RFP_Attachment_7_DD254_Revised.pdf
PDF 70 KB Posted
- Attached to
- DDS Crowdsourced Vulnerability Discovery & Disclosure Services (CVDD) FA2 Federal contract opportunity
- Solicitation number
- HQ003418R0202
- Issued by
- DOD Washington Headquarters Service
About this file
RFP Amendment 0002_Attachment 7 Revised DD254
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP_Attachment_7_DD254_Revised_copy_(2).pdf | ||
| RFP_Amendment_Attachment_5_CLINs_IDIQ_Provisions_and_Clauses.pdf | ||
| RFP_Amendment_0001_Attachment_2_IDIQ_PWS_080218.pdf | ||
| RFP_Amendment_0001_Attachment_1_HQ0034-18-R-0202_080218.pdf | ||
| RFP_Amendment_0001__Attachment_8___Questions_FINAL_080118_(002).pdf | ||
| RFP__Amendment_0001_Attachment_3_Task_Order_PWS_080218.pdf | ||
| RFP_Amendment_0001_Attachment_4_Task_Order_Pricing_Template_v2.xlsx | XLSX spreadsheet | |
| FINAL_RFP_Attachment_7_DD254.pdf | ||
| RFP_Attachment_4_Task_Order_Pricing_Template.xlsx | XLSX spreadsheet | |
| FINAL_RFP_Attachment_1_HQ0034-18-R-0202.pdf | ||
| FINAL_RFP_Attachment_5_CLINs_IDIQ_Provisions_and_Clauses.pdf | ||
| FINAL_RFP_Attachment_2_IDIQ_PWS.pdf | ||
| FINAL_RFP_Attachment_3_Task_Order_PWS.pdf | ||
| FINAL_RFP_Attachment_6_Task_Order_Provisions_and_Clauses.pdf |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of AEM LiveCycle Designer
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List of Attachments (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)
| CurrentPage: |
| PageCount: |
| Classification: |
| SerialNum: |
| a. Facility clearance level. Select one.: 2 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Choose Yes or No: 0 |
| Choose Yes or No: 1 |
| Prime: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 1 |
| Choose Yes or No: 0 |
| Soli: TBD |
| DueDate: |
| dateA: 2018-06-26 |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 1 |
| No: 1 |
| No: 1 |
| No: 1 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: TBD |
| Name: N/A |
| Name: Thomas Prudhomme |
| Cage: TBD |
| CSO: TBD |
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: |
See Item 6a., and at government facilities Block9:
Conduct crowdsourced vulnerability discovery and disclosure (CVDD) services across the full range of networks, systems, and information, including web applications, software, source code, and software-embedded devices across the whole Department of Defense.
| a: 0 |
| a: 1 |
| a: 1 |
| f: 0 |
| f: 0 |
| f: 0 |
| b: 0 |
| b: 0 |
| b: 0 |
| g: 0 |
| g: 0 |
| c: 0 |
| c: 0 |
| c: 1 |
| h: 0 |
| h: 0 |
| d: 0 |
| d: 0 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 0 |
| NonSCI: 0 |
| j: 1 |
| j: 0 |
| k: 1 |
| k: 0 |
| Enter your name here.: See Item 13 Security Guidance |
| Enter your name here.: See Item 13 Security Guidance |
| e: 1 |
| e: 1 |
| l: 1 |
| m: 1 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: Defense Office of Prepublication and Security Review (DOPSR) |
1155 Defense Pentagon Washington, DC 20301
| PublicAuthority: Coordinate with DOPSR |
| AddSig: |
| RemoveSig: |
| text: ITEM 10j CUI |
The contractor will have access to CUI which is not classified information, but does require protection from unauthorized disclosure. Refer to DoDM 5200.01, Volume 4, “DoD Information Security Program: Controlled Unclassified Information (CUI), available at: http://www.esd.whs.mil/DD/
PERSONALLY IDENTIFIABLE INFORMATION (PII)
The contractor will likely have access to PII. PII (e.g. social security number, medical information) must be safeguarded as CUI. The Contractor:
- Will ensure any PII is safeguarded as required by existing statutory; regulatory; and policy requirements.
- Will ensure all employees complete Privacy Act training provided via icompass.
- Will not intentionally view PII of any individual unless officially needed in performance of this contract.
- Will not share PII with anyone who does not have an official need to know.
- Will process PII only on government approved systems/equipment.
- Will report immediately to the Government owner of the system storing PII and to the WHS Security Office any known or suspected failure to safeguard PII.
The contractor must ensure CUI is processed only on government approved systems or as specified below under DOD INFORMATION ON NON-DOD INFORMATION SYSTEMS. Although the contractor must comply with all requirements to safeguard CUI, common requirements include: Enforce need to know; access CUI only for an official purpose; do not store CUI on removable media; keep CUI at authorized work locations; encrypt email containing CUI; lock CUI in desk drawers/file cabinets when not in use; dispose of CUI using burn bags; do not post CUI to publically accessible websites.
PROPRIETARY INFORMATION
Proprietary information must be safