Attachment 10 - SOO 4 NSWC Development _23 Mar11_.pdf
PDF 92 KB Posted
- Attached to
- SITEC Application Management Services Federal contract opportunity
- Solicitation number
- H92222-10-R-0046
- Issued by
- United States Special Operations Command
About this file
Atch 10 - SOO 4 NSWC Development
View the file
Other files for this federal contract opportunity
Show all 34
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
H92222-10-R-0046, 0002 Attachment 10
STATEMENT OF OBJECTIVES FOR EVALUATION
NAVAL SPECIAL WARFARE COMMAND (NSWC) SOFTWARE & TRA INING SUPPORT
1.0 DESCRIPTION OF SERVICES: Reference PWS, Paragraphs 5.1 and 5.4. The objective of this Task Order is to provide support services in developing web, database, and application servers and software. This task applies to NSWC (East and West).
2.0 PURPOSE: Support the development, migrations, testing, documentation, integrations and maintenance of government off-the-shelf (GOTS)/ contractor off-the-shelf (COTS) web base software, database development software, and application development software. Additionally, this effort will provide end-user training for both developed and legacy software solutions.
3.0 SPECIFIC REQUIREMENTS/DELIVERABLES:
3.1 Support Requirements. Contractor shall provide configuration and consultation services for the Naval Special Warfare Special Operations Command (WARCOM), requirements for these services include development and design of the WARCOM Portal on the SIPRNET and NIPRNET using the Microsoft Office SharePoint Services 2007 (MOSS) and/or future released version. This also requires the development of web parts and applications as necessary to enhance the operability of the portal.
3.2 Support the sustainment and life cycle upgrade of web applications, and the development of WARCOM unique mission critical applications to support the command.
3.3 Provide assistance to WARCOM with the evaluation of information sharing and knowledge management issues and strategies. Formulate a migration strategy for all identified WARCOM applications and information into the portal and identify potential new applications and services for delivery as well as an impact assessment for each tool. Facilitate migration of WARCOM business processes onto the SIPRNET using the WARCOM portal as our primary workplace, information source, and collaboration site on the SIPRNET.
3.3.1 Support the WARCOM goal of supporting the operational missions to conduct as much business as possible on the SIPRNET.
3.3.2 Expedite the process of developing data flows and automating data feeds to create a commander’s operational picture, support critical mission information and collaboration capabilities, migrate applications to the SIPRNET, and support the migration and automation of business processes and information to the WARCOM portal.
3.4 Provide technical and requirements analysis, recommendations for procedural direction, process improvements, and planning for complex customer programs and systems within WARCOM with a goal to integrate into SharePoint portals and support the Secure Operating Environment (SOE) initiative. Prepare reports and presentations for colleagues, senior management, and customers and deliver a Vision and Scope for any solution that requires customization above the inherent out of the box capabilities of SharePoint. The composite of this information shall be documented on the Business Process Management site on the WARCOM portal. Based on these goals and objectives, and with Government concurrence, determine if customization is required, deliver a Vision and Scope document outlining proposed customized solutions, and work with the government to prioritize development through the WARCOM Portal Working Group. Develop and perform training, marketing, knowledge capture strategies and proposals for customer, and consult as necessary on all initiatives, technical issues and other initiatives.
3.5 Develop and maintain WARCOM’s business and command and control (C2) software applications as identified and prioritized by the C&IWG requirements process. Provide PMO support for all applications developed. This includes maintenance of the following applications already in place:
3.5.1 WARCOM Apps Suite of Tools:
• WARCOM Personnel Databases
• Scheduler
• Tasker
• Training Records
• Equipment/Resources
3.5.2 Provide IT support services for Electronic Records Management for the NSW enterprise. Personnel supporting this requirement will be located at NAVSPECWARCOM (Coronado). The manager assigned at Coronado will serve as the records manager supporting the daily operations of the NAVSPECWARCOM Records Management program, to include end-user assistance and training.
3.6 Prepare a Vision/Scope document for identified major projects. Utilize standard Microsoft Solutions Framework format, to include; project overview, vision statement, functional requirements, solution concept, user profiles, design goals, project roles and responsibilities, updated risk assessment and backup/data recovery, project schedule, and change management plan.
