DD254_(revised).pdf

PDF 100 KB Posted

Attached to
Naval Circuit Management Office Program Management Federal contract opportunity
Solicitation number
HC1028-18-R-0086
Issued by
Defense Information Systems Agency

About this file

Attachment L4 DD254 (revised)

View the file

Other files for this federal contract opportunity

Other files attached to Naval Circuit Management Office Program Management, newest first.
File Type Posted
Attachment_L1_Past_Performance_Information.docx DOCX document
Q&A_Amendment_02.docx DOCX document
HC1028-18-R-0086_RFP_Amend_02.docx DOCX document
HC1028-18-R-0086_AMD02_conformed_copy.docx DOCX document
Q&A.docx DOCX document
Attachment_L1_Past_Performance_Information.docx DOCX document
HC1028-18-R-0086__conformed_copy.docx DOCX document
HC1028-18-R-0086_RFP_Amend_01.docx DOCX document
HC1028-18-R-0086_RFP.pdf PDF
Attachment_L2-Cost_Price_Template.xlsx XLSX spreadsheet
Attachment_L4_-_DD254.pdf PDF
Attachment_L1_Past_Performance_Information.docx DOCX document
Attachment_L3_-_Question_&_Answer_Template.docx DOCX document
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Please wait...

If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.

You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.

For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.

Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.

Continuation Page:

13. SECURITY GUIDANCE. The security classification guidance needed for this classified effort is identified below. If difficulties are encountered in applying this guidance or other contributing factor indicates a need for changes in this guidance, the contractor is encouraged and authorized to submit suggested changes to improve or challenge the guidance and/or the assigned classification to information or material furnished or generated under this contract. The contractor may also submit questions for interpretation of this guidance to the official identified on this form.

Pre-award access is not required. This DD Form 254 reflects the security requirements for the contract upon awarded.

This Contract will provide life-cycle support services for NCMO provisioning including operations and maintenance services which process classified information. Actual knowledge of the generation or production of classified information is not required for performance of this contract. However, cleared personnel are required to perform tasks.

Please note, contractor personnel performing tasks on Alliant P&S contracts and are assigned duties using sensitive unclassified automated information systems (AIS) designated as ADP-I (Top Secret based upon a Single Scope Background Investigation (SSBI) or ADP-II (the minimum investigation required is a National Agency Check plus written Inquiries (NACI). Network and database management, installation and maintenance personnel having unescorted access to network equipment on the Top Secret sensitive DISN must also be cleared at the same level of access.

General Information:

All visit access requests (VARs) by contractors shall be sent via the Joint Personnel Adjudication System (JPAS) to the DISA VAR Center (JPAS SMO: DKABAA10) or appropriate SMO for the effort. The COR/TM must approve the VAR prior to sending the request to the facility being visited. Contractors must also provide a copy of the VAR to the security manager.

The COR/TM must be notified and approve the receipt and/or generation of classified information under this contract.

All classified information received and/or generated under this contract is the property of the U.S. Government regardless of proprietary claims. Upon completion or termination of this contract, the U.S. Government will be contacted for destruction or disposition instructions. Foreign Nationals will not perform on any area of the contract (classified or unclassified).

Reference Item 10a: Contractor is authorized to receive Government furnished cryptographic equipment. Access to classified COMSEC information requires a final U.S. Government clearance at the appropriate level. Further disclosure of COMSEC information by a contractor, to include subcontracting, requires prior approval of the government contracting activity. Nonaccountable COMSEC information, though not tracked in the COMSEC material control system, may still require a level or control within a document control system. Refer to NSA/CSS Manual 3-16, Control of Communications Security Material, and page E-4 for guidance

Reference Item 10e (1): This contract requires access to SCI.

