Atch_1_DD254_REV_1_16_Apr_18.pdf
PDF 341 KB Posted
- Attached to
- POTFF Federal contract opportunity
- Solicitation number
- H92222-18-R-0010
- Issued by
- United States Special Operations Command
About this file
Attachment 1 DD254 Rev 1
View the file
Other files for this federal contract opportunity
Show all 24
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Page 1 of 10 Pages
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(Please read Instructions BEFORE completing this application.) (The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires October 31, 2020
The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED
(See instructions.)
TOP SECRET
b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/MATERIAL
REQUIRED AT CONTRACTOR FACILITY
NONE
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.) 3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. PRIME CONTRACT NUMBER (See instructions.)
a. ORIGINAL (Complete date in all cases.)
DATE (YYYYMMDD)
20180411
b. SUBCONTRACT NUMBER
SEE CONTINUATION PAGE
b. REVISED (Supersedes all previous specifications)
REVISION NO. DATE (YYYYMMDD)
c. SOLICITATION OR OTHER NUMBER H92222-18-R-0010
DUE DATE
05/01/2018 c. FINAL (Complete Item 5 in all cases.)
DATE (YYYYMMDD)
4. IS THIS A FOLLOW-ON CONTRACT? NO YES. If Yes, complete the following:
Classified material received or generated under ________________(Preceding Contract Number) is transferred to this follow-on contract.
5. IS THIS A FINAL DD FORM 254? NO YES. If Yes, complete the following:
In response to the contractor’s request dated ___________________, retention of the classified is authorized for the period of:______________________________________.
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code.)
a. NAME, ADDRESS, AND ZIP CODE
TBD
b. CAGE CODE
TBD
c. COGNIZANT SECURITY OFFICE (CSO) (Name, Address, ZIP Code, Telephone)
TBD
7. SUBCONTRACTOR(S)
a. NAME, ADDRESS, AND ZIP CODE
SEE CONTINUATION PAGE
b. CAGE CODE c. COGNIZANT SECURITY OFFICE (CSO) (Name, Address, ZIP Code, Telephone)
8. ACTUAL PERFORMANCE
a. LOCATION(S) (For actual performance, see instructions)
SEE CONTINUATION PAGE
b. CAGE CODE c. COGNIZANT SECURITY OFFICE (CSO) (Name, Address, ZIP Code, Telephone)
9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT
The contractor shall provide all personnel and services necessary to perform Preservation of the Force and Family (POTFF) Resiliency and Human Performance Programs support.
Period of Performance is from 09 October 2018 – 08 October 2026 (Annual DD FM 254 Review Required)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION
b. RESTRICTED DATA g. NORTH ATLANTIC TREATY ORGANIZATION (NATO) INFORMATION
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.)
h. FOREIGN GOVERNMENT INFORMATION
d. FORMERLY RESTRICTED DATA i. ALTERNATIVE COMPENSATORY CONTROL MEASURES (ACCM)
INFORMATION
e. NATIONAL INTELLIGENCE INFORMATION: j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)
(1) Sensitive Compartmented Information (SCI)
k. OTHER (Specify) (See instructions.)
SEE CONTINUATION PAGE(2) Non-SCI
DD FORM 254, NOV 2017 PREVIOUS EDITION IS OBSOLETE.
X 1 20180416 mailto:whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil
Page 2 of 10 Pages
DD FORM 254 (BACK), NOV 2017
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER
CONTRACTOR'S FACILITY OR A GOVERNMENT ACTIVITY (Applicable only if there is no access or storage required at contractor facility. See instructions.)
h. REQUIRE A COMSEC ACCOUNT
b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY i. HAVE A TEMPEST REQUIREMENT
c. RECEIVE, STORE, AND GENERATE CLASSIFIED INFORMATION OR
MATERIAL
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE (DCS)
e. PERFORM SERVICES ONLY l. RECEIVE, STORE, OR GENERATE CONTROLLED
UNCLASSIFIED INFORMATION (CUI).
(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES m. OTHER (Specify) (See instructions)
SEE CONTINUATION PAGE
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL
INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION
CENTER
12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by the appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified
DIRECT THROUGH (Specify) PUBLIC RELEASE AUTHORITY Requests must be forwarded through the responsible Contracting Official (Item 16), Certifying Official (Item 17) and the HQ USSOCOM Special Operations Communication Office (SOCS-SOCO) prior to public release.