3.7 Provide a Functional Specification and Design (FSD) document for each spiral of the project development cycle. Each FSD shall include the architecture and identify a schedule for each spiral of the project as well as the solution scope, user roles, principle threads, high level component definition, and logical/physical design.
3.8 Build solutions designed and specified in the FSD Document for each spiral.
3.9 Support/Maintenance Requirements:
3.9.1 Perform Tier 2 & 3 Incident functions as assigned by the Service Desk.
3.9.2 Participate and execute the ongoing user adaptation, end-user training, and the change management process developed and delivered as part of Project Vision/Scope Definition task.
4.0 SECURITY REQUIREMENTS.
4.1 Security shall be in accordance with the attached DD254. Contractor team individual(s) supporting this task shall be cleared at the Secret level at the start of this task. Contractors must meet the eligibility requirements to obtain higher clearances as required by the task order. Contractors shall require access to NIPRNET/SIPRNET computer systems only at government facilities. Contractor shall be authorized to courier classified information up to the “Secret” level in performance of official duties upon approval of and designation by the COR.
4.2 The Contractor shall insure requirements for safeguarding classified information and classified materials, for obtaining and verifying personnel security clearances, for verifying security clearances and indoctrination of visitors, for controlling access to restricted areas, for protecting government property, and for the security of automated and non-automated management information systems and data are fulfilled. The contractor’s management system shall prevent unauthorized disclosure of classified and sensitive unclassified information. The government shall be immediately notified if any security incident or any indication of a potential unauthorized disclosure or compromise of classified or sensitive unclassified information.
4.3 The Contractor shall provide security management support. Typical efforts include, but are not limited to, performing classified document control functions, classified materials inventories, program access requests, preparing and monitoring personnel indoctrination and debriefing agreements, and maintaining and using security-related databases.
5.0 REPORTS. CDRLs 1 – 21 will apply to this task order.
6.0 SERVICE LEVEL AGREEMENTS. SLAs F1 – F4 will apply to this task order.
7.0 MATERIALS. Government shall provide necessary materials to complete this Task Order. The Government will provide office space for a maximum of 7 contractor personnel (Coronado = 6 and Little Creek = 1) for this task.
Personnel assigned to this task shall have access to the Government test facility and shall identify any specific software or hardware devices required for the performance of the Task Order as soon as possible after Task Order award.
8.0 PACKAGING, HANDLING, STORAGE, AND TRANSPORT ATION: N/A
9.0 HOURS OF WORK: Normal working hours shall be day shift, 0800 to 1700 Monday through Friday.
Periodic work after normal duty hours to support updates and maintenance of services will be required to ensure minimal disruption of service to the customers. The contractor will provide on-call support for tier 3 level support for these services 24/7 to ensure continuous delivery of these critical services.
10.0 PERSONNEL: Functional leads will be designated for all of the support functions identified in Section 3.
All functional leads in support of this Task Order are considered key positions. As such, contractor shall submit resumes for all new and replacement candidates proposed.
10.1 QUALIFICATIONS: Contractor shall provide personnel capable of demonstrating knowledge and experience with Microsoft Windows Server 2003 and Windows XP operating systems. Personnel shall also have demonstrated experience with the installation, configuration, and administration of MOSS 2007 Portal (including portal design, creating Web Parts, and document libraries), Ms SQL Server 2005, Internet Explorer 6.0, and Visual Studio software development application. Personnel shall also have experience with XML integration, InfoPath, SharePoint services, Electronic Records Management System (ERMS), and the integration of other services and products with a structured query language database server.
INSTRUCTIONS TO OFFERORS (ITO)
NAVAL SPECIAL WARFARE COMMAND/CNSWC SOFTWARE SUPPO RT
Background: This instruction to offerors gives specific guidance to assist the contractors in the preparation of a proposal against the Statement of Objectives (SOO) for Naval Special Warfare Command/CNSWC Software Support Task Order under the Special Operations Command Information Technology (SITEC) Application Management contract.
Participating Entity: Naval Special Warfare Command (NAVSOC)
Provided as Attachments to the ITO: SOO, DD 254, SCI (if applicable) and FOUO Addendums
General Information:
Period and Place of Performance: 1 Jun 2011 – 31 May 2012, with 2, 1-year option periods. Place of Performance is onsite. The Government anticipates this work to be performed on site at Coronado NAB, CA, and Little Creek NAB, VA.