All contractor SCI work and access will be at a designated government SCF Facility (SCIF)

a. The number of personnel required to have access to SCI is determined by the COR/TM and the DISA SSO.

b. The Director, Defense Intelligence Agency (DIA) and Director, Defense Information Systems Agency (DISA), as the executive agent for DIA, have exclusive security responsibility for SCI released to the contractor or developed under this contract.

c. Contractor generated or Government furnished material may not be provided to the Defense Technical Information Center. Contract generated technical reports will bear the statement ‘Not Releasable to the Defense Technical Information Center per DoD Instruction 5230.24.

d. All contractor personnel requiring access to SCI information must: be U.S. citizens, have been granted a final ICD 704 security clearance by the U.S. Government, and have been indoctrinated for the applicable compartments of SCI access prior to being given any access to such information released or generated under this contract.

e. Classified material released or generated under this contract is not releasable to foreign nationals without the expressed written permission of the Director, DISA (through the DISA SSO) and Director, DIA.

f. SCI received under this contract may not be released to subcontractors without permission of the DISA SSO.

g. The contractor and COR/TM will revalidate all SCI billets under this contract with the DISA SSO annually or when a revised DD Form 254 issued, whichever is sooner.

h. All SCI visit requests by contractors shall be forwarded to the COR/TM for approval and need-to-know certification before being sent through the DISA SSO to the facility to be visited.

i. STE terminals installed at the contractor's facilities shall be supported by a COMSEC account (of the contractor of DISA). STEs in SCI Facilities (SCIFs) require the KSV 21 Encryption Card.

If the contractor requires access to JWICS network, a NATO briefing will be required due to NATO information residing on the JWICS network.

Reference Item 10f:

a. To execute this contract, additional security requirements in addition to DoD 5220.22-M will be required. The contractor shall comply with the security provisions of these programs. Marking and/or classification guidance for material originated or generated under this contract will be provided through the SAP Management Office under separate cover. Any material generated by the contractor (including correspondence, drawings, models, mockups, photographs, schematics, progress, special and inspection reports, engineering notes, computations and training aids) shall be classified according to content. Guidance for classification shall be derived from the applicable Security Classification Guides, documents, or special instructions. Such material shall not contain contractor logos or similar identifiers which identify the specific contractor or team members.

b. The Contractor Special Security Officers shall coordinate with the DISA Security Office (MPS6) and SAP Management Office prior to subcontracting any portion of this contract.

c. All personnel requiring access to SAP information must be U.S. citizens, have been granted a final U.S. Government security clearance, and have been indoctrinated for the applicable SAP prior to being given access to such information generated or received under this contract.

d. Contractor generated or Government furnished material may not be provided to the Defense Technical Information Center. Contractor generated reports will bear the statement: “Not Releasable to the Defense Technical Information Center” per DoD Instruction 5230.24.

e. Upon expiration of this contract, the contractor is required to have a closeout inspection by the DISA SSO and/or SAP Management Office to ensure proper disposition of material and equipment. The contractor shall request disposition instructions for all classified and unclassified project material. The contractor may be directed to properly destroy the material or return it. If classified or unclassified project material is to be retained by the contractor, every effort should be taken to transfer it to a follow-on contract or similar effort, if applicable. This must be done, however, with the contracting officer’s (KO) approval. The material shall be returned or destroyed as instructed, unless written authorization by the KO to retain specific material for a specific period of time is received. Any exception to security policy shall be referred to the Cognizant Security Office and the DISA Security Office (MPS6) for coordination with the appropriate agency(s) and the KO.

f. The contractor is required to have a closeout inspection

Reference Blocks 10f: This contract will be performed at the DISA Facility HQ Ft George G. Meade only. Security Guidance will be provided under separate cover by the Program Security Office. (PSO)

Reference Block 10g: Access up to and including (NATO SECRET) material will be required for reference at (Government FSO).

Reference Block 10j: Contractor will be provided with and will abide by DoD Regulation 5400.7, DoD Freedom of Information Act Program, and DoD 5200.01-M, Information Security Program. Guidance provided under separate cover NOTE: Non-DoD user agencies that use other terms that are similar to FOUO are responsible for providing proper guidance to the contractor for the information that requires protection from public disclosure.

