Bidders Library Security - DISAI 240-110-38.pdf

PDF 77 KB Posted

Attached to
TEC II Services RFP Federal contract opportunity
Solicitation number
HC102821R0006
Issued by
Defense Information Systems Agency

About this file

This Defense Information Systems Agency instruction outlines responsibilities and procedures for industrial security related to classified federal contracts. It assigns oversight of industrial security matters to the agency's Security Division chief and identifies requirements for program managers, contracting officers, and security managers. Contractors and subcontractors must complete DD Forms 254 to obtain security clearances and ensure proper handling of classified information. If a contractor has foreign ownership, control or influence, a risk mitigation agreement must be in place such as a Special Security Agreement requiring national interest determination approval. The instruction also addresses limited facility clearances and screening contractors from state sponsors of terrorism.

View the file

Other files for this federal contract opportunity

Other files attached to TEC II Services RFP, newest first.
File Type Posted
HC102821R0006 Conformed Through amendment 0008.pdf PDF
HC102821R0006 Conformed Through amendment 0007.pdf PDF
HC102821R0006 Conformed Through amendment 0006.pdf PDF
HC102821R0006 Conformed through amendment 0002.pdf PDF
HC102821R00060002.pdf PDF
Bidders Library DODI 5000 02.pdf PDF
Bidders Library Security - ISOO Handbook.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 1.pdf PDF
Bidders Library Security - DISAI 240-115-04.pdf PDF
Bidders Library Security - DISAI 240-110-35.pdf PDF
Bidders Library Operational Test and Evaluation - JITC OTE Guidebook v2 0.docx DOCX document
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-19-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 10-18-2010.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 6-16-2003.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 04-03-2018.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 1-21-2015.pdf PDF
Bidders Library JITC Instructions - JITCI 100-50-01.pdf PDF
Bidders Library JITC Instructions - JITCI 210-20-02.pdf PDF
Bidders Library JITC Instructions - JITCI 210-15-01.pdf PDF
Bidders Library JITC Instructions - JITCI 200-05-07.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC Notional Guide for Action Officers.pdf PDF
Bidders Library Interoperability Test and Evaluation - JITC Fact Sheet.pdf PDF
Bidders Library Interoperability Test and Evaluation - DODI 8551 01.pdf PDF
Bidders Library Interoperability Test and Evaluation - DoD 8570 01-M.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDI 4000 19.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoDD 510035.pdf PDF
Bidders Library DoD Policy Instruction and Guidance - DoD Net Centric Service Strategy.pdf PDF
Bidders Library DISA - DISA Mandatory Contractor Training as of 20201110.xlsx XLSX spreadsheet
Bidders Library Cybersecurity - DoDI 8510 01.pdf PDF
Bidders Library Security - DISAI 240-110-8.pdf PDF
Bidders Library Cybersecurity - DOD Cybersecurity TE Guidebook.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 3.pdf PDF
Bidders Library Security - DoDM 5200 02.pdf PDF
Bidders Library Security - DoDM 5200 01 Vol 2.pdf PDF
Bidders Library Security - DoDM 5200 48.pdf PDF
Bidders Library Security - DoDD 5230 20.pdf PDF
Bidders Library Security - DoDM 5105 21.pdf PDF
Bidders Library Security - DISAI 240-110-39.pdf PDF
Bidders Library Operational Test and Evaluation - DOTE TEMP Guidebook.pdf PDF
Bidders Library Operational Test and Evaluation - DTM 11-003.pdf PDF
Bidders Library Operational Test and Evaluation - DoTE MEMO 7-23-2013.pdf PDF
Bidders Library Operational Test and Evaluation - DISA Test and Evaluation Scorecard Template.pptx PPTX presentation
Bidders Library Operational Test and Evaluation - DoDD 5000 01.pdf PDF
Bidders Library JITC Instructions - JITCI 280-120-01.pdf PDF
Bidders Library JITC Instructions - JITCI 640-50-07.pdf PDF
Bidders Library JITC Instructions - JITCI 380-50-02.pdf PDF
Bidders Library JITC Instructions - JITCI 200-50-02.pdf PDF
Bidders Library JITC Instructions - JITCI 200-05-05.pdf PDF
Bidders Library JITC Instructions - JITCI 200-05-06.pdf PDF
HC102821R0006.pdf PDF
Show all 50

TEC II Services RFP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEFENSE INFORMATION SYSTEMS AGENCY

P. O. BOX 549

FORT MEADE, MARYLAND 20755-0549

DISA INSTRUCTION 240-110-38* 17 March 2017

SECURITY

Industrial Security

1. Purpose. This Instruction assigns responsibilities and duties for industrial security.

It provides guidance on contractors with foreign ownership, control, or influence (FOCI).

It also addresses limited facility clearance (FCL).