13. SECURITY GUIDANCE. The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein.)
SEE CONTINUATION PAGE
14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
No Yes (If Yes, identify the pertinent contractual clauses in the contract document itself or provide the appropriate statement which identifies the additional Requirements. Provide a copy of the requirements to the CSO. Use Item 13 if additional space is needed.)
SEE CONTINUATION PAGE
15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the CSO. No Yes (If Yes, explain and identify specific areas and government activity responsible for inspections. Use Item 13 if additional space is needed.)
SEE CONTINUATION PAGE
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
a. GCA NAME
HQ USSOCOM/SOF AT&L-KH
b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See instructions.)
H92222
c. ADDRESS (Include ZIP Code.)
HQ USSOCOM/SOF AT&L-KH
7701 Tampa Point Blvd MacDill AFB, FL 33621
d. POC NAME (See instructions.)
Jace Anders
e. POC TELEPHONE (Include Area Code.)
(813) 826-7247
f. EMAIL ADDRESS (See instructions.)
Jace.Anders@socom.mil
17. CERTIFICATION AND SIGNATURES. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.
a. TYPED NAME OF CERTIFYING OFFICIAL
(Last, First, Middle Initial) (See instructions.)
Spurling, Alicia N.
b. TITLE Primary Contracting Officer’s Representative
c. ADDRESS (Include ZIP Code.)
HQ USSOCOM/SOF AT&L-PEO-SV
7701 Tampa Point Blvd MacDill AFB, FL 33621d. AAC OF THE CONTRACTING OFFICE
(See instructions.)
N/A
e. CAGE CODE OF THE PRIME CONTRACTOR (See instructions.)
N/A
f. TELEPHONE (Include Area Code.)
(813) 826-1851
g. EMAIL ADDRESS (See instructions.)
alicia.spurling@socom.mil
h. DATE
20180416
i. SIGNATURE
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICAL
a. CONTRACTOR f. OTHERS AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)
b. SUBCONTRACTOR HQ USSOCOM SMO
c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR
b. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION
e. ADMINISTRATIVE CONTRACTING OFFICER
TBD
CONTINUATION PAGE
Page 3 of 10 Pages
DD FORM 254 (BACK), NOV 2017
13. SECURITY GUIDANCE (Continued) The Contracting Officer’s Representative/Program Manager listed in Item 17 will provide a copy of all applicable security directives for this contract. Appropriate applicable HQ USSOCOM security directives, regulations, and standard operating procedures will be provided by the requiring agency (normally through the Performance Monitor or Component/Theater Special Operations Command COR/PM).
Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified information (furnished or generated) to the source from which received unless retention or other disposition instructions are authorized in writing by the USSOCOM Government Contracting Agency/Activity. Furthermore, the contractor will account for and return all Common Access Cards (CACs) to Contracting Officer's Representative, Program Manager, or Trusted Agent upon completion or termination of the classified contract, termination of employment, or suspension of classified clearance or access of any contractor employee. Security badges, installation entry passes/vehicle decals issued to contractor personnel will be returned to the appropriate issuing office as required.
THIS DD FORM 254 IS ESTABLISHED FOR THE BASE CONTRACT. INDIVIDUAL TASK ORDERS WILL IDENTIFY TASK ORDER SPECIFIC SECURITY REQUIREMENTS AND INCLUDE A TASK ORDER SPECIFIC DD FORM 254.
SEE CONTINUATION PAGE
This DD Form 254 is tentatively approved. Upon company selection, but prior to award and any classified release, this DD Form 254 with all pertinent information inserted in appropriate sections will be submitted to SMO for final review and approval.
Additional persons assisting with completion of form (signatures and titles)
Reviewed/Tentatively Approved HQ USSOCOM Industrial Security 16 April 2018
14. ADDITIONAL SECURITY REQUIREMENTS. (Continued) While performing duties at USSOCOM, Component (JSOC, AFSOC, NSWC, MARSOC, or USASOC), or Theater Special Operation Command (SOCNORTH, SOCCENT, SOCEUR, SOCPAC, SOCSOUTH, SOCAFRICA, or SOCKOR) owned and operated facilities, the contractor will adhere to the applicable Information Security Program, ADP and DODIIS Programs, Physical Security Program, Industrial Security Program, and SCI/SAP Program (if applicable). Prior approval of the contracting activity is required for subcontracting. Access to intelligence information requires special briefings and a U.S. Government clearance at the appropriate level.