Reference 10k: (SIPRNet / JWICS access) The contractor will access JWICS at the government facility only. The contractor will access SIPRNET at the government and contractor facility.

Reference Block 11c: Contractor will reference the appropriate security classification guidance when generating or deriving classified material or hardware. All classified information received or generated will be properly stored and handled according to the markings on the material. All classified information received or generated is the property of the U.S. Government. At the termination or expiration of this contract, the U.S. Government will be contacted for proper disposition instructions.

Contractor will abide by the following security classification guidance:

Guidance will be provided under separate cover

Reference Item 11e: Equipment Maintenance Services – Reference Block 11e: Contract is for equipment maintenance services on equipment which processes classified information. Actual knowledge of, generation, or production of classified information is not required for performance of the contract. Cleared personnel are required to perform this service because access to classified information cannot be precluded by escorting personnel.

Engineering Services Contract is for engineering services. Classification and markings on the material to be furnished will provide the classification guidance necessary for performance of this contract.

Reference Item 11f, HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES. Overseas performance locations (including activity addresses):

(1) HQ USEUCOM ECJ35-STO Unit 30400, Box 1000 APO AE 09128-4209 (Patch Barracks, Montana Strasse, Ge 2302, Rm29, 70569 Stuttgart, Germany)

(2) FKJ2-PO-OPT Unit 15237 FPO AP 96205-0010 (Osan AFB)

(3) Commander Seventh Fleet Attn: N32 Unit 25104 FPO AP 96601-6003 (Yokosuka, Japan)

(4) HQ USAREUR (ODCSOPS) Plans Division AEAGC-P-PC) Unit 29351 APO AE 09014 (Weisbaden, Germany)

(5) HQ USAFE/INS Unit 3050 P.O. Box 80 APO AE 09094 (Ramstein AFB, Germany)

(6) CINCUSNAVEUR Attn: ETCS (SS) N37, PSC 802, Box 5 FPO AE 09499-0157 (London, England)

(7) COMUSNAVCEN/N2 Admin Support Unit – SW Asia PSC-45 FPO AE 09834-2800 (Bahrain)

(8) HHD, 41ST SIG BN Box C2 APO AP 09131 (Seoul, Korea)

Reference Block 11f: Contractors when performing or traveling outside the United States under this contract will:

a) All personnel will obtain an AOR specific foreign travel brief within 90 days of travel and will provide proof of training to the COR/TM.

b) All personnel will receive the Antiterrorism Level I Awareness training within one year prior to travel.

• For DoD contractors performing on overseas contracts, provide a copy of the DD Form 254 to the appropriate DSS Office of Industrial Security, International. (See NISPOM Appendix A or contact DSS.)

Reference Block 11g:

a. Technical information on file at the Defense Technical Information Center will be made available to the contractor if the contractor requires such information.

b. The contractor must prepare and forward a DD Form 1540 to the COR/TM for authorization BEFORE the services may be requested.

Reference Item 11h: REQUIRE A COMSEC ACCOUNT:

Contractor is authorized to receive Government furnished cryptographic equipment. Access to classified COMSEC information requires a final U.S. Government clearance at the appropriate level. Further disclosure of COMSEC information by a contractor, to include subcontracting, requires prior approval of the contracting activity. Contact the DISA CIO COMSEC Custodian, at Commercial (301) 225-3405.

Reference Block 11i: The contractor shall not process classified information by electrical means prior to a DISA TEMPEST evaluation of the equipment/systems and facility, and written DISA certification that the facility meets DISA TEMPEST criteria. In order to expedite the DISA TEMPEST evaluation, the contractor shall provide a list of equipment, to include model number, which is associated with the processing of classified information. In addition, the estimated percentage of classified information processed, cable/conduit runs, a floor plan layout that depicts placement of equipment in relation to other rooms, equipment distances from walls or uncontrolled areas, and physical security being afforded the equipment both during processing and after hours. The above TEMPEST evaluation and DISA approval will not be required if previous DISA approval can be furnished and is no more than 2 years old. The existing approval must be for processing information at the same or higher level and at the same facility and blocks of equipment. The DISA Certified TEMPEST Technical Authority is the only authorized approving agent for TEMPEST systems within DISA.