2. Applicability. This Instruction applies to all Defense Information Systems Agency (DISA) activities and the Joint Force Headquarters – Department of Defense Information Networks (JFHQ-DoDIN).

3. Authority. This Instruction is published in accordance with the authority contained in DoD 5220.22-R, Industrial Security Regulation, December 1985; DoD 5220.22-M, National Industrial Security Program Operating Manual, February 2006, 18 May 2016; Directive-Type Memorandum (DTM) 15-002, Policy Guidance for the Processing of National Interest Determinations (NIDs) in Connection with Foreign Ownership, Control, or Influence (FOCI), 11 February 2015; and Federal Acquisition Regulation (FAR) Subpart 4.4, Safeguarding Classified Information Within Industry. (In case of a conflict between DoD 5220.22-M and DoD 5220.22-R, DoD 5220.22-R takes precedence.)

4. Responsibilities.

4.1 Directors, Executives, Commanders, and Chiefs of Major Organizational Elements.

These individuals will:

4.1.1 Ensure Program Managers (PMs) and Contracting Officer's Representatives (CORs) consult their Security Managers (SMs) to determine the security requirements for their contracts.

4.1.2 Ensure DD Forms 254: Department of Defense Contract Security Classification Specification, are updated and renewed, if applicable, in a timely manner and submitted to the Industrial Security Program Manager (ISPM) for approval, if necessary.

4.1.3 Ensure operations security and counterintelligence are considered and included in the framework of the contract preparation.

4.1.4 Ensure contract personnel resident at DISA field activities have a copy of all approved DD Forms 254 issued for specific contracts at their location.

DISAI 240-110-38

4.1.5 Ensure assigned SMs establish a timeframe for receipt, review, and forwarding of DD Forms 254 to the ISPM. (This timeframe is to be disseminated to supported CORs and the ISPM.)

4.1.6 Ensure CORs review the security clearance eligibility of each contractor performing work on DISA contracts requiring access to classified information. (This review should be conducted at least annually and can be accomplished when contractors requiring access are submitted for a Visit Authorization Request [VAR].)

4.2 Workforce Services and Development Directorate (WSD) Chief, Security Division (MP6). The WSD Chief, MP6, will:

4.2.1 Oversee industrial security at DISA activities through program reviews and random visits to DISA contracting activities, as needed.

4.2.2 Maintain a level of expertise in industrial security for DoD contracts, personnel, and facilities and provide technical guidance, as necessary, to DISA senior staff.

5. Duties.

5.1 Industrial Security Program Manager (ISPM). The ISPM will:

5.1.1 Review all prime DD Forms 254 with a Statement of Work (SOW), Statement of Objectives (SOO), or Performance Work Statement (PWS) received from the supporting organizational SM. (Subcontractor DD Forms 254 will be reviewed if access to sensitive compartmented information [SCI], special access program [SAP], or focal point is required;

if Alternative Compensatory Control Measures [ACCM] are required; or if foreign ownership, control, or influence [FOCI] of the subcontractor is present.)

5.1.2 Provide technical advice in proper completion and suggest necessary changes, if any, on all prime DD Forms 254.

5.1.3 Provide industrial security training annually or as necessary to all Contracting Officers (KOs), CORs, PMs, and SMs throughout the Agency.

5.1.4 Coordinate with the Defense Security Service (DSS) on the completion process of the DD Form 254 and other industrial security matters.

5.1.5 Report adverse information to DSS that could affect the facility clearance level of a contractor facility.

5.2 Security Manager (SM). An SM will:

5.2.1 Ensure contractor personnel are aware of and adhere to local security policies and procedures.

5.2.2 Receive, review, and provide advice and assistance for all DD Forms 254, SOWs, SOOs, and/or PWSs, consistent with the authorities cited in paragraph 3, prior to submission to the ISPM. (Subcontractor DD Forms 254 will be reviewed and forwarded to the ISPM if access to SCI, SAP, or focal point is required; if ACCM is required; or if FOCI of the subcontractor is present. If none of these requirements are present for the subcontract, the SM will provide approval and send a courtesy copy to the ISPM.)

5.2.3 Provide assistance, as needed, to the KO, COR, PM, or others, as assigned during the completion of the DD Form 254, and oversight of the security elements contained in the DD Form 254.

5.2.4 Provide assistance and information, as necessary, regarding industrial security issues or concerns to the ISPM.

5.2.5 Attend DD Form 254 training provided by the ISPM at least once annually.

5.2.6 Ensure any notices received from DSS with adverse information concerning the status of a contractor facility clearance are provided to the ISPM.

5.3 Contracting Officer's Representative (COR) or Program Manager (PM). A COR or PM will:

5.3.1 Review all proposed solicitations to determine whether access to classified information may be required by contractor personnel during contract performance.

