DD_Form_254_Continuation_Sheet_061115.docx

DOCX document 32 KB Posted

Attached to
Instrumentation Support Federal contract opportunity
Solicitation number
HDTRA2-15-R-0005
Issued by
Defense Threat Reduction Agency

About this file

DD Form 254 Continuation Sheet

View the file

Other files for this federal contract opportunity

Other files attached to Instrumentation Support, newest first.
File Type Posted
Sample_Task_Order__2_Test_Support_V7_072015.docx DOCX document
DD_254_Proposed_061115.pdf PDF
ISC_SOO-V8_6-30-15.docx DOCX document
DRAFT_Solicitation.doc DOC document
Socio-Economic_Commitment_-_Management_Subfactor.xls XLS spreadsheet
CDRLs_Proposed_v4_072015.docx DOCX document
Sample_Task_Order__1_v5_071515.docx DOCX document
ISC_MASTER_GOVERNMENT_PROPERTY_MAY_2015.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Continuation DD Form 254 Contract # TBD Contractor TBD

- Item 10a Communications Security (COMSEC) Information Contractor is authorized to receive Government furnished cryptographic equipment. Access to classified COMSEC information requires a final U.S. Government clearance at the appropriate level. Further disclosure of COMSEC information by a contractor, to include subcontracting, requires prior approval of the DTRA contracting activity.

- Item 10f Special Access Program (SAP) Information SAP access requirements will be vetted through the DTRA Special Programs Manager (DTRA SAPCON), who will coordinate access requirements with the organization owning the SAP or SAP material. The contractor will comply with applicable Joint Air Force Army Navy (JAFAN) documents and the SCG for the DTRA SAP, which will be provided under separate cover. The contractor will only perform work on SAP information and materials in the DTRA SAPF, or a SAPF accredited by the organization owning the SAP or SAP information. All contractor personnel who are required to have SAP access must be US citizen and be eligible for a final US government security clearance at the appropriate level. Unless otherwise approved, the contractor shall not retain any SAP material or information upon the termination of this contract.

- Item 10i Limited Dissemination Information All "For Official Use Only" information shall be marked, safeguarded, transmitted, and disclosed in accordance with DoD 5200:1-R, "Information Security Program", Appendix 3.

- Item 10j For Official Use Only Information The location for contract performance is at the Prime contractor address, actual performance location, Defense Threat Reduction Agency (DTRA) 8725 John J. Kingman Road, Fort Belvoir, Virginia, and/or other DTRA sites.

- Item 11a Have access to classified information only at another contractor's facility or a government activity The location for contract performance is at the Prime contractor address, actual performance location, Defense Threat Reduction Agency (DTRA) 1680 Texas Street, Albuquerque, NM, 87117, and/or other DTRA sites.

- Item 11c Receive and generate classified material All classified information received or generated under this contract is the property of the U.S. Government. At the termination or expiration of this contract, the U.S. Government will be contacted for proper disposition instructions. The Program Manager (PM)/Contracting Officer’s Technical Representative (COTR) will provide the appropriate supporting Security Classification Guides to the contractor. Any security classification guidance will be provided by the Program Manager under separate cover. This applies to the actual performance location only.

- Item 11d Fabricate, modify, or store classified hardware The contractor is required to fabricate, modify, and store classified hardware. The Government will provide one work area and computer with DTRA network access. Under no circumstances shall individuals working on this contract remove from DTRA any classified electronic media without prior approval and permission. All contractors in privileged user positions must have a completed a SSBI in accordance with DOD I 8500.2, 6 February 2003, paragraph E3.4.8, and Table E3.T1, prior to filling the position. Privileged users are defined as, but not limited to, persons in the following roles or positions: Information Assurance (IA) Managers/Officers, supervisors of IT positions, system administrators, maintainers of IA-enabled products (e.g. routers, switches, firewalls), personnel performing system monitoring and testing, and personnel who issue Classified PKI certificates.