Reference Blocks 11i:

a. The contractor will not process classified information by electrical means prior to a TEMPEST evaluation of the equipment/systems and facility, and written certification by the DIA Certified TEMPEST Technical Authority that the facility meets DIA’s TEMPEST criteria. In order to expedite the TEMPEST evaluation, the contractor shall provide a list and layout of equipment in accordance with DOD 5105.21 M-1 TEMPEST Addendum. The enclosure will include a floor plan layout that depicts placement of equipment in relation to other equipment, telephone lines and instruments, cable/conduit runs, etc. The drawing(s) are to show dimensions of rooms, physical relation to other rooms, equipment distances from walls or uncontrolled areas, and physical security being afforded the equipment both during processing and after hours.

b. Previous DIA Certified TEMPEST Technical Authority approval may be furnished provided it is not more than 2 years old so long as the physical accreditation has been maintained. If physical accreditation was lost or de-certified, the TEMPEST accreditation must be issued based on the new physical accreditation by DIA. The approval must be for processing information of the same or higher level security classification and for the same facility and blocks of equipment.

Reference Block 11j: The contractor will comply with OPSEC requirements and they will be provided under separate cover.

Reference Block 11k: The contractor is authorized to use the services of DCS. DISA must obtain written approval from the Commander, Defense Courier Service, Attn: Operations Division, Fort George G. Meade, MD. 20755-5370, in order to impose this requirement on contractors. Only certain classified information qualifies for shipment by DCS. DISA is responsible for complying with DCS policy and procedures. Prior approval of DISA is required before a Prime Contractor can authorize a subcontractor to use the services of DCS

Reference Item 11L: IT-I access required

AUTOMATED DATA PROCESSING (ADP) POSITION DESCRIPTIONS AND INVESTIGATION REQUIREMENTS

Critical-Sensitive Positions (ADP-I positions):

Those positions in which the incumbent is responsible for the planning, direction, and implementation of a computer security program; major responsibility for the direction, planning and design of a computer system, including the hardware and software; or, can access a system during the operation or maintenance in such a way, and with a relatively high risk for causing grave damage, or realize a significant personal gain. ADP-I designated positions require a Single Scope Background Investigation (SSBI)

Non-critical-Sensitive Positions (ADP-II positions):

Those positions in which the incumbent is responsible for the direction, planning, design, operation, or maintenance of a computer system, and whose work is technically reviewed by a higher authority of the ADP-I category to ensure the integrity of the system. ADP-II designated positions require a DoD National Agency Check Plus Written Inquiries (DNACI)/National Agency Check Plus Written Inquiries (NACI).

Non-sensitive Positions (ADP-III positions):

There are NO Non-sensitive positions within DISA.

Continuation page:

14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to ISM requirements, are established for this contract. (If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the cognizant security office. Use item 13 if additional space is needed.) The contractor will be provided and will abide by ICD 704 Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and Other Controlled Access Program Information, October 1, 2008 and by ICD 705 Sensitive Compartmented Information Facilities, May 26, 2010. Provided under separate cover. The contractor will abide by DCID 6/6 (formerly 1/7), Security Controls on the Dissemination of Intelligence Information, 11 July 2001. Provided under separate cover. TEMPEST requirements apply. Guidance provided in Block 13 as reference Block 11i. OPSEC requirements apply. Guidance provided in Block 13 as reference Block 11j.