5.3.2 Complete the DD Form 254 with a SOW, SOO, or PWS for the review of the SM when contracts require access to classified information.

5.3.3 Coordinate with the appropriate SM on any questions, concerns, or issues regarding the completion of the DD Form 254.

5.3.4 Ensure all requests for requirements and/or acquisition packages include DD Form 254 concurrence by the ISPM prior to release.

5.3.5 Ensure contractor personnel have the appropriate security clearance and information technology (IT) access level, as stipulated in the SOW, SOO, and/or PWS.

5.3.6 Ensure contracts and orders requiring access to classified information and/or spaces are not awarded without ISPM final approval of the DD Form 254.

5.3.7 Ensure a signed copy of the DD Form 254 is provided to all offices checked for distribution.

5.3.8 Submit requests for a DISA Badge and local area network access to the MP6 Visit Authorization Request (VAR) Center through the organizational SM or site SM for field activities, 7 days in advance of the personnel arriving.

5.3.9 Ensure contractor employees are properly briefed on security procedures and requirements applicable to their duties.

5.3.10 Inform contractors and subcontractors of the security classification and requirements assigned to the various documents, material, tasks, subcontracts, and components of the classified contracts.

5.3.11 Monitor personnel status changes of contractors assigned, notify the appropriate COR, DISA VAR Center, or local Security Manager of contractor employee departures and ensure all government-issued credentials (DISA Badge, Common Access Card, Pentagon Badge, etc.)

are retrieved prior to departure.

5.3.12 Ensure existing contracts requiring access to classified information include a valid DD Form 254 that has been approved by the ISPM and a copy is on file with DSS.

5.3.13 Ensure any notices received from DSS with adverse information concerning the status of a contractor facility clearance are provided to the ISPM.

5.3.14 Ensure copies of all DD Forms 254 and related contract documentation are retained, in accordance with DFARS 204.805 - Disposal of Contract Files and the FAR 4.805 - Storage, Handling and Contract Files.

6. Contractors with Foreign Ownership, Control, or Influence (FOCI).

6.1 If a contractor chosen for performance on a classified contract has FOCI, a risk mitigating vehicle must already be in place. Otherwise, FOCI might jeopardize the security of classified information held by the contractor. If the mitigating vehicle is a Special Security Agreement, a National Interest Determinations (NID) may be required. The NID can be program, project, or contract specific. The DSS will provide a copy of the recommendations to the program office and MP6 for NID consideration.

6.2 If DISA considers sponsoring a NID, the requesting program office is to obtain a formally signed memorandum via the Director, Operations Directorate (OP), addressed to DSS requesting assistance in processing the NID. The justification from the requesting program office must address and explain how the FOCI contractor's product or service is crucial or is the sole avail-able source. If applicable, the memorandum must also provide a written explanation when contract cancellation would cause unacceptable delays in the field or for support organizations.

The DSS contacts the Foreign Disclosure Officer and the Top Secret Control Officer for top secret; National Security Agency for communications security; Office of Director for National Intelligence for SCI; and Department of Energy for Restricted Data or Formerly Restricted Data to obtain release approval.

6.3 The NID and associated documentation are reviewed and validated by MP6. Once completed, the package is forwarded to DSS for approval by the owners of the desired proscribed information.

6.4 For a company that is owned or controlled by the government of a terrorist country, a waiver request must be submitted through the Director, OP, via MP6 and the Procurement Services Directorate (PSD) Policy, Quality Assurance, and Procedures Division (PL2) to the Secretary of Defense for approval. PL2 serves as the liaison between DISA and Deputy Director, Defense Procurement and Acquisition Policy (DPAP) Contract Policy/and International Contracting (CPIC), to include logging and tracking of the request once it has been submitted to CPIC. (Properly identify in the subject line of the request "Waiver of the Prohibition of an Award to a Contractor with Ownership or Control by the Government of a Country that is a State Sponsor of Terrorism, DFARS 209.104-1(g)(i)(B).")

7. Limited Facility Clearance (FCL). The decision to request a limited FCL is made by the Director, OP, as an authorized official of DISA to certify, in writing, that there is a compelling need to issue the limited FCL and accept the risk inherent in not mitigating the FOCI. The limited FCL permits performance up to the secret level on classified contracts issued by DISA.

The limited FCL shall remain in effect until written concurrence is received by the department or agency which owns or controls the classified information.

MARK E. ROSENSTEIN

Colonel, USA Chief of Staff

*This Instruction replaces DISAI 240-110-38, 12 March 2013.

OPR: WSD MP6

DISTRIBUTION: Approved for public release; distribution is unlimited.

2017-03-16T11:12:16-0400
ROSENSTEIN.MARK.ERIC.1078644431

File details come from the government source that posted it. Updated .