Training Requirement: Contractors performing on this contract at military installations are required to conduct command and unit specific security training (Initial/Refresher INFOSEC, OPSEC, EMSEC, AT/FP, Intelligence Oversight, etc.). This training will be provided by the responsible military organization.
IA requirements: Specific Information Assurance requirements may be mandated and are authorized by the responsible command/unit where primary performance location is identified.
All security incidents/violations will be reported to the responsible cognizant security office, facility security officer, contracting officer, and primary contracting officer representative (PCOR/COR) for the contract.
15. INSPECTIONS. (Continued) Defense Security Service is relieved of all inspection responsibility within USSOCOM, Component (JSOC, AFSOC, NSWC, MARSOC, or USASOC), Theater Special Operation Command (SOCNORTH, SOCCENT, SOCEUR, SOCPAC, SOCSOUTH, SOCAFRICA, SOCKOR) and other U.S. Government owned and operated facilities but retains responsibility for all non-SCI classified material released to or developed under the contract and held within the contractor's facility.
Continuation of Page 4 of 10
Ref 2b: Subcontracting of this effort must be approved by HQ USSOCOM prior to award. Forward requests and draft Subcontract DD FM 254s to the Certifying Official identified in Item 16 and USSOCOM Industrial Security (IndustrialSecurity@socom.mil).
(IAW USSOCOM R 380-9, Industrial Security, please allow 10 duty days for review/approval).
Ref 7: See guidance in Ref 2b.
Ref 8a: Additional performance locations, both CONUS and OCONUS, will be required based on specific requirements of individual task orders.
Ref 8: Performance Locations (Continued):
a. USSOCOM b. N/A c. HQ USSOCOM SOCS-Z-SM
7701 Tampa Point Blvd MacDill AFB, FL 33621-5323
a. USASOC b. NA c. Commander, USASOC AOIN-SOD 2929 Desert Storm Drive, Stop A Fort Bragg, NC 28310
a. JSOC b. NA c. HQ JSOC
ATTN: JSOC-SD
P.O. Box 70239 Fort Bragg, NC 28307
a. AFSOC b. N/A c. 1st Special Ops Wing IP Office 212 Lukasik Avenue, Ste. 230 Hurlburt Field, FL 32544
a. NSWC b. N/A c. Commanding Officer, NSW 2000 Trident Way San Diego, CA 92155
a. MARSOC b. N/A c. Commander, MARSOC Bldg RR 400 Rifle Range Rd Camp Lejeune, NC 28542-0116
a. SOCCENT b. N/A c. SOCCENT Security 7561 Blackbird St, Building 1043 MacDill AFB, FL 33621-5101
a. SOCKOR b. N/A c. SOCKOR Security USAG-Yongsan BLDG 1262 Galwall-dong 104 Gate #17 Camp Kim, Yongsan-gu, Seoul, Korea 140-012
a. SOCSOUTH b. N/A c. SOCSOUTH Security 29401 125TH Ave Building 600 Homestead ARB, FL 33039
Item 13 Security Guidance. (Continued):
Ref 10e(1): See attached SCI Addendum.
Ref 10f: See attached SAP Addendum.
Ref 10i. Alternative Compensatory Control Measures (ACCM) Program information is governed by DoD M 5200.01-V3, DoD Information Security Program: Protection of Classified Information, Enclosure 2, Section 18; CJCS Manual 3213.02D, Joint Staff Alternative Compensatory Control Measures Program Management Manual, and supporting documentation for each ACCM sub-system, including security classification guides, program security plans, and governing directives. Inspections of ACCM information in USSOCOM, Component (JSOC, AFSOC, NSWC, MARSOC, or USASOC), or Theater Special Operation Command (SOCNORTH, SOCAFRICA, mailto:IndustrialSecurity@socom.mil
Continuation of Page 5 of 10
SOCCENT, SOCEUR, SOCPAC, SOCSOUTH, or SOCKOR) owned and operated facilities are under the auspices of the respective Command or Component ACCM Coordinator/ACCM Program Control Officer (ACCM Coord/ACCM PCO). If applicable, ACCM material maintained by the Contractor within their facility must be afforded protection commensurate with DOD requirements and strictly controlled based on need-to-know and required briefings. DSS personnel conducting inspections of the Contractor must be briefed on to the specific program by the appropriate government ACCM Coord/ACCM PCO responsible for the material prior to being granted access.
Ref 10j: Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as specified in the FOUO Addendum included with this specification.
Ref 10k: NIPRNET/SIPRNET/JIANT/JWICS access required at government facilities only.