REFERENCES

a. DoD 5220.22-R, Industrial Security Regulation, 18 March 2011

b. DOD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), 02 February 2008

c. DoD 5220.22, National Industrial Security Program, 27 September 2004

e. DoD 5200.1-R, Information Security Program, 24 February 2012

f. DoD 5200.2-R, Personnel Security Program, 16 January 1987

g. DoD 5230.24, Distribution Statements on Technical Documents, 18 March 1987

h. DoD 5205.2, DOD Operations Security (OPSEC) Program, 06 March 2006

i. DIAM 50-4, Security of Compartmented Computer Operations (U), 24 June 1980

j. DIAM 50-5, Volumes I & II, Sensitive Compartmented Information (SCI) Contractor Administrative Security, 22 October 1979

k. Director of Central Intelligence Directive (DCID) 1/7, Security Controls on the Dissemination of Intelligence Information, 30 June 1998

l. DCID 6/4 Personnel Security Standards & Procedures Governing Eligibility for Access to Sensitive compartmented Information (SCI) 02 July 2008

m. DCID 1/19, Security Policy for SCI (U), 01 March 1995

n. ICD 704 Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and Other Controlled Access Program Information, October 1, 2008 and ICD 705 Sensitive Compartmented Information Facilities, May 26, 2010.

o. DoD Directive 8500, 01E, Information Assurance, 24 October 2002

p. Administrative Instruction No. 26, Information Security Supplement to DoD 5200.1-R, 01 April 1987

q. DoD 5400.7, DoD Freedom of Information Act (FOIA) Program, 02 January 2008

r. DoD 5400.11 DoD privacy Program, 08 May 2007

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(Please read Instructions BEFORE completing this application.) (The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED (See instructions.)

b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/MATERIAL REQUIRED AT CONTRACTOR FACILITY

DUE DATE (YYYYMMDD)

c. SOLICITATION OR OTHER NUMBER

b. SUBCONTRACT NUMBER

a. PRIME CONTRACT NUMBER (See instructions.)

DATE (YYYYMMDD)

c. FINAL (Complete Item 5 in all cases.)

DATE (YYYYMMDD)

REVISION NO.

b. REVISED (Supersedes all previous specifications.)

DATE (YYYYMMDD)

a. ORIGINAL (Complete date in all cases.)

(Preceding Contract Number) is transferred to this follow-on contract.

Classified material received or generated under YES. If Yes, complete the following:

NO

4. IS THIS A FOLLOW-ON CONTRACT?

, retention of the classified material is authorized for the period of:

In response to the contractor's request dated YES. If Yes, complete the following:

NO

5. IS THIS A FINAL DD FORM 254?

c. COGNIZANT SECURITY OFFICE (CSO) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code.)

c. COGNIZANT SECURITY OFFICE(S) (CSOs) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

7. SUBCONTRACTOR(S) (Click button to add more subcontractors.)

c. COGNIZANT SECURITY OFFICE(S) (CSOs) (Name, Address, ZIP Code, Telephone) (If applicable, see instructions.)

b. CAGE CODE (If applicable, see instructions.)

a. LOCATION(S) (For actual performance, see instructions.)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT (Click here if more space is needed.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION

d. FORMERLY RESTRICTED DATA

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.)

b. RESTRICTED DATA

e. NATIONAL INTELLIGENCE INFORMATION:

f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION

k. OTHER (Specify) (See instructions.)

j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)

i. ALTERNATIVE COMPENSATORY CONTROL MEASURES (ACCM) INFORMATION

h. FOREIGN GOVERMENT INFORMATION

g. NORTH ATLANTIC TREATY ORGANIZATION (NATO) INFORMATION

DD FORM 254, NOV 2017

PREVIOUS EDITION IS OBSOLETE.

Adobe LiveCycle Designer ES4

(1) Sensitive Compartmented Information (SCI)

(2) Non-SCI CLASSIFICATION (When filled in):

CLASSIFICATION (When filled in):

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT ACTIVITY (Applicable only if there is no access or storage required at contractor facility. See instructions.)

h. REQUIRE A COMSEC ACCOUNT

k. BE AUTHORIZED TO USE DEFENSE COURIERS

j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

i. HAVE A TEMPEST REQUIREMENT

b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY

c. RECEIVE, STORE, AND GENERATE CLASSIFIED INFORMATION OR MATERIAL

f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES

g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER

e. PERFORM SERVICES ONLY

d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED

INFORMATION (CUI).