- Item 11j Have Operations Security (OPSEC) requirements All contractors supporting this effort will receive initial and annual refresher OPSEC training and will be periodically reminded of their responsibility to protect sensitive information. The contractor will develop a Critical Information List (CIL) which will identify the sensitive/unclassified information associated with the contract effort which, if disclosed, may tip an adversary as to our intentions and/or capabilities. Additionally, Critical Program Information (CPI) must be identified and protected IAW DoD Instruction 5200.39, “Critical Program Information Protection Within the Department of Defense”, dated July 16, 2008. CPI is defined as “highly sensitive information pertaining to a program which if compromised could cause significant degradation in mission effectiveness; shorten the expected life span of the program; significantly alter program direction; or enable an adversary to defeat, counter, copy, or reverse engineer the technology or capability.”

- AT1. AT Level 1 Training: IAW DoDI 2000.16, “DoD Antiterrorism (AT) Standards“, 2 October 2006, para E3.18.4, all contractor employees (to include subcontractor employees) supporting this contract that require access to a military installation, facility, controlled access area or test area shall complete AT Level 1 awareness training within 30 calendar days after the contract start date and annually thereafter. The contractor shall submit certificates of completion for each affected employee/subcontractor employee to DTRA/J0XS7. AT Level 1 awareness training is available at the following web site: https://atlevel1.dtic.mil/at/

- AT2. Overseas Travel: All contractor employees (to include subcontractor employees) supporting this contract that travel overseas must have completed AT Level 1 training and comply with U.S. Department of State travel requirements for each foreign country destination IAW DFARS clause 252.225-7043, March 2006, “Antiterrorism/Force Protection for Defense Contractors Outside the U.S.”. The employee must comply with reporting requirements identified in DoDD 5240.6, Enclosure 4. DTRA J0XS7 will be notified in parallel to DSS for all travel anomalies (e.g. elicitation; AIS theft) within five calendar days of travel completion.

- CI1. Critical Program Information (CPI): The owning DOD agency has identified CPI within this contracted effort that requires additional CI/Security countermeasures. The Program Manager or the COR will provide the contractor with a copy of the Counterintelligence Support Plan (CISP), Program Protection Plan (PPP) and Security Classification Guide (SCG) IAW DoDI 5200.39, 16 July 2008, “Critical Program Information”. The contractor shall notify DTRA/J0XS7 of efforts to gain illicit access/identified loss or compromise of CPI within one calendar day.

- CI2. CI Awareness Training: All contractor employees (to include subcontractor employees) supporting this contract are required to complete CI Awareness training requirements as outlined in DoDD 5240.6, 30 May 2013, “Counterintelligence Awareness and Reporting”, Enclosure 3. Contractors may complete this training via the DTRA Albuquerque newcomer’s in-processing or annual CI Awareness refresher training. Off-site contractors may request on-site training from DTRA J0XS7.

- CI3. Anomaly Reporting: All contractor employees (to include subcontractor employees) supporting this contract are required to comply with reporting requirements as outlined in DoDD 5240.6, 30 May 2013, “Counterintelligence Awareness and Reporting”, Enclosure 4, Section 5. DTRA J0XS7 will be notified in parallel to DSS for all notifications regarding the reportable contact, activity, indicator or behavior. Unsolicited suspicious/foreign country originated emails (e.g. foreign symposia invitations; intern or Ph.D. candidate requests; scientific paper review; technology purchase requests) and foreign national business cards shall be retained by the recipient until disposition instructions have been received by DSS or DTRA J0XS7.