Ref 11a: Contractor performance is restricted to the government Performance Locations identified in Item 8. Government agency or activity will provide security classification guidance for performance of this contract. Submit visit request to COR and/or Security Management Office for need-to-know verification.
Ref 11f: Classified performance in locations other than the United States, Puerto Rico, U.S. Possessions and Trust Territories is restricted to SOCKOR, Seoul South Korea.
Ref 11l: Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as specified in the FOUO Addendum included with this specification
Ref 11m: Access to all USSOCOM facilities requires contractors to possess a minimum of a SECRET clearance.
Ref 11m: Contractor will be authorized to courier classified information up to the SECRET in performance of official duties upon approval of and designation by the COR, PM and/or SSO.
Continuation of Page 6 of 10
SCI ADDENDUM
This supplement applies to:
Prime Contract Number: TBD Subcontract Number: N/A Delivery/Task Order Number: TBD Expiration Date: 08 October 2026
The following controls will apply to Sensitive Compartmented Information (SCI) provided under this contract.
1. Item 10e (2): Security clearances for contractors working within SCIF spaces must be adjudicated meeting Intelligence Community Policy Guidance (ICPG) 704.1, 704.2, 704.3, 704.4, 704.5 eligibility requirements. Prior approval of the contracting activity is required for sub-contracting. Access to intelligence information requires special briefings and a final U.S. Government clearance at the appropriate level.
2. Item 13: Department of Defense (DOD) Manual 5105.21, Volumes 1-3, Intelligence Community Policy Guidance (ICPG) 704.1, 704.2, 704.3, 704.4, 704.5, Intelligence Community Standard (ICS) 705-1&2 including the Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities (IC Tech Spec-for ICD/ICS 705, and Headquarters, United States Special Operations Command (HQ USSOCOM) 380-6, provide the necessary guidance for physical and information security measures and are part of the SCI security specifications for the contract.
3. Item 13: Inquiries pertaining to classification guidance will be directed to the responsible USSOCOM Contracting Officer’s Representative/Program Manager/Contract Monitor (Alicia Spurling, 813-826-7247)
4. Item 13: All SCI furnished to the contractor in support of this contract / delivery / task order remains the property of the DOD or the agency or command that releases the information. Upon termination of the contract, all furnished SCI will be returned to the HQ USSOCOM Special Security Office (SSO) or the prime contractor.
5. Item 14: This contract / delivery / task order requires that FOUR (4) contract billets be established in order to fulfill the contractual obligations incurred. Access will be granted by the government agency. Upon completion or cancellation of the contract, the Contractor SSO (CSSO) will debrief or notify the HQ USSOCOM SSO to debrief all personnel not required for contract closeout and those billets will be disestablished.
6. Item 14: Names of contractor personnel requiring access to SCI and justification for SCI billets will be submitted to HQ USSOCOM SSO after contract monitor coordination. Billet justifications will include the contract statement of work. If a Single-Scope Background (SSBI) Investigation has not been completed upon approval of billets by the HQ USSOCOM SSO, the CSSO will submit necessary forms to the Personnel Security Management Office for Industry (PSMO-I) for an SSBI. An SSBI and access to SCI will comply with the National Industrial Security Program Manual. Upon completion of the SSBI, a nomination for SCI access will be submitted to HQ USSOCOM SSO.
7. Item 14: The CSSO will advise HQ USSOCOM SSO, through the contract monitor, upon reassignment of personnel to other duties not associated with this contract.
8. Item 14: The CSSO must coordinate with the SCI contract monitor before subcontracting any portion of SCI efforts involved in the contract. A separate DD Form 254 for the subcontractor will be processed and a copy provided to HQ USSOCOM SSO.
9. Item 14: The contractor will not use references to SCI access, even by unclassified acronyms, in advertisements, promotional efforts, or recruitment of employees.
10. Item 14: All SCI work will be performed at the Performance Locations identified in Item 8 and in subsequent Task Orders.
11. Item 15: HQ USSOCOM SSO has exclusive security responsibility for all SCI released to the contractor or developed under this contract. Defense Intelligence Agency and HQ SOCOM SSO retain authority for all inspections of the contractor to ensure compliance with SCI directives, regulations, and instructions.