Travel: Based on historical information, no travel is anticipated in support of this task.
Historical Labor Requirements: This requirement was currently being accomplished via EITC Task Orders #948.
Instructions: All offerors are to submit their task order proposals IAW Section H clause entitled “Ordering Procedures” and section L of the RFP. The following information is provided to assist with this submission:
Proposal: Contract Type: CPFF
Evaluation Statement: The proposal will be evaluated in accordance with the following paragraph and section H6 of the RFP.
Best Value Determination: The Government will evaluate the Task Order Management Plan, Performance Work Statement (PWS), and Task Order Price proposed. Task Order Management and PWS are significantly more important than Task Order Price.
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
1. CLEARANCE AND SAFEGUARDING
(The requirements of the DoD Industrial Security Manual apply to all security aspects of this effort.)
a. FACILITY CLEARANCE REQUIRED
Secret
b. LEVEL OF SAFEGUARDING REQUIRED
None
2. THIS SPECIFICATION IS FOR: (X and complete as applicable)
3. THIS SPECIFICATION IS: (X and complete as applicable)
a. PRIME CONTRACT NUMBER
a. ORIGINAL (Complete date in all cases) Date (YYYYMMDD)
20110701
b. SUBCONTRACT NUMBER
b. REVISED (Supersedes all previous specs)
Revision No. Date (YYYYMMDD)
c. SOLICITATION NUMBER H92222-10-R-0046
DUE DATE (YYYYMMDD)
20110404 c. FINAL (Complete Item 5 in all cases) Date (YYYYMMDD)
4. IS THIS A FOLLOW -ON CONTRACT? YES NO If YES, complete the following
Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract
5. IS THIS A FINAL DD FORM 254? YES NO If Yes, complete the following:
In response to the contractor’s request dated , retention of the classified material is authorized for the period of
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
a. NAME, ADDRESS, AND ZIP CODE
TBD
b. CAGE
CODE
TBD
c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)
TBD
7. SUBCONTRACTOR
a. NAME, ADDRESS, AND ZIP CODE
b. CAGE
CODE
c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)
8. ACTUAL PERFORMANCE
a. LOCATION See Item 13
b. CAGE
CODE
c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)
9. GENERAL IDENTIFICATION OF THIS PROCUREMENT
Provide Information Technology web, database, and application development support and end-user training services to NAVSOC.
Period of Performance: 1 July 2011 to 30 June 2012
10. THIS CONTRACT WILL REQUIRE
ACCESS TO:
YE
S
NO 11. IN PERFORMING THIS CONTRACT, THE
CONTRACTOR WILL:
YES NO
a. COMMUNICATIONS SECURITY (COMSEC)
INFORMATION
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER
CONTRACTOR’S FACILITY OR A GOVERNMENT ACTIVITY
b. RESTRICTED DATA
b. RECEIVE CLASSIFIED DOCUMENTS ONLY
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION
c. RECEIVE AND GENERATE CLASSIFIED MATERIAL
d. FORMERLY RESTRICTED DATA
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE
e. INTELLIGENCE INFORMATION e. PERFORM SERVICES ONLY
(1) Sensitive Compartmented Information (SCI)
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUT SIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES
(2) Non-SCI
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL
INFORMATION CENTER (DTIC) OR OTHER SECONDARY
DISTRIBUTION CENTER
f. SPECIAL ACCESS INFORMATION
h. REQUIRE A COMSEC ACCOUNT
g. NATO INFORMATION
i. HAVE TEMPEST REQUIREMENTS
h. FOREIGN GOVERNMENT INFORMATION
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
i. LIMITED DISSEMINATION INFORMATION X k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVIC E
j. FOR OFFICIAL USE ONLY INFORMATION WILL BE HANDLED IAW FOUO Addendum l. OTHER (Specify ) Access to all USSOCOM facilities requires contractors to possess a minimum of a secret clearance.
X
k. OTHER (Specify)
DD Form 254, DEC 1999 PREVIOUS EDITION IS OBSOLETE
12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the Industrial Security Manual or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for approval prior to release. Direct Through (Specify)
Requests must be forwarded through the certifying official (block 16), USSOCOM Office of Public Affairs (SOCS-PA), and the Contracting Officer
To the Directorate for Freedom of Information and Security Review, Office of the Assistant Secretary of Defense (Public Affairs)* for review.