- IS1. CUI Protection: The contractor requires access to Controlled Unclassified Information (CUI). All CUI shall be marked, safeguarded, transmitted, transported, destroyed and disclosed IAW DoDM 5200.01-V4, February 24, 2012, “DoD Information Security Program: Controlled Unclassified Information”, The Information Security Oversight Office (ISSO) publication “Marking Classified National Security Information”, and DoD Memorandum “Encryption of Sensitive Unclassified Data at Rest on Mobile Computing Devices and Removable Storage Media”, 3 July 2007. CUI sent via electronic mail shall be encrypted IAW the Federal Information Security Management Act of 2002 (FISMA). The contractor, at its own expense, is required to obtain, install, and manage Public Key Infrastructure (PKI) certificates for its employees that participate in this work effort on contractor-owned AIS. Contractor-owned AIS used to create, process, and/or store CUI must meet DoD requirements. Cover sheets will be affixed to printed CUI material to conceal sensitive content. Transmission of CUI via personal or commercial email accounts is prohibited IAW CJCSI 6510.01F, 9 Feb 2011, “Information Assurance (IA) and Support to Computer Network Defense (CND)”. CUI related to this work effort shall be segregated from all other electronically stored data on the contractor’s AIS; access will be restricted to only those contractor(s) that directly support this work effort. CUI shall not be disseminated, discussed, produced, stored or transmitted via the Internet (e.g. social networking web sites; cloud-based file servers that are not owned/managed by the DoD or the contractor). The contractor will ensure that Information Technology personnel that have Administrator-level security permissions on their network are U.S. persons that possess an active SECRET clearance. Expenditure of funds for security containers or closed areas for the sole purpose to protect CUI material is prohibited.

- IS2. Classified Protection: The contractor requires access to classified source data up to, and including, SECRET, CNWDI/RD, TOP SECRET and/or TOP SECRET SCI in support of this work effort. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with source documents. Use of “Multiple Sources” on the “Classified By” line necessitates compliance with the NISPOM, paragraph 4-208, and use of a bibliography. Classification, declassification, and markings shall be IAW EO 13526. All classified information received or generated under this contract is the property of the U.S. Government. DTRA J0XS7 will provide the appropriate Security Classification Guide (SCG) to the contractor under separate cover to the actual performance location. Access to, as well as the collecting, processing, and/or generating of classified information, data and/or video, shall only occur at cleared contractor or government facilities.

- IS3. Critical Information: The contractor requires access to Critical (aka: Sensitive) Information, which is defined as “Any information where the loss, misuse, or unauthorized access to or modification of which could adversely affect the national interest or the conduct of federal programs, or the privacy to which individuals are entitled under Section 552a of Title 5, U.S. Code (aka: The Privacy Act), but which has not been specifically authorized under criterions established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense or foreign policy.” DTRA further defines Critical Information as including, but not limited to, information which could be useful to a hostile agent in developing countermeasures; involve new or highly sensitive technology; identify key indicators or operational capabilities that could be used by a hostile agent to determine operational capabilities, weaknesses, or wartime mission.

- IS4. Information Spill: DTRA J0XS7 will be notified in parallel to DSS if an information spill (i.e. classified information is introduced onto unclassified AIS) is identified. The contractor shall immediately execute the DSS information spill checklist and cooperate fully with the DTRA J0XS7-assigned Preliminary Inquiry Officer with DTRA’s damage assessment. The contractor shall provide DTRA J0XS7 with a formal after action report that identifies when/how the spill was introduced onto the unclassified AIS (and by whom), how the spill contained/sanitized, and a full listing of AIS systems (internal and external to the contractor) that stored/processed/were sent the classified data.

- IS8. AIS/Computer Security: AIS security must meet standards established by the National Institute for Standards and Technology (NIST), NISPOM, and/or DoD 8500 series guidance, to include the implementation of Public Key Infrastructure (PKI). PKI certificates will be obtained/maintained at contractor expense. IAW the Federal Information Security Management Act of 2002 (FISMA), NIST standards for the protection of Personally Identifiable Information (PII) will be used to protect contract-related CUI. Whenever possible, contract-provided CUI/FOUO/Sensitive But Unclassified (SBU) information shall be segregated on the contractor’s AIS. Access to this network-stored information will be limited to employees actively working on this contract or task orders amended to the contract (via computer network user account/network security permissions). Classified AIS will meet standards established in the NISPOM ad accompanying supplements/guidance. DTRA J0XS7 must be immediately notified of any suspected/actual loss of AIS media that stores DTRA information.