Continuation of Page 7 of 10
12. In accordance with DODM 5105.21 Volume 1-3, the following activity is designated User Agency Special Security Office for SCI requirement:
HQ USSOCOM
Special Security Office 7701 Tampa Point Boulevard Telephone: DSN 299-1876 MacDill AFB, Florida 33621-5323 Commercial: (813) 826-1876
Reviewed/Approved HQ USSOCOM SSO Industrial Security
Continuation of Page 8 of 10
PROTECTING SPECIAL ACCESS PROGRAM (SAP) INFORMATION
(2 January 2018 edition)
Special Access Program (SAP) discussion, storage, and processing associated with this effort will be conducted in SAP Facilities (SAPF) specifically approved, in writing, by the USSOCOM SAPCO or designated USSOCOM Program Security Officer (PSO). Contact the individual in Block 16 for approved SAPF locations.
SAP activities are governed by Revision 1, of the Department of Defense Overprint to the National Industrial Security Program Operating Manual (NISPOM) Supplement; DOD Manual 5200.01 (DOD Information Security Program) Volumes 1-4, DOD Directive 5205.07 (Special Access Program Policy); DOD Manual 5205.07 (DOD Special Access Program Security Manual), Volumes 1-4; DOD Instruction 5205.11, (Joint SAP Implementation Guide (JSIG)); USSOCOM Manual 380-2 (SAP Security Guide); USSOCOM Manual 380-7 (USSOCOM Arms Control Readiness Inspection Program) and applicable program security classification guides and subsequent versions. Applicable documents will be provided to the contractor by the PSO under separate cover.
Access to SAP information requires employees to undergo additional personnel security screening and meet the requirements of DoD SAP accessing directives and policies in accordance with DODM 5205.07, Volume 2. The individual must meet applicable eligibility requirements and possess a final Secret or Top Secret security clearance depending on the level of access required in performance of this contract. Program Access Requests (PAR) for contractor personnel must be submitted by the Contractor’s Program Security Officer (CPSO) to the PSO for approval by the designated Access Approval Authority (AAA). Personnel approved for access will receive a program indoctrination briefing and must sign a SAP Indoctrination Agreement (PIA) prior to receiving access to program information or material. The CPSO will maintain the signed PIA and forward a copy to the PSO for entry into the appropriate database system.
SAP inspections and security oversight while in USSOCOM or Component government facilities are under the cognizance of the USSOCOM PSO or SAPCO representative, as appropriate. Additional Component SAP security requirements may apply for activities conducted at Service Component or Sub-unified command locations. The Performance Monitor or component command COR at these locations/facilities will provide specific or additional guidance. SAP reviews conducted at contractor facilities are under the security oversight of the Defense Security Service (DSS) unless officially relieved of oversight responsibilities.
OPSEC-sensitive or classified communication will be conducted via PSO-approved secure channels from within the SAPF. Transmission of documents via secure facsimile between terminals within SAPFs may be approved by the PSO. Only the U.S. Postal Service Register or Certified mail, if authorized, will be used to mail program material unless an alternate method is approved by the PSO. Briefed personnel are authorized to courier classified information within the continental United States with written approval from the CPSO or PSO. Two (program briefed) personnel are required to courier Top Secret material unless prior approval is obtained from the PSO. Couriers will be in the possession of PSO-issued courier authorization letters prior to travel. All material, to be mailed or carried, will be wrapped and transmitted in accordance with DODM 5205.07, Volume 1.
Prior to processing SAP information on any Automated Information System (AIS), the contractor will provide the PSO with a System Security Plan (SSP) and other documentation required in JSIG for Assessment & Authorization (A&A) from the Authorizing Official (AO), or subsequent policy. The PSO will issue program specific Security Authorization following verification of the A&A process. USSOCOM Special Access Program (SAP) Policy Memorandum: Removable Media and Two-Person Integrity Control Policy is applicable for this contract.
Destruction of program material will be conducted only by program indoctrinated personnel using destruction equipment and procedures approved by the PSO. A single person may destroy non-accountable classified material. Accountable material must be destroyed, and documented, by two program cleared individuals.
The PSO will be advised of any reports which affect the baseline facility clearance or any incident that has an adverse impact on a personnel security clearance. All briefed personnel are required to report any information that could have an impact on their ability to protect classified information. Reportable items include: foreign travel, contacts, or associations; criminal, civil, financial, or mental health issues; and changes in personal status such as marriage, divorce, or employment. CPSOs are reminded of their responsibilities to diligently report any significant action or any change in an employee’s eligibility to the PSO immediately.