* In the case of non-DoD User Agencies, requests for disclosure shall be submitted to that agency
13. SECURITY GUIDANCE. The security classification guidance needed for this classified effort is identified below. If any difficulty is encountered in applying this guidance, or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes. The contractor may also challenge guidance or the classification assigned to any information or material furnished or generated under this contract; and may submit questions for interpretation of the guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Add additional pages as needed to provide complete guidance.)
While performing duties within HQ USSOCOM, AFSOC, NSWC, NSWG2, MARSOC, JSOC, USASOC, SOCCENT, SOCEUR, SOCSOUTH, SOCAFRICA, SOCKOR and SOCJFCOM owned and operated facilities, the contractor must also adhere to all service/component command/local security directives, regulations, and standard operating procedures at different contract performance locations. The Program Manager listed in block 16 will provide a copy of all applicable security directives for this contract. Appropriate local service/component command security directives, regulations, and standard operating procedures will be provided by the requiring agency (normally through the Performance Monitor or component command COR). Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified information (furnished or generated to the source from which received unless retention or other disposition instructions are authorized in writing by the USSOCOM Government Contracting Agency/Activity. Furthermore, the contractor will account for and return to the appropriate issuing office, all identification badges and/or entry passes/vehicle decals issued to contractor personnel upon completion or termination of the classified contract, termination of employment, or suspension of classified clearance or access of any contractor employee.
Ref 8 a continue:
a. Naval Special Warfare Command b. N/A c. Commander, Naval Special Warfare Command 2000 Trident Way 2000 Trident Way San Diego, CA 92155 San Diego, CA 92155
a. Naval Special Warfare Group Two b. N/A c. Naval Special Warfare Group Two 1300 Helicopter Road Security Manager Norfolk, VA 23521 1300 Helicopter Way Bldg 3854 Norfolk, VA 23521-2944
Ref 10f: SAP processing associated with this effort will be conducted in facilities specifically approved for SAP processing by the USSOCOM SAPCO or equivalent component-level SAP Coordination Office (SAPCOORD). Contact the appropriate servicing SAPCO for approved SAP facilities locations. SAP activities are governed by Revision 1 Department of Defense Overprint to the National Industrial Security Program Operating Manual Supplement, 1 Apr 04, USSOCOM Manual 380-2 and applicable program security classification and procedures guides. USSOCOM and Component-managed SAPFs and SAP Temporary Secure Working Areas (TSWA) are governed by JAFAN 6/9. Access to SAP information requires employees undergo additional personnel security screening and meet the requirements of DoD SAP-accessing directives and policies. SAP inspections and security oversight while in USSOCOM or Component-managed facilities are under the cognizance of the USSOCOM or Component SAPCOORD, as appropriate. Additional SAP security requirements may apply
X at non HQ USSOCOM locations/facilities based on service/component command requirements. The Performance Monitor or component command COR at these locations/facilities will provide specific and additional guidance. SAP inspections conducted at approved contractor facilities are under the security oversight of the Defense Security Service (DSS) unless officially relieved of their oversight responsibilities.
Ref 10j: FOUO information/provided under this contract shall be safeguard as specified in the attachment, Protecting for Official Use Only (FOUO) Information.
Ref 10k: ACCM information is governed by DoD 5200.1-R, “Information Security Program,” Chapter 6, Section 8, “Alternative Compensatory Control Measures (ACCM),” and OSD/C3I Memorandum, 18 April 2003, “Revised Alternative Compensatory Control Measures (ACCM) Guidance”; Focal Point Program information is governed by CJCS Manual 3213.02B, “Focal Point Program Procedures”, and supporting documentation for each Focal Point sub-system, including security classification guides, program security plans, and governing directives. Inspections of ACCM information in USSOCOM and/or each Military Service Component (AFSOC, NSWC, NSWG2, USASOC, MARSOC, SOCSOUTH, and SOCKOR) facilities are under the auspices of the respective Command or Component FPPCO. Additional ACCM requirements may be required at non USSOCOM locations/facilities (based on service/command requirements). The Performance Monitor or component command COR at these locations/facilities will provide specific information.
14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to ISM requirements, are established for this contract. YES NO
(If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement, which identifies the additional requirements. Provide a copy of the requirements to the Cognizant Security Office. Use Item 13 if additional space is needed.)