- OS1. OPSEC Training: All contractors (including subcontractors) supporting this work effort shall supplement their current security practices by requiring any personnel involved in executing this contract to complete DTRA J0XS7-sponsored and administered Operations Security (OPSEC) training within 30 calendar days of contract execution (and annually thereafter). Upon contract award, all identified contractors (including subcontractors) will notify the COR of their acknowledgement that they will meet the requirements of the DTRA J0XS7 generated OPSEC Plan.

- OS2. Social Media: All contractors (including subcontractors) supporting this work effort shall not post onto the Internet their affiliation with this contract effort, to include test schedules/locations, associated technologies and peers involved in the contract effort.

- OS3. OPSEC Plan: This contract requires the establishment and maintenance of an OPSEC Plan. At a minimum, this plan shall identify: initial OPSEC training, education provided, annual refresher training and review. The OPSEC Plan must be approved by DTRA J0XS7.

- OS4. Critical Information: Sensitive or Critical Information is defined as “any information where the loss, misuse, or unauthorized access or modification of which could adversely affect the national interest or the conduct of federal programs, or the privacy to which individuals under Section 552a of Title 5, U.S. Code (aka: The Privacy Act), but which has not been specifically authorized under criterions established by Executive Order or an Act of Congress, to be kept secret in the interest of national defense or foreign policy.” Within DTRA, sensitive information includes, but is not limited to, information which could: be useful to a hostile agent in developing countermeasures; involve new or highly sensitive technology; identify key indicators or operational capabilities that could be used by a hostile agent to determine operational capabilities, weaknesses, or wartime mission. The application of government-approved protection equipment, devices, techniques, or services to C4 systems over which sensitive information is transmitted is deemed essential to protect critical DTRA information. National Security Agency (NSA) or NIST developed equipment or techniques shall be implemented in conjunction with DoD 5220.22-M requirements by the Contractor to protect critical unclassified and classified information related to this contractual effort. The loss or suspected loss of government information (to include Controlled Unclassified Information, or CUI, whether stored in electronic or printed format) must be immediately reported to the COR and DTRA J0XS7. This includes, but is not limited to, network intrusion, facility break-in, inadvertent release, loss of electronic media, etc. The contractor will complete additional reporting requirements as required by DoD 5220.22-M, Chapter 1, Section 3.

- PE1. Clearance Requirement: All contractors (including subcontractors) supporting this work effort shall be U.S. citizens and been granted an appropriate security clearance level for the DoD information they will receive from the government. SECRET clearances are based on a favorably adjudicated National Agency Check (NAC) with a Law and Credit Check (NACLC); a TOP SECRET clearance is based on a favorably adjudicated Single Scope Background Investigations (SSBI) via the Defense Security Service, Defense Industrial Clearance Officer, 600 10th Street, Fort Meade, MD, 20755. All contractors classified as a “Privileged User” that support this contract (e.g. Information Assurance Manager/Officer, Information Technology personnel, PKI certificate manager) must have completed their SSBI with favorable results prior to supporting this contract.

- PE3. Clearance Revocation/Expiration: DTRA J0XS7 shall be immediately notified of any contractor supporting this work effort whose security clearance is downgraded, suspended, surrendered, expired or revoked. The contractor’s access to DTRA information (electronic or printed) shall be immediately suspended pending DTRA J0XS7 guidance.

- PE4. Employment Termination: The contractor shall provide DTRA J0XS7 with advance notice of contractor(s) supporting this work effort that will be self-terminating their employment, retiring, absent from duty or employment for more than 60 consecutive days or are being removed from their position. The company will ensure the departing employee does not have continued access to any information or technology associated with this contract. If the employee was issued a DTRA proximity reader badge or a DTRA computer network account that employee must be formally out-processed via DTRA J0XS7.

- PE5. Security Agreement: The contractor will complete a DD Form 441, 31 May 2011, “Department of Defense Security Agreement”; all employees that support this work effort and will have access to classified information must complete a SF 312, “Classified Information Nondisclosure Agreement”. A copy of the signed DD Form 441 and SF 312 documents shall be provided to DTRA J0XS7 prior to starting the work effort.

- PE6. In-House Contractor: All contractors that will perform contract work within a DTRA workspace shall be in-processed by DTRA J0XS7. These contractors are required to formally out-process from DTRA J0XS7, return their DTRA-issued badge(s), and coordinate the return of DTRA-issued equipment with the COR.

- PE7. Security Reporting: The contractor is required to immediately notify DTRA J0XS7 for the following security-related incidents: a contractor is administratively removed from the contract effort or has their employment terminated; a contractor is elicited for information regarding this contract from anyone not working on the contract; when a contractor mishandles, fails to secure, uses information provided via this contract for personal gain or provides contract-provided information to a foreign nation; when classified information provided via this contract is discovered on unauthorized AIS; a contractor has their security clearance revoked by their employer or by a security clearance adjudicator; a contractor requests their security clearance to be downgraded/revoked or requests their access to classified information to be removed; the discovery of any nonconformance with the OPSEC Plan; suspected or verified loss of CPI or Critical Information.

- PH1. Installation Access: Contractor(s) that require access to a military installation in support of this work effort must comply with installation policies, directives, Random AT Measures (RAM), and Force Protection Condition (FPCON) levels. The contractor can be denied access IAW DoDI 5200.08, 10 December 2005, “Security of DoD Installations and Resources”, DTM 09-12, Interim Policy Guidance for DoD Physical Access control, and DTM 13-005, 25 April 2013, “Deviations from the DoD Physical Security Program”. The contractor shall comply with installation requests for information required for background checks to meet installation access requirements. The contractor must comply with all personal identity verification requirements as directed by the DoD and/or local policy. The contractor will comply with Force Protection Condition (FPCON) changes that can occur on the overall installation or a specific installation facility.

- PH2. DTRA Facility Access: Contractor(s) that require access to any DTRA facility in support of this work effort shall submit a Visit Authorization Letter (VAL) to DTRA J0XS7. The VAL shall use the format defined in the NISPOM, para 6-104. The VAL may be faxed to (505) 846-8983 or sent via the Joint Personnel Adjudication System (JPAS) to GQDD614. The visit duration will not exceed the period of contract performance. All classified visit requests shall be forwarded to the Program Manager for approval. The use of personally owned devices (PED) is prohibited in all DTRA facilities; contractor owned PEDs require pre-approval from DTRA J0XS7 to be introduced into a DTRA workspace. Unauthorized introduction of PED/contractor owned PEDs constitutes a security incident that will require a formal security incident inquiry/report for corrective action to be conducted. A DTRA proximity reader badge will be issued only to a contractor that must be in a DTRA workspace a minimum of three days per week or requires access to a DTRA-owned/managed computer network. A contractor will not be issued a DTRA proximity badge without receiving an in-processing security briefing.

- PH3. DTRA Facility Proximity Badges All personnel at DTRA (military, civilian, contractor or other government agency personnel) that require a permanent DTRA badge or access to the DTRA LAN must receive a DTRA J0XS7 in-processing security brief before issuance of a DTRA badge or access to the DTRA LAN. Contractors or other government agency employees working at or supporting DTRA must be in DTRA spaces a minimum of three days per week for a DTRA permanent badge to be issued to them. Some contractors or other government agency employees working at or supporting DTRA may be required to have a DTRA LAN account. Contractors or other government agency employees working at or supporting DTRA that will be issued a DTRA permanent badge or a DTRA LAN account must be in-processed by DTRA J0XS7.

- OC3. Security Agreement: The contractor shall comply with the Security Agreement (DD Form 441) including the NISPOM and any revisions to that manual, notice of which has been furnished to the contractor.