Per DOD Manual 5205.07 Volume 1, Encl. 11, Sec 3. : “Any (contractual) relationship with a prospective subcontractor requires prior approval by the PSO.” All security requirements levied upon the prime contractor will “flow-down” to the subcontractor. SAP access and other requirements must be pre-coordinated and approved by the PSO prior to implementation.
Continuation of Page 9 of 10
IAW DODM 5200.01, Vol 3, Encl. 6, any security incident involving the potential loss, compromise, or suspected compromise of classified information must be reported to the PSO immediately using appropriate secure channels. Security infractions will be documented in the individuals personal security file and made available for review during PSO visits.
Reviewed/Approved Chief, HQ USSOCOM SAPCO
Continuation of Page 10 of 10
PROTECTING "FOR OFFICIAL USE ONLY" (FOUO) INFORMATION
(Updated June 2014)
1. GENERAL:
a. The "For Official Use Only" (FOUO) marking is assigned to information at the ti.me of its creation in a DOD User Agency. It is not authorized as a substitute for a security classification marking but is used on official government information that may be withheld from the public under exemptions 2 through 9 of the Freedom of Information Act (FOIA).
b. Other non-security markings, such as "Limited Official Use" and "Official Use Only" are used by non-DOD User Agencies for the same type of information and should be safeguarded and handled in accordance with instruction received from such agencies.
c. Use of the above markings does not mean that the information cannot be released to the public under FOIA, only that it must be reviewed by the Government prior to its release to determine whether a significant and legitimate government purpose is served by withholding the information or portions of it
2. MARKINGS:
a. Unclassified documents containing FOUO information will be marked "UNCLASSIFIED//For Official Use Only" or "U//FOUO" at the bottom of the front cover (if any), on the first page, on each page containing FOUO information , on the back page, and on the outside of the back cover (if any). Each paragraph containing FOUO information shall be marked as such.
b. Within a classified document, an individual page that contains both FOUO and classified information will be marked at the top and bottom with the highest security classification of information appearing on the page. Individual paragraphs shall be marked at the appropriate level be it classified, unclassified, or FOUO. An individual page that ONLY contains FOUO and unclassified information shall be marked “FOR OFFICIAL USE ONLY” or the highest classification of the entire document at the top and bottom of the page.
If an individual portion contains FOUO information but no classified information, the portion will be marked, "FOUO."
c. Mark other records, such as computer print outs, photographs, films, tapes, or slides "FOR OFFICIAL USE ONLY" so that the viewer knows the record contains FOUO information.
d. Removal of the "For Official Use Only" marking can only be accomplished by the originator or other competent authority. When the "For Official Use Only" status is terminated, all known holders will be notified to the extent practical.
3. DISSEMINATION: "For Official Use Only" information may be disseminated between officials of DOD Components, DOD contractors, consultants, and grantees to conduct official business for the DOD. FOUO information may also be passed to officials in other departments and agencies of the executive and judicial branches to fulfill a government function. Recipients shall ·be made aware of the special handling instructions detailed in this document and that it's exempt from public disclosure under the FOIA utilizing the following statement: "This document contains information EXEMPT FROM MANDATORY DISCLOSURE UNDER THE FOIA".
4. STORAGE: During working hours, "For Official Use Only" information shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During nonworking hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during nonworking hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after- hours protection or the material can be stored in locked receptacles such as file cabinets, desks, or bookcases.
5. TRANSMISSION: "For Official Use Only" information may be sent in the following ways:
a. Mail - FOUO may be sent via first-class mail or parcel post. Bulky shipments may be sent by fourth-class mail.
b. Fax - Normally FOUO may be sent over facsimile equipment. To prevent unauthorized disclosure the following should be considered:
Use of special cover sheets, location of fax machines {both ends), and whether authorized persoru1el are around to receive FOUO information.
c. E-Mail/Websites E-mail may be used on approved secure communication systems or systems utilizing other protective measures such as Public Key Infrastructure (PKI) or transport layer security (e.g., https).
**Make sure documents/methods that transmit FOUO material call attention to any FOUO attachments. **
6. DISPOSITION: When no longer needed, FOUO information must be disposed of in a way that will preclude its disclosure to unauthorized individuals.
7. UNAUTHORIZED DISCLOSURE: Unauthorized disclosure of "For Official Use Only" information does not constitute a security violation but the releasing agency should be informed of any unauthorized disclosure. The unauthorized disclosure of FOUO information protected by the Privacy Act may result in criminal sanctions and disciplinary action may be taken against those responsible.
File details come from the government source that posted it.