While performing at Military Service/Component Command (USSOCOM, AFSOC, NSWC, NSWG2, MARSOC, or USASOC) owned and/or operated locations/facilities, the contractor will adhere to the respective Military Service/Component Command: Information Security Program, ADP and DoDIIS Programs, Physical Security Program, Industrial Security Program, and SCI/SAP Program (if applicable). Appropriate local service/component command security directives, regulations, and standard operating procedures will be provided by the requiring agency (normally through the Performance Monitor or component command COR) at these locations/facilities.
Prior approval of the contracting activity is required for subcontracting. Access to intelligence information requires special briefings and a U.S. Government clearance at the appropriate level.
Training Requirement: Contractors performing on this contract at military installations are required to conduct command and unit specific security training (OPSEC, EMSEC, At/FP, Etc.). This training will be provided by the responsible military organization.
IA requirements: Specific Information Assurance requirements may be mandated and are authorized by the responsible command/unit where primary performance location is identified.
Contractor will be authorized to courier classified information up to the “TS/SCI” level in performance of official duties upon approval of and designation by the COR, PM, KO, and/ SSO.
AFSOC Requirement:
Provide the information requested by the Notification of Government Security Activity clause and Visitor Group Security Agreements Clause, AFFARS 5352.204-9000, to the Servicing Security Activity indicated in Item 13 above. Refer to the contract document for these clauses. The visitor group will operate per DoD 5200.1-R, AFI 31-401, AFI 31-601, Hurlburt Field supplements and unit security program operating instructions, plans and procedures.
USASOC Requirement (Ref 10f): Defense contractor personnel who require access to Army Special Access Program (SAP) information, as defined by AR 380-381, shall agree to undergo random counterintelligence scope polygraph examinations, when requested by proper authority, to determine suitability for receiving and/or maintaining access to SAP information.
Contractors shall certify prior to contract award, or subsequent to award, but prior to the commencement of duties for new employees, that all personnel so identified have freely consented to such examination.
1. Contractor personnel who withdraw their consent at any time during their period of access shall be immediately removed from access to SAP information, and such action shall be promptly reported to the contracting officer or such party as the contracting officer may direct.
2. Additional information about polygraphs and DD Form 254 for SAPs is contained in AR 380-381, including the requirement for distribution of a copy of all DD Form 254 in support of SAP contracts to be forwarded to HQDA (DACS-DMP), Room 2A528, 200 Army Pentagon, Washington, DC 20310-0200 and HQ USSOCOM (SOAL-SP), 7701 Tampa Point Blvd, MacDill AFB, FL 33621-5323.
3. Additionally, any requirement that contractor personnel shall undergo polygraph examinations needs to be clearly stated in the contract document.
All security violations/incidents will be reported to the responsible cognizant security office, facility security officer, contracting officer, and primary contract officer representative (PCOR) for the contract.
15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the Cognizant Security Office. YES NO
(If Yes, explain and identify specific areas or elements carved out and the activity responsible for inspections. Use Item 13 if additional space is needed.)
Defense Security Service is relieved of inspection responsibility within USSOCOM and/or each Military Service Component ( AFSOC, NSWC, NSWG2, MARSOC, and USASOC) owned and operated locations/facilities. Classified contract activities and performance at each
Military Service’s locations/facilities are governed by applicable service/component command/local security directives, regulations, and standard operating procedures and are the responsibility of the respective Security Officers. Collateral contractor classified operations conducted within military installations/facilities will be under the Security Cognizance of the services respective Security Management Office. If applicable, SCI/SAP/ACCM portions of the contract fall under the purview of the location/facility SSO/SAPCO/FPCO.
Additional SCI/SAP/ACCM requirements/responsibilities may exist at different contract performance locations. The Performance Monitor or component command COR at these locations/facilities will provide specific information.
16. CERTIFICATION AND SIGNATURE. Security require ments stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.
a. TYPED NAME OF CERTIFYING
OFFICIAL
Gregory J Brauer
b. TITLE J6 Contract Manager
c. TELEPHONE (Include Area Code)
(813) 826-7086
d. ADDRESS (Include Zip Code) 17. REQUIRED DISTRIBUTION
HQ USSOCOM / J65
7701 Tampa Point BLVD MacDill AFB FL 33621-5323
a. CONTRACTOR
b. SUBCONTRACTOR
c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR
e. SIGNATURE D. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION
E. ADMINISTRATIVE CONTRACTING OFFICER
F. OTHERS AS NECESSARY USSOCOM SSO/SAPCO
DD FORM 254 (BACK), DEC 1999
PROTECTING "FOR OFFICIAL USE ONLY" (FOUO) INFORMATI ON
1. GENERAL:
a. The "For Official Use Only" (FOUO) marking is assigned to information at the time of its creation in a DoD
User Agency. It is not authorized as a substitute for a security classification marking but is used on official government information that may be withheld from the public under exemptions 2 through 9 of the Freedom of Information Act (FOI A).
b. Other non-security markings, such as "Limited Official Use" and "Official Use Only" are used by non-DoD
User Agencies for the same type of information and should be safeguarded and handled in accordance with instruction received from such agencies to the extent that such may be withheld from the public under exemptions 2 through 9 of the FOIA and marked in accordance with 2.c below. As used herein, “FOUO” markings shall only be applied to information described in 5 USC § 552(b), and shall also indicate the applicable FOIA Exemption. Contractor shall apply this Attachment 4A in a manner consistent with its policies implementing Section 15 of the Federal Advisory Committee Act, 5 USC App. § 15 (1997).
c. Use of the above markings does not mean that the information cannot be released to the public under FOIA, only that it must be reviewed by the Government prior to its release to determine whether a significant and legitimate government purpose is served by withholding the information or portions of it.
2. MARKINGS:
a. An unclassified document containing FOUO information will be marked "For Official Use Only" at the bottom of the front cover (if any), on the first page, on each page containing FOUO information, on the back page, and on the outside of the back cover (if any). No portion markings will be shown.
b. Within a classified document, an individual page that contains both FOUO and classified information will be marked at the top and bottom with the highest security classification of information appearing on the page. If an individual portion contains FOUO information but no classified information, the portion will be marked, "FOUO."
c. Any "'For Official Use Only" information released to a contractor by a DoD User Agency is required to be marked with the following statement prior to transfer.
“This document contains information EXEMPT FROM MANDATORY DISCLOSURE UNDER THE
FOIA. Exemptions apply.”
d. Removal of the "For Official Use Only" marking can only be accomplished by the originator or other competent authority. When the "For Official Use Only" status is terminated, all known holders will be notified to the extent practical.
3. DISSEMINATION: Contractors may disseminate "For Official Use Only" information to their employees and subcontractors who have a need for the information in connection with a classified contract. Contractors must ensure employees and subcontractors are aware of the special handling instructions detailed below.
4. STORAGE: During working hours, "For Official Use Only" information shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During nonworking hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during nonworking hours.
When such internal security control is not exercised, locked buildings or rooms will provide adequate after- hours protection or the material can be stored in locked receptacles such as file cabinets, desks, or bookcases.
5. TRANSMISSION: "For Official Use Only" information may be sent via first-class mail or parcel post. Bulky shipments may be sent by fourth-class mail. DoD components, officials of DoD components, and authorized DoD contractors, consultants, and grantees send FOUO information to each other to conduct official DoD business. Tell recipients the status of such information, and send the material in a way that prevents unauthorized public disclosure. Make sure documents that transmit FOUO material call attention to any FOUO attachments. Normally, you may send FOUO records over facsimile equipment. To prevent unauthorized disclosure, consider attaching special cover sheets, the location of sending and receiving machines, and whether authorized personnel are around to receive FOUO information. FOUO information may be passed to officials in other departments and agencies of the executive and judicial branches to fulfill a government function. Mark the records "For Official Use Only" and tell the recipient the information is exempt from public disclosure under the FOIA and requires special handling.
Electronic transmission of FOUO information, e.g., voice, data or facsimile, and e-mail, shall be by approved secure communications systems or systems utilizing other protective measures such as Public Key Infrastructure (PKI), whenever practical.
6. DISPOSITION: When no longer needed, FOUO information must be shredded.
7. UNAUTHORIZED DISCLOSURE: Unauthorized disclosure of "For Official Use Only" information does not constitute a security violation but the releasing agency should be informed of any unauthorized disclosure. The unauthorized disclosure of FOUO information protected by the Privacy Act may result in criminal sanctions and disciplinary action may be taken against those responsible.
File details come from the government source that posted it. Updated .