test / programmatic delays as a result of ineffective or inadequate security planning, training, and execution.
Deliverable:
A124 IP SOP for Secured Areas
3.26.4.3.10. The Contractor shall provide an adequate amount of NSA approved shredders capable of destroying paper, other media, and hard drives. NSA approved CD/DVD and paper shredders shall be strategically positioned throughout Arnold AFB and the NFAC testing environments to support day-to-day operational requirements IAW 32 CFR Part 117, DoDM5200.01 Volume 1_AFMAN 16-1404 Volume 1, DoDM5200.01 Volume 2_AFMAN 16-1404 Volume 2, DoDM5200.01 Volume 3_AFMAN 16-1404 Volume 3, DoDI5200.48_DAFI16-1403, DODM5220.22V2_AFMAN16-1406V2, AFI 10- 701, and supplements. The Contractor shall train all designated personnel on the use of the equipment.
The Contractor is required to provide NSA approved equipment (NSA/CSS EPL 0202M Annex A to NSA/CSS 02 02, NSA/CSS Evaluated Products List) for the des uction of classified material.
3.26.4.3.11. The Contractor shall provide an adequat amount of secure CUI destruction / shred collection bins, to ensure all AEDC sensitive pape and data storage devices / media, at Arnold AFB is properly destroyed IAW DoDI5200.48_DAFI16-1403.
The Contractor shall ensure that the security specialist located at the NFAC utilizes local CUI destruction equipment and / or procedu s. CUI may be destroyed by any of the means approved for the destruction of cl ssified informat on or by any other means that would make it difficult to recognize or reconstruc the info mation. Recycle bins are not approved for controlled information.
The Contractor should nticipate de troying or disposing of ~25 tons annually; however, this fluctuates depending upon mission needs.
Performance Standard:
STD: Secure bins for collection of CUI intended for destruction shall be strategically positioned throughout work centers and adequately destroyed at least bi-monthly (approximately 110).
3.26.4.3.12. The Contractor shall provide overnight transitory storage capability located in the Arnold AFB Base Defense Operations Center approved for safeguarding classified material, up to the secret level, IAW 32 CFR Part 117, DoDM5200.01 Volume 1_AFMAN 16-1404 Volume 1, DoDM5200.01 Volume 2_AFMAN 16-1404 Volume 2, DoDM5200.01 Volume 3_AFMAN 16-1404 Volume 3, and supplements.
Overnight transitory storage is for use by AEDC visitors and transitory personnel. The Contractor shall advertise this capability at key visitor reception points.
The Contractor shall ensure that the security specialist located at the NFAC utilizes local overnight transitory storage capabilities and / or procedures.
STD: Zero validated complaints.
Deliverable:
A124 IP SOP for Secured Areas
3.26.4.3.13. The Contractor shall provide security-related technical assistance to the Government and Contractor personnel for briefings and conferences held at Arnold AFB and the NFAC.
The Contractor should anticipate providing security-related technical assistance to Government and Contractor personnel for 150 briefings and conferences annually.
Performance Standard:
STD: No more than one validated customer complaint per quart r
3.26.4.3.14. The Contractor shall participate in security and other program meetings, integrated product team (IPT) meetings, test concept meetings, working group meetings, CI support meetings, and participate in the development of solutions to items of concern or action items related to test IAW 3 CFR Part 117, AFI 10-701, AFI 16-1404, AFMAN 16-1405, DODM5220 22V2_AFMAN16-1406V2, and supplements.
For example, Installation Security Advisory Group, OPSEC Working Groups, Security Working Groups, or other security relat d working groups or IPTs.
Performance Standards:
a) STD: No more than one miss d mee ing per quarter.
b) STD: No more than ne validat d customer complaint per quarter.
3.26.5. Controlled Spaces / ncident Management
The Contractor shall manage all AF secured areas and provide Security Incident management support sufficient to ensure full compliance with DoD, service, and local directives at Arnold AFB and the NFAC.
3.26.5.1. The Contractor shall ensure entry and exit inspections in at least one controlled area weekly in order to deter and detect unauthorized introduction or removal of classified material from AF secured areas IAW 32 CFR Part 117, DoDM5200.01 Volume 1_AFMAN 16-1404 Volume 1, DoDM5200.01 Volume 2_AFMAN 16-1404 Volume 2, DoDM5200.01 Volume 3_AFMAN 16-1404 Volume 3, and DoDI5200.48_DAFI16-1403.
Ensure SOPs include Entry / Exit Control procedures for use by owner / users or area custodians of controlled areas established for classified operations include procedures for entry and exit checks. The NFAC shall be included in the Contractor’s weekly entry and exit inspection schedule.
a) STD: Entry / Exit inspection schedule and data must be maintained for inspection purposes and random enough to deter unauthorized removal of classified material and documented.
b) STD: Zero security violations due to compromise of classified or CUI material.
Deliverable:
A124 IP SOP for Secured Areas
3.26.5.1.1. The Contractor shall prepare written SPP necessary for the implementation of the NISPOM IAW 32 CFR Part 117, NISPOM and DODM5220.22V2_AFMAN16- 1406V2, and supplements. SPPs must be submitted and approved for use by the Government (SSA) prior to performance start date of this c ntract.
If the company elects to change, modify, develop an addendum, ann x, supplement, to their SPP, or add an internal SOP, for any on-base security operations, it wil require Government written approval of those security procedures. The NFAC sh ll be included in the Contractor’s SPPs.
Deliverable:
A123 SPP Document
3.26.5.1.2. The Contractor shall estab ish security requirements for all controlled physical space required to supp rt test operations and other activities held at Arnold AFB and the NFAC IAW DoDM5 00.01 Volume 1_AFMAN 16-1404 Volume 1, DoDM5200.01 Volume 2_AFMAN 16 1404 Volume 2, and DoDM5200.01 Volume 3_AFMAN 16-1404 Volume 3.
All controlled spaces (AF ecured a eas or other spaces requiring limited access) shall have a SOP with detailed instruction on how the area is to be maintained.
Performance Standards:
a) STD: Zero unauthorized entries due to inadequate security guidance.
b) STD: Zero security incidents which result in a loss or security compromise due to inadequate security guidance.
Deliverable:
A124 IP SOP for Secured Areas
3.26.5.1.3. The Contractor shall establish and maintain physical security requirements for all classified space located at Arnold AFB and the NFAC, IAW DoDM5200.01 Volume 1_AFMAN 16-1404 Volume 1, DoDM5200.01 Volume 2_AFMAN 16-1404 Volume 2, DoDM5200.01 Volume 3_AFMAN 16-1404 Volume 3, DoDI5200.48_DAFI16-1403, DODM5220.22V2_AFMAN16-1406V2 and supplements.
The Contractor shall provide a SOW for all new and modified alarm requirements at Arnold AFB. The SOW will be required before a request for proposal can be drafted.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .