Attachment_2_DD254_Litigation_Sppt.pdf

PDF 1 MB Posted

Attached to
Litigation Support Services Federal contract opportunity
Solicitation number
HQ0034-15-R-0017
Issued by
DOD Washington Headquarters Service

About this file

Attachment 2 DD254

View the file

Other files for this federal contract opportunity

Other files attached to Litigation Support Services, newest first.
File Type Posted
PWS_Litigation_Sppt_revised_20150807.pdf PDF
HQ0034-15-R-0017-0001_Amendment.pdf PDF
Attachment_1_PWS_Litigation_Sppt.pdf PDF
Solicitation_HQ0034-15-R-0017.xps XPS file
Attachment_3_PPQ_Litigation_Sppt.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DD254, Item 13………… Continuation Page

Government Customer Name: WHS ESD FOID

Prime Contract Number: TBD

Solicitation or Other Number: TBD

Contractor Name: TBD

PERSONALLY IDENTIFIABLE INFORMATION (PII)

- Contractor shall protect PII as required by laws and regulations (i.e. Privacy Act of 1974; DoD 5400.11-R;

DoDM 5200.1M Volume 4). A few of these safeguards are:

1. Immediately report known or suspected instances of a privacy breach to the security manager at: whs.pentagon.em.mbx.security-officers@mail.mil.

2. If involved in a breach, immediately attempt to recover the PII to bring it back under DoD control.

3. Pick up and safeguard PII found unprotected. 4. Enforce “need to know.”

5. Look for PII during “end of day checks.” 6. Store PII in a locked desk drawer or file cabinet.

7. Encrypt email containing PII. 8. Validate the recipient of PII requires PII for an official purpose.

9. Ensure all recipients on email require the PII before hitting “send.”

10. Use a burn bag to destroy PII.

11. Store and process PII only in approved customer locations.

12. Apply appropriate markings to documents and email that contain PII.

13. Do not store PII on laptops or other removable media.

14. If teleworking, access PII only through connection to the WHS network and using only a WHS issued laptop.

15. If teleworking, prevent family and friends from viewing PII.

16. Do not email PII to personal email accounts/servers (i.e. yahoo or gmail).

17. Password protect documents containing PII if you cannot encrypt an email.

18. Retrieve or clear PII from fax machines, printers, and copiers.

19. Escort visitors. 20. Do not discuss PII near unauthorized persons or in unauthorized locations.

21. Remove your CAC if you walk away from your computer.

22. Do no list PII on the subject line of emails.

23. If emailing PII outside of .mil for an official purpose and you cannot encrypt the email, you must password protect the document.

24. Do not share/use/post PII to social media sites or any publically accessible web site.

25. Do not post PII to a shared network drive/folder unless the folder is limited to access by those persons with an official “need to know.”

26. Do not store PII in a motor vehicle.

27. Do not place PII in trash cans or recycle bins 28. Do not store PII on CD/DVDs unless approved in writing by the COR/COTR.

29. Ensure 100% accountability of paper documents containing PII mailto:whs.pentagon.em.mbx.security-officers@mail.mil mailto:whs.pentagon.em.mbx.security-officers@mail.mil

Unauthorized Disclosure of Classified Information

a. Secretary of Defense memorandum “Deterring and Preventing Unauthorized Disclosures of Classified Information,” October 18, 2012.

b. Under Secretary of Defense (Intelligence) memorandum “Improving Policy and Procedures for Unauthorized Disclosure Reporting,” June 19, 2012.

Definitions:

a) Authorized Person – A person who has a favorable determination of eligibility for access to classified information, has signed an SF 312 nondisclosure agreement, and has a need to know for the specific classified information in the performance of official duties. Source: DoDM 5200.01 Vol 2.

o Need-to-Know – A determination made by an authorized holder of classified information that a prospective recipient requires access to specific classified information in order to perform or assist in a lawful and authorized governmental function. Source: DoDM 5200.01, Vol 3 o Unauthorized Disclosure – Communication or physical transfer of classified or controlled unclassified information to an unauthorized recipient. Source: DoDM 5200.01, Vol 3.

o Violation – Any knowing, willful, or negligent action that could reasonably be expected to result in an unauthorized disclosure of classified information. Source: DoDM 5200.01, Vol 3.

