Exhibit_6_DD254_AdditInfo_01062017.pdf
PDF 159 KB Posted
- Attached to
- Construction Management Technical Support Services (CMTSS) Federal contract opportunity
- Solicitation number
- HQ003417R0028
- Issued by
- DOD Washington Headquarters Service
About this file
Exhibit 6b DD254 Supplemental Information
View the file
Other files for this federal contract opportunity
Show all 25
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Continuation Pages Item #13 of DD254
Contract No: TBD
ITEM 10j. FOR OFFICIAL USE ONLY (FOUO)
-FOUO and /or other types of Controlled Unclassified Information (CUI) provided under this contract shall be safeguarded as required by government policy.
-Contractor shall ensure Personally Identifiable Information (PII) protected under the Privacy Act Program is safeguarded as required by government policy.
-FOUO markings applied to information shall not be removed or altered unless approved in writing by the originator of the information.
-Enforce “need to know”
-Do not release FOUO information to unauthorized persons to include the public.
-Destroy FOUO information by approved methods (e.g. burn bags) at the Pentagon, Mark Center, and RRMC facilities.
10k OTHER
-Official DoD Information.
-Defined as: All information that is in the custody and control of the Department of Defense, relates to information in the custody and control of the Department, or was acquired by DoD employees as part of their official duties or because of their official status within the department.
-Classified information up to the level indicated in item 1a.
-The contractor shall coordinate with Defense Security Service for processing personnel security clearances.
-Personnel Security Clearances have been issued.
-Contractor must have an active valid facility clearance equal to the level of the contract.
-Personnel selected to work on the contract must possess an active final security clearance at the level of the contract, interim clearances will not be accepted.
-Each individual has received required initial/refresher security training.
-Each individual has completed a Standard Form 312 Classified Non-Disclosure Agreement.
-The security clearance has been posted in JPAS and sent to Government Agency Security Manager.
-Contractor shall comply with Government policy to safeguard classified information.
-Contractor shall not release any DoD/Federal Government/Foreign Government information to any unauthorized person/entity.
-Personnel and contractors participating in the project management of SCIFs should be performed by U.S. companies using U.S. citizens to reduce risk, but may be performed by U.S.
companies using U.S. persons (an individual who has been lawfully admitted for permanent residence as defined in 8 U.S.C. § 1101(a)(20) or who is a protected individual as defined by Title 8 U.S.C. § 1324b (a)(3)).
ITEM 11L. IN PERFORMANCE OF THIS CONTRACT, THE CONTRACTOR WILL:
-Contractor shall successfully complete training related to derivative classification. Refer to Defense Security Service Training (if applicable).
-Contractor shall comply with security classification guidance when generating classified information (if applicable).
-Contractor shall ensure appropriate government approvals are in place to store classified information at the facility listed in item 6a.
-Contractor shall comply with government policy for access to and safeguarding of classified information.
-Contractor shall follow government policy for access to and safeguarding of all government information, facilities and equipment.
-The fact specific wording may not be written in this DD254 does not constitute a waiver to comply with government policy.
-Prime contractor shall have an active SECRET facility clearance
-RRMC personnel and contractors must have an active SECRET clearance & active SECRET facility clearance
HAVE OPSEC REQUIREMENTS
-OPSEC promotes mission effectiveness by preserving essential secrecy about US intentions, capabilities, and current activities. Refer to DoD 5220.22R (Industrial Security Regulation), DoD 5220.22-M Sup 1 (National Industrial Security Program Operating Manual), and 5205.02 (DoD Operations Security Program).
OPSEC is concerned with all sources of OPSEC is directed towards protection of UNCLASSIFIED intelligence on classified or sensitive programs of such nature that disclosure of the indicators may lead to the compromise whenever open sources (such as technical articles, press releases, national publications, congressional records, or contract awards) provide information that hostile intelligence services (HOIS) can piece together resulting in actions harmful to US interest. It covers the total problem by addressing vulnerabilities, countermeasures and weaknesses in a program which could lead to the disclosure of classified information. Unlike other security programs, OPSEC doesn’t really lend itself to complete identification of security requirements (countermeasures) during initial contract preparation.
Input from the contractor in the form of an OPSEC plan must be developed and provided by the Contractor. OPSEC countermeasures and plans must be flexible to address changes in the threat environment.
The contractor shall provide a written OPSEC plan to the COR for review and approval by the OPSEC Officer. The plan must contain detailed procedures and actions to be taken by the prime contractor and or sub-contractor for the protection of hard copy and electronic information as well as physical security of the contractor facilities, access control procedures, etc, that afford protection to the information.
The contractor shall comply with OPSEC requirements imposed by any program supported. The contractor must develop OPSEC guidance as required by the Statement of Work/Performance of Work. OPSEC is a structured process that identifies critical information, analyzes friendly actions, integrates threat analysis and risk assessments and then helps personnel apply protective measures to mitigate unacceptable risks.
Contractors and their personnel supporting WHS (including all subordinate activities), must have OPSEC awareness and education/training initially and annually as required by the Government.
HAVE INSIDER THREAT PROGRAM
On May 18, 2016, the Department of Defense published Change 2 to DoD 5220.22-M, “National Industrial Security Operating Manual (NISPOM).” NISPOM Change 2 requires contractors1 to establish and maintain an insider threat program to detect, deter and mitigate insider threats. Specifically, the program must gather, integrate, and report relevant and credible information covered by any of the 13 personnel security adjudicative guidelines2 that is indicative of a potential or actual insider threat to deter cleared employees3 from becoming insider threats; detect insiders4 who pose a risk to classified information; and mitigate the risk of an insider threat.5 Contractors must have a written program plan in place to begin implementing insider threat requirements of Change 2 no later than November 30, 2016.
Industrial Security Letter 2016-02 (ISL2016-02) provides clarification and guidance to assist contractors as they establish and tailor an insider threat program to meet NISPOM Change 2 requirements.
Insider Threat Minimum Standards for Contractors
NISPOM 1-202 requires the contractor to establish and maintain an insider threat program that will gather, integrate, and report relevant and available information indicative of a potential or actual insider threat. DSS will consider the size and complexity of the cleared facility in assessing its implementation of an insider threat program to comply with NISPOM Change 2.
COMMON ACCESS CARDS
-The government issued credential (CAC) is the property of the U.S. Government and shall not be retained by the cardholder upon expiration, replacement, or when the DoD affiliate of the employee has been terminated. Unauthorized possession of an official credential like a CAC can be grounds for prosecution under section 701, title 18, US Code.
-If a CAC is required for performance of this contract, each individual must have at a minimum, a completed favorable NACI.
-Individuals who require a security clearance in performance of this contract will be issued a CAC when appropriate based on favorable results of the background check and eligibility of a security clearance posted in JPAS.
-Individuals who do not require a security clearance in performance of this contract will be processed for an HSPD-12 NACI through WHS if a prior investigation is not valid to meet the requirements of a CAC.
-Contractor shall follow instructions provided to complete this process.
-All CACs shall be returned to the Government when expired or no longer needed for performance of this contract.
ACCESS TO DOD INFORMATION SYSTEMS
-Contractor shall ensure DoD information is processed according to government policy. Some policy requirements are:
-DoD information shall be processed only on approved DoD information systems.
-Classified information shall be processed only on information systems approved for classified processing at the appropriate level.
-DOD information shall not be processed on non-DoD approved information systems (e.g.
personal computers/contractor computers.
-Contractor shall not modify DoD information systems or introduce hardware or software unless approved by the government customer.
-Contractors shall not use removable media (e.g. thumb drives, CDs) to store DoD information.
WIRELESS SECURITY POLICY
-Contractor shall not operate wireless access points (e.g. Hot Spots, routers) or any other Radio Frequency (RF) installations.
VIOLATIONS
-Contractor shall not
-Contractor shall report all suspected or known security violations to safeguard DoD information, equipment, facilities, and personnel to the Government Contracting Officer and Security Manager.
PROPERTY
-Contractor shall return all property to the DoD (government customer) when no longer required for performance of this contract.
CONTINUED RESPONSIBILITY
-Upon completion of the contract, the contractor shall continue to safeguard classified information, controlled unclassified information, and any other information they have had access to or knowledge of.
-Contractor shall report attempts by unauthorized persons to gain access to information. Notify the government customer but do not send any classified information in this notification.
Filename: Additional Security Requirements FM Block 13 Cont 20161221 REV1.docx
Directory: C:\Users\Houser\Documents\My Documents\DD254\CMTSS Template: C:\Users\Houser\AppData\Roaming\Microsoft\Templates\Normal.dotm Title:
Subject:
Author: EITSD Keywords:
Comments:
Creation Date: 1/5/2017 3:33:00 PM Change Number: 2 Last Saved On: 1/5/2017 3:33:00 PM Last Saved By: Ronald House Total Editing Time: 1 Minute Last Printed On: 1/5/2017 3:33:00 PM As of Last Complete Printing Number of Pages: 6 Number of Words: 1,539 (approx.)
Number of Characters: 8,773 (approx.)
| 2017-01-05T15:35:35-0500 | |
| HOUSE.RONALD.1022161853 |
File details come from the government source that posted it. Updated .