- OC4. Electronic Device Policy in DTRA Facilities: In accordance with DTRA instructions and policies, the use of personally owned electronic devices is prohibited in all DTRA facilities. Unauthorized introduction of such devices into the DTRA facility constitutes a security incident, which will be followed with a formal security incident inquiry/report for corrective action. Unless issued/approved by DTRA, all electronic devices which require access into the DTRA facility must be coordinated and approved through the Security and Counterintelligence, Technical Security Branch.

- OC5. Training: All in-house contractors must attend and complete the DTRA J0XS7 hosted “Initial Newcomers Security Training” and “Annual Security Awareness Training”.

- OC6. Notifications: The contractor is required to notify the COR of the following incidents; the COR will immediately notify DTRA J0XS7:

a. When a contractor employee working on this contract mishandles, fails to secure, or uses contract-provided information for personal use or personal gain.

b. When a contractor employee working on this contract expresses a desire of their security clearance to be downgraded, revoked or no longer wants access to classified information.

- OC7. Controlled Unclassified Information (CUI) Addendum: The following procedures will be used to protect CUI material:

HANDLING: Access to CUI material shall be limited to those employees that require the information to conduct work related to this contract. The CUI marking is assigned to material created by a DOD user agency. CUI is not a classification and does not meet the requirements to be classified but does require extra protection to insure the information (e.g., military plans, internal operating procedures, export controlled information, personal identifiable information, etc.) is not released to the public.

MARKING: CUI information will be marked IA W DoD 5200.1-R and the ISOO Marking Guide; for example FOUO; "FOR OFFICIAL USE ONLY" will be displayed at the bottom of each page and back cover (if any) of a document. If CUI is contained inside of a classified document:

a. Mark an individual paragraph containing CUI, but not classified material by placing the appropriate CUI marking at the beginning of the paragraph, i.e. "FOUO"

b. The top and bottom of each page that contains both CUI and classified material with the highest security classification of the material on that page.

c. The appropriate CUI marking at the bottom of each page that has CUI but does not have classified material.

d. If a classified document also contains CUI material or if the classified material becomes CUI when declassified, place the following statement on the bottom of the cover or the first page under the classification marking: "NOTE: If declassified, review the document to make sure material is not CUI and not exempt under DoD 5400-7-R before public release."

e. Mark all other contract-related records (e.g. computer print outs, photographs, films, tapes, slides) with the appropriate CUI marking or the appropriate abbreviation before the text begins, so the receiver can identify, and then safeguard, that record at its highest security classification level.

f. Mark each part of a message that contains CUI material. Unclassified messages containing CUI material must use portion marking to indicate that paragraph contains CUI.

g. Insure messages that transmit CUI material call attention to any CUI attachments.

h. CUI material released to a contractor by a DoD User agency must have the following statement on the front page or cover: "THIS DOCUMENT CONTAINS MATERIAL EXEMPT FROM MANDATORY DISCLOSURE UNDER THE FREEDOM OF INFORMATION ACT. EXEMPTION (S) ____ APPLYS." or other CUI control instructions as described in 5200.1-R, the ISOO Marking Guide or other regulatory guidance.

STORAGE: Protection of CUI material shall be conducted by the contractor IAW DoD 5200.1-r appendix 3 section AP3.2.4 or as amended. Procedures for protecting CUI on AIS systems and networks must be identified in the AIS/SPP provided to the CSA and to DTRA/SCQ. Expenditure of funds for security containers or closed areas for the sole purpose to protect CUI material is prohibited.

TRANSMISSION: CUI material shall be transmitted by the same methods as other unclassified material. Discussion of CUI material on the telephone is authorized if necessary for the performance of the contract. CUI material may be transmitted over telephone lines in digital form, by telecopy, or by other DSN Teletype lines without encryption.

RELEASE: CUI material shall not be released outside the contractor's facility except to representatives of the DoD or via the COR.

DESTRUCTION: When no longer needed, CUI material shall be disposed of by a method that precludes its disclosure to unauthorized individuals as further explained in Item 13d.

File details come from the government source that posted it. Updated .