(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)

m. OTHER (Specify) (See instructions)

12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address.

(See instructions)

DIRECT

THROUGH (Specify)

PUBLIC RELEASE AUTHORITY:

13. SECURITY GUIDANCE. The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes;

to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Click button to add additional pages as needed to provide complete guidance.)

14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

Yes No (If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. Use Item 13 or click button if additional space is needed.)

15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the CSO.

(If Yes, explain and identify specific areas and government activity responsible for inspections. Click button or use Item 13 if additional space is needed.)

Yes No

e. POC TELEPHONE (Include Area Code.)

f. EMAIL ADDRESS (See instructions.)

b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See instructions.)

d. AAC OF THE CONTRACTING OFFICE (See instructions.)

e. CAGE CODE OF THE PRIME CONTRACTOR (See instructions.)

d. POC NAME (See instructions.)

c. ADDRESS (Include ZIP Code.)

a. GCA NAME

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

17. CERTIFICATION AND SIGNATURES. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.

a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See instructions.)

f. TELEPHONE (Include Area Code.)

g. EMAIL ADDRESS (See instructions.)

i. SIGNATURE

h. DATE

b. TITLE

c. ADDRESS (Include ZIP Code.)

f. OTHERS AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)

e. ADMINISTRATIVE CONTRACTING OFFICER

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION

c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR

b. SUBCONTRACTOR

a. CONTRACTOR

DD FORM 254 (BACK), NOV 2017

CLASSIFICATION (When filled in):

CLASSIFICATION (When filled in):

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

7. SUBCONTRACTOR(S) (Continued)

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. LOCATION(S) (For actual performance, see instructions.)

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. LOCATION(S) (For actual performance, see instructions.)

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. LOCATION(S) (For actual performance, see instructions.)

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. LOCATION(S) (For actual performance, see instructions.)

8. ACTUAL PERFORMANCE (Continued)

9. GENERAL UNCLASSIFIED IDENTIFICATION OF THIS PROCUREMENT (Continued)

DD FORM 254, NOV 2017

Pages of Continuation Page CLASSIFICATION (When filled in):

CLASSIFICATION (When filled in):

15. INSPECTIONS (Continued)

14. ADDITIONAL SECURITY REQUIREMENTS (Continued)

13. SECURITY GUIDANCE (Continued) Pages of Continuation Page

DD FORM 254, NOV 2017

Additional persons assisting with completion of form (signatures and titles) CLASSIFICATION (When filled in):

CLASSIFICATION (When filled in):

9.0.0.2.20120627.2.874785

WHS/ESD/DD

DD 254, Nov 2017, "DoD Contract Security Classification Specification" No No No No Yes DD254 Block 13 attachment.docx DD254 Block 14 attachment.docx

a. Facility clearance level. Select one.: 1
b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4
2.c. Due date (four digit year, two digit month, two digit day.: 20180713.00000000
2.c. Solicitation or other number.: HC1028-18-R-0086
Mark X if solicitation or other number.: Yes
2.b. Subcontract number.:
Mark X if Subcontract.: Off
2.a. Prime contract number.:
Date (4 digit year, 2 digit month, 2 digit day).:
Date (4 digit year, 2 digit month, 2 digit day).:
3.b. If revised, revision number.:
Date (Complete in all cases) (4 digit year, 2 digit month, 2 digit day).:
12. Public Release. Proposed public releases shall be submitted for approval prior to release: X first box if Direct, second box if Through.:
4. If yes: Classified material received or generated under. Enter the preceding contract number, (enter Preceding contract number) is transferred to this follow on contract.:
Retention of the classified material is authorized for the period of::
5. If yes, complete the following: In response to the contractors request dated::
6.c. Cognizant security office. (Name, address, and zip code).:
6.b. CAGE code.:
6. Contractor. a. Name, address, and zip code.:
c. Cognizant security office. (Name, address, and zip code).:
b. CAGE code.:
7. Subcontractor(s). a. Name, address, and zip code.:
8.c. Cognizant security office (Name, address, and zip code).: Navy Information Forces

ATTN: Security 115 Lakeview Pkwy Suffolk, VA 23425

8.b. CAGE code.: SMO Code:
8. Actual performance. a. Location.: Navy Information Forces

115 Lakeview Pkwy Suffolk, VA 23425

9. General unclassified description of this procurement.:
10. Contractor will require access to: X if COMSEC information.: Yes
X if restricted data.: Off
X if NATO information.: Yes
X if other.: Yes
X if CUI.: Off
X if alternative compensatory control measures (ACCM) information.: Off
X if foreign government information.: Off
X if formerly restricted data.: Off
X if formerly restricted data.: Yes
X if formerly restricted data.: Yes
X if special access program (SAP) information.: Yes
X if CNWDI.: Off
Specify other require;ments (see instructions).: SIPRNET/JWICS
Specify other require;ments (see instructions).: IT-1 Access Required
Button1:
Button2:
CheckBox1: 0
DelPage9:
DelPage7:
Classification (when filled in).:
Classification (when filled in).:
11. In performing this contract, the contractor will: X if have access to classified information only at another contractor's facility or a government activity.: Off
X if receive and store classified documents only.: Off
X if require a COMSEC account.: Off
X if be authorized to use the Defense Courier Service.: Yes
X if have access to CUI.: Off
X if have OPSEC requirements.: Yes
X if have a TEMPEST requirement.: Off
X if receive, store, and generate classified material.: Yes
X if have access to U.S. classified information outside the U.S., Puerto Rico, U.S. possessions and trust territories.: Off
X if authorized to use the services of DTIC or other secondary distribution center.: Yes
X if perform services only.: Yes
X if fabricate, modify, or store classified hardware.: Off
X if other.: Yes
If through, specify.: Public release of material is not authorized. All requests must be forwarded through the certifying official (Block 16), Fleet Cyber Command Office of
Public release authority:: Public Affairs, and the contracting officer.
13. Security guidance.: See Continuation Sheet for Item 13
15. Inspections. X first box if yes, second box if no.:
15. Inspections. X first box if yes, second box if no.:
15. Inspection. If yes is checked, explain and identify specific areas or elements carved out and the activity responsible for inspections.:
14. Additional security requirements. If yes, identify.: See Continuation Sheet for Item 14
e. POC telephone number (include area code).:
f. Email address (see instructions).:
d. Activity address code of the contracting office.:
d. POC name (last, first, middle initial).:
d. Cognizant security office. (Name, address, and zip code).:
16.a. Government contracting authority (GCA) name.:
17.a. Typed name of government or contractor security official (last, first, middle initial).:
f. Telephone number (include area code).:
g. Email address (see instructions).:
b. Title.:
c. Address (include ZIP Code).:
h. Date signed.:
i. Signature (click to sign).:
Specify other distribution.:
17.f. Mark X if others as necessary.: Off
17.e. Mark X if administrative contracting officer.: Yes
17.d. Mark X if U.S. activity responsible for overseas security administration.: Off
17.c. Mark X if Cognizant Security Office for prime and subcontractor.: Yes
17.b. Mark X if Subcontractor.: Off
17. Required distribution. a. Mark X if Contractor.: Yes
b. Activity address code of the contracting office.:
e. CAGE code of the prime contractor.:
SignatureField1:
attachmentsList:
AddAttachment:
ViewAttachment:
RemoveAttachment:
DelPage13:
DelPage14:
DelPage15:
Classification (when filled in).:
9. General identification of this procurement.:
Total number of pages.:
Page number of this page.:
Button3:
DeletePage:
Signature.:
Title.:
Title.:
Title.:
Title.:
Signature.:
Signature.:
Signature.:

File details come from the government source that posted it.