b) Contracting Officer (CO) – (DOD) The Service member or Department of Defense civilian with the legal authority to enter into, administer, modify, and/or terminate contracts. Source: JP 4-10

c) Contracting Officer Representative (COR) – (DOD) A Service member or Department of Defense civilian appointed in writing and trained by a contracting officer, responsible for monitoring contract performance and performing other duties specified by their appointment letter. Also called COR. Source: JP 4-10

d) Controlled Unclassified Information (CUI) – Unclassified information that requires safeguarding or dissemination controls, pursuant to and consistent with applicable law, regulations, and Government-wide policies. Source: DoDM 5200.01, Vol 4

e) Compromise – An unauthorized disclosure of classified information. Source: DoDM 5200.01, Vol 3.

f) Determining Need for Access. The individual with authorized possession, knowledge, or control of the information has the final responsibility for determining whether a prospective recipient’s official duties requires them to possess or have access to any element or item of classified information, and whether that prospective recipient has been granted the appropriate security clearance by proper authority. DoDM 5200.01, Vol 3.

g) Official DoD Information – All information that is in the custody and control of the Department of Defense, relates to information in the custody and control of the Department, or was acquired by DoD employees as part of their official duties or because of their official status within the Department.

h) Violation – Any knowing, willful, or negligent action that could reasonably be expected to result in an unauthorized disclosure of classified; or o Any knowing, willful negligent action to classify or continue the classification of information contrary to the requirements of Executive Order 13526, its implementing directives, or DoDM 5200.01-M.

o Any knowing, willful, or negligent action to create or continue a special access program contrary to the requirements of Executive Order 13526, DoDD 5205.07, or DoDM 5200.01. Source: DoDM 5200.01

i) Personal Responsibility for Safeguarding – Everyone who works with classified information is personally responsible for taking proper precautions to ensure that unauthorized persons do not gain access to classified information. Everyone granted access to classified information is personally responsible for protecting the classified information they know, possess, or control and for complying with the pre-publication security review processes specified in DoDD 5230.09 (Reference (k)). Classified information shall be protected at all times either by storing it as this Volume prescribes or by having it under the personal observation and control of an authorized individual. Source: DoDM 5200.01, Vol 3.

Applicable policies may include but not limited to; DoD Directives, Regulations, Manuals, Directive Type Memoranda, and other official guidance:

a) DoD 5220.22-M, National Industrial Security Program Operating Manual, February 28, 2006

b) DoDM 5200.01, Volumes 1 - 4, DoD Information Security Program, February 24, 2012

c) DoDI 8523.01, Communications Security (COMSEC), April 22, 2008

d) DoDM 5205.02-M, DoD Operations Security (OPSEC) Program Manual, November 3, 2008

e) DoDM 5105.21, Volumes 1-3, Sensitive Compartmented Information (SCI) Administrative Security Manual, October 19, 2012

f) DoD 5200.2-R, Personnel Security Program, January 1987

g) DoD 5400,11-R, Department of Defense Privacy program, May 14, 2007

h) DoDI 5240.06, Counterintelligence Awareness and Reporting (CIAR), May 17, 2011

i) DoDM 1000.13-M, Volume 1, DoD Identification (ID) Cards: ID Card Life-Cycle, January 23, 2014

j) Administrative Instruction 30, Force Protection on the Pentagon Reservation, June 26, 2009

k) DoDD 5210.50, Unauthorized Disclosure of Classified Information to the Public, July 22, 2005

l) Secretary of Defense memorandum, Deterring and Preventing Unauthorized Disclosures of Classified Information, October 18, 2012.

m) Under Secretary of Defense (Intelligence) memorandum, Improving Policy and Procedures for Unauthorized Disclosure Reporting, June 19, 2012.

Item 1a. Actual Performance

ITEM 1a. FACILITY CLEARANCE

- When access to DoD information is at a government facility/location, the contractor shall follow all local government policy and procedures to safeguard information (classified or unclassified).

- Personnel clearances/access shall be issued and posted in JPAS prior to access.

- The contractor shall ensure all required security education, training requirements, and/or re-certification is accomplished prior to access.

- When required (i.e., COMSEC, TEMPEST, SAP, SCI, etc), the contractor shall seek written approval from the

CO before subcontracting.

- Information/equipment shall be returned to the Government customer when no longer required for performance on this contract.

- Contractor shall immediately notify the customer and Whs.pentagon.em.mbx.security-officers@mail.mil if any information is missing/lost/stolen/compromised.

Item 8. Actual Performance

ITEM 8. ACTUAL PERFORMANCE

- 4800 Mark Center Drive, Ste 02F09-02, Alexandria, VA 22350 mailto:security@whs.mil

Item 10. Actual Performance

Item 10. Contractor Will Require Access To:

Access at the facility listed in 6a?

Access at the Gov’t customer’s facility?

NSA

COMSEC

account required?

DIA

Accredited

SCIF

required?

Notes

a. COMSEC Information

NO NO NO

b. Restricted Data NO YES

c. CNWDI NO YES

d. Formerly Restricted Data

NO YES

e(1) SCI NO YES NO e(2) Non-SCI NO YES

f. Special Access

g. NATO

h. Foreign Gov’t

i. Limited Dissemination

NO NO

j. For Official Use Only (FOUO)

k. Other (Contractor will Require Access To) i.e., CUI, PII, etc.

ITEM 10b. RESTRICTED DATA

- Contractor shall obtain government approval for access to Restricted Data and follow government policy to safeguard Restricted Data.

- Contractor shall not have access to Restricted Data until all approvals are in place and access recorded in the Joint Personnel Adjudication System (JPAS).

ITEM 10c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI)

- Contractor shall obtain government approval for access to CNWDI and follow government policy to safeguard CNWDI.

- Contractor personnel shall not have access to CNWDI until all approvals are in place and access recorded in JPAS.

- GCA approval is required prior to granting CNWDI access to a subcontractor.

ITEM 10d. FORMERLY RESTRICTED DATA

- Contractor shall obtain government approval for access to Formerly Restricted Data and follow government policy to safeguard Formerly Restricted Data.

- Contractor shall not have access to Formerly Restricted Data until all approvals are in place and (Restricted Data) access recorded in JPAS.

ITEM 10e(1). SENSITIVE COMPARTMENTED INFORMATION (SCI)

- Contractor shall obtain government approval for access to SCI and follow government policy to safeguard

SCI.

- Contractor shall not have access to SCI until all approvals are in place and SCI access recorded in JPAS.

- Contractor shall not have access to SCI until all approvals, briefings, non disclosures are signed and SCI access recorded in JPAS.

- Prior approval of the GCA is required before a subcontract involving access to SCI can be issued.

ITEM 10e(2). NON SCI

- Contractor shall obtain government approval for access to Non-SCI and follow government policy to safeguard Non-SCI.

- Contractor shall not have access to Non-SCI until all approvals are in place and SCI access recorded in JPAS.

- Prior approval of the GCA is required before a subcontract involving access to Non-SCI can be issued.

ITEM 10f. SPECIAL ACCESS INFORMATION

- Access to SAP information requires approval from the SAP Program Security Office.

- Contractor shall follow government policy to safeguard SAP information.

- If access to Special Access Information is subcontracted, the prime contractor is responsible to incorporate additional security requirements.

ITEM 10g. NATO INFORMATION

- Contractor shall obtain government approval for access to NATO information and follow government policy to safeguard NATO information.

- Contractor shall not have access to NATO information until all approvals are in place and NATO access recorded in JPAS.

- The prime contractor must receive approval from the GCA to grant NATO access to a subcontractor.

ITEM 10h. FOREIGN GOVERNMENT INFORMATION

- Contractor shall obtain government approval for access to Foreign Government Information and follow government policy to safeguard Foreign Government Information.

- The prime contractor must receive approval from the GCA to grant access to a subcontractor.

ITEM 10j. FOR OFFICIAL USE ONLY (FOUO)

- FOUO and/or other types of Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as required by government policy.

- Contractor shall:

o Ensure Personally Identifiable Information (PII) (also a type of CUI) protected under the Privacy Act

Program is safeguarded as required by government policy.

o FOUO markings applied to information shall not be removed or altered unless approved in writing by the originator of the information.

o Enforce “need to know.”

o Not release FOUO information to unauthorized persons to include the public/media.

o Destroy FOUO information by approved methods (e.g. burn bag).

ITEM 10k. OTHER (CONTRACTOR WILL REQUIRE ACCESS TO)

- Official DoD Information.

o See Definitions.

Item 11. In Performing This Contract, The Contractor Will

ITEM 11a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER CONTRACTOR’S FACILITY

OR A GOVERNMENT ACTIVITY

- Refer to Item 8 for actual performance location.

ITEM 11e. PERFORM SERVICES ONLY

- See Item 9.

ITEM 11l. OTHER (specify)

GOVERNMENT POLICY

- The fact that specific wording may not be written in this DD254 does not constitute a waiver to comply with government policy.

PENTAGON BADGE

- If a Pentagon Badge is required for performance on this contract, each individual must have at a minimum, a completed favorable NCIC check before issuance.

- Contractor shall follow instructions provided to complete this process.

- Badges shall be used only for an official authorized purpose in performance of this contact.

- Photocopying/duplicating of badges is prohibited.

- All badges shall be returned when expired or no longer required for performance of this contract. Return badges to:

WHS Security 4800 Mark Center Drive, 03F09-02 Alexandria, VA 22350

COMMON ACCESS CARD (CAC)

The government issued credential (CAC) is the property of the U.S. Government and shall not be retained by the cardholder upon expiration, replacement, or when the DoD affiliation of the employee has been terminated.

Unauthorized possession of an official credential, like a CAC, can be prosecuted criminally under section 701, title 18, United States Code.

- All CACs shall be returned when expired or no longer required for performance of this contract. The CAC must be returned to the issuing office or the DA&M WHS Security Manager at:

WHS Security 4800 Mark Center Drive, 03F09-02 Alexandria, VA 22350

- If a CAC is required for performance on this contract (access to DoD information systems or facilities) each individual must have at a minimum, a completed favorable NACI. Other acceptable (favorable) background checks are:

o BI, BIPN, BIPR, CNCI, IBI, LBI, LBIP, LBIX, MBI, NACB, NACLC, NACS, NLC, NNAC, NSI, PPR, PRI, PRS, PRSC, PTSBI, SBBI, SBPR, SSBI.

- Individuals who require a security clearance to perform on this contract will be issued a CAC when appropriate based on the favorable results of ongoing or previous background checks. Favorable results of a background check and eligibility of a security clearance must be posted to JPAS.

- Individuals who do not require a security clearance to perform on this contract will be processed for a NACI background check by WHS (if the individual does not have a prior acceptable favorable background check).

- Individuals must comply with requirements for submission of the NACI check. Coordinate with the CO and the government customer.

- Non-U.S. persons (foreign nationals) who require a CAC card to perform on this contract must meet one or more of the following conditions:

o Possess legal residence status in the United States for a minimum of 3 years, favorable FBI fingerprint check, and initiation for a NACI background check.

o Possess a favorably adjudicated NACI or equivalent investigation.

o Meets investigation requirements for DoD employment as recognized through international agreements pursuant to ‘Employment of Foreign National” section of DoD 1400.25-M o Possess a visit status and security assurance that has been confirmed, documented, and processed in accordance with international agreements pursuant to DoDD 5230.20

- A CAC will be issued by WHS when appropriate.

INFORMATION SYSTEMS

- Personnel occupying Information Assurance management or user access positions must have the appropriate investigation level, security clearance and approval(s) in place.

- Contractor shall ensure DoD information is processed according to government policy. Some policy requirements are:

o DoD information shall be processed only on DoD approved information systems.

o Classified information shall be processed only on information systems approved for classified processing at the appropriate level.

o DoD information shall not be processed on Non DoD approved information systems (e.g.

personal/home/contractor computers).

o Contractor shall not modify DoD information systems or introduce hardware or software unless approved by the CO and government customer.

o Contractors shall not use removable media (e.g. thumb drives, CDs) to store DoD information.

WIRELESS SECURITY POLICY

http://www.law.cornell.edu/uscode/18/701.shtml http://www.law.cornell.edu/uscode/18/701.shtml

- The contractor shall not install or operate wireless access points (e.g. Hot spots, routers) or any other Radio Frequency (RF) installation without prior Reservation Installation Application (RAI) approval.

- Contractor shall not bring personnel electronic devices (e.g. cell phone) into any secure facilities.

DOD COMPUTING SECURITY BEST PRACTICES

- Contractor shall follow these best practices.

DO:

- Complete IA awareness training.

DON’T:

- Process DoD information on personal computer devices.

- Use digital signatures for DoD email.

- Transfer data using commercial web email.

- Use encryption to safeguard CUI.

- Obtain a threat briefing if traveling OCONUS.

- Download files from commercial web email or entertainment sharing sites to DoD computers.

- Open emails from unknown users or suspicious emails.

- Remove your CAC from devices when you are not physically present.

- Report suspicious emails and/or activities to Security.

- Discuss DoD information in public places.

- Use unknown computers to charge DoD devices.

- Encrypt Personally Identifiable Information

(PII).

- Use DoD procured and/or owned removable storage media on non-government networks and computers.

- Click on pop-up messages or unknown links.

- Store passwords on electronic devices or online.

- Email DoD information to personal email accounts such as yahoo/hotmail.

- Email Personally Identifiable Information (PII) to personal emails accounts such as yahoo/hotmail.

DOD MOBILE DEVICE SECURITY BEST PRACTICES

- Contractor shall follow these best practices.

DO: DON’T:

- Obtain threat awareness training on wireless usage in public areas.

- Use wireless headsets or hands free devices.

- Disable wireless devices when not in use.

- Bring wireless enabled devices into classified areas and/or introduce wireless enabled devices into DoD GFEs (e.g. laptop, desktop).

- Use the CAC for authentication.

- Connect a blackberry type device to public wireless internet access points.

- Password protect wireless devices.

- Leave wireless devices unattended.

- Remove and secure removable media and peripheral devices when not in use.

- Use text messaging services to discuss sensitive information.

- Lock and secure devices when not in use.

- Accept Bluetooth connection requests.

- Immediately report lost or stolen devices to Security.

- Use removable storage media unless specifically approved by the GSA or government customer.

- Use personally procures and/or owned removable storage media on DoD networks and computers.

SECURITY OF UNCLASSIFIED DOD INFORMATION ON NON-DOD INFORMATION SYSTEMS

- Contractor is not authorized to process Unclassified DoD information on Non-DoD Information Systems.

o Non-DoD Information Systems are defined as: Any information system that is not owned, used, or operated by the Department of Defense AND that is not used or operated by a contractor or other non- DoD entity on behalf of the Department of Defense.

WEB SITES

- Contractor shall not post DoD information to any DoD controlled restricted web site unless approved by the CO and government customer.

- Contractor shall not post DoD information to any publicly accessible web.

PERSONAL DEVICES

- Contractor shall not use any personal or other non DoD approved devices (e.g. laptops, cell phones, pda’s, cameras, voice recorders) to store, receive, process or transmit DoD information.

COMPLIANCE WITH GOVERNMENT CUSTOMER SECURITY PROGRAMS

- Contractor shall comply with government customer programs designed to safeguard information, facilities, equipment and personnel by complying with established education & awareness programs and operating procedures including but not limited to: Information Security, Physical Security, Personnel Security, Communications Security, Information System Security, Controlled Unclassified Information, Operations Security, Counterintelligence, Anti Terrorism Force Protection and Emergency Planning.

ORIGINAL CLASSIFICATION AUTHORITY

- NOT AUTHORIZED.

DERIVATIVE CLASSIFICATION

- Derivative Classification may not be performed until an approved Security Classification Guide is provided to the contractor by the CO and/or government customer.

- Personnel at government location performing this function must first complete training at dss.mil. Create a STEPP account. Complete course code: IF103.16. Email the certificate of completion to:

whs.pentagon.em.mbx.security-officers@mail.mil.

- Contractor shall not re-word, modify or otherwise alter originally classified information.

DECLASSIFICATION & DOWNGRADING OF CLASSIFIED INFORMATION

- Declassification & downgrading of classified information is prohibited.

UNAUTHORIZED PUBLIC DISCLOSURE OF CLASSIFIED INFORMATION

- Contractor shall not release any classified information to the public.

o Public disclosure includes but is not limited to: person to person, the internet, social web sites, newspapers, television, radio.

- Contractor shall report known or suspected instances of unauthorized public disclosure of classified information.

- Contractor shall report known or suspected unauthorized disclosures to the CO, government customer and the DA&M WHS Security Manager at Whs.pentagon.em.mbx.security-officers@mail.mil.

o At a minimum include the information described at Enclosure 3 of Reference J.

o Additionally the Contractor shall:

Not include classified information when reporting the incident via unclassified telephone or unclassified computer systems.

Not confirm or deny the existence of classified information to the media or public.

Not save, copy, paste classified information to DoD networks or to personal or company computer systems.

Not print classified information.

Not share classified information with unauthorized persons.

Follow instructions provided by the government.

Understand the classified information disclosed to the public remains classified and still requires safeguarding. Only an Original Classification Authority can declassify the information.

o Refer queries from the public, media, or press to the DA&M WHS Security Manager.

o Refer all Congressional queries to the DA&M WHS Security Manager.

VIOLATIONS

- Beyond NISPOM required actions, the contractor shall also report to the CO and government customer (Whs.pentagon.em.mbx.security-officers@mail.mil) all suspected or known violations to safeguard DoD information, equipment, facilities, personnel.

HAND CARRYING CLASSIFIED MATERIAL

- Hand carrying is limited to the Washington/Baltimore regional area.

- Contractor shall comply with the government security requirements (below).

o Contractor shall receive training, be issued a courier card and have a lockable double courier bags to hand carry classified information.

- Travel by aircraft with classified information is prohibited.

TELEWORK

Telework with classified information is prohibited.

- If approved to Telework, Telework must be accomplished by connection to the WHS established network using a DoD approved laptop.

mailto:whs.pentagon.em.mbx.security-officers@mail.mil o Telework with DoD information in paper form or on removable media (e.g. CDs) is prohibited.

DISPOSITION OF DOD INFORMATION

- Contractor shall return all DoD information used in performance of this contract when no longer needed or upon conclusion of this contract, whichever occurs first.

PROPERTY

- Contractor shall return all property to the government customer when no longer required for performance of this contract.

PHOTOGRAPHY/RECORDINGS

- Recording images/audio (by any means) of DoD information, equipment, personnel or facilities is prohibited.

CONTINUED RESPONSIBILITY

- Safeguarding DoD information is a lifelong obligation.

- Upon completion of this contract, Contractor shall continue to safeguard classified information, Controlled

Unclassified Information, and any other information they have had access to or knowledge of.

- Contractor shall report attempts by unauthorized persons to gain access to information. Send email notification to the DA&M WHS Security Manager at: Whs.pentagon.em.mbx.security-officers@mail.mil.

Notify the CO and government customer. Do not send classified information in this notification.

Item 12. Public Release

- Safeguarding DoD information is a lifelong obligation.

- Any DoD information intended for publication or dissemination must undergo a security and policy pre-publication review. This includes, but is not limited to:

o Books o Manuscripts and theses o Biographies o Articles o Book reviews o Audio/video materials o Speeches o Press releases o Conference briefings o Research papers o Gaming materials o Other media

- Prior to initiating a security review ensure the owner (Government Agency) of the information has conducted an internal security review and written guidance has been provided.

- Report unauthorized releases of DoD information to: Whs.pentagon.em.mbx.security-officers@mail.mil.

Item 14. Additional Security Requirements

- Item 10e(1). All access to SCI will be on-site at the customer location and the contractor will follow government policy to safeguard SCI.

- Contractor shall not have access to SCI until all approvals, briefing and non-disclosures are in place and SCI accesses recorded in JPAS.

Item 16e. Signature

This DD254 is limited to the validation of security requirements. Expenses necessary to comply with security requirements is strictly between the contracting office, government customer and the contractor.

Questions About This DD Form 254

Please contact the DA&M WHS Security Manager at: Whs.pentagon.em.mbx.security-officers@mail.mil.

END OF ITEM 13

(FOUO)_DD254-Litigation Support_ESD-FOID_20150626_Page_1
(FOUO)_DD254-Litigation Support_ESD-FOID_20150626_Page_2
(FOUO)_Item13-Litigation Support_ESD-FOID_20150626

File details come from the government source that posted it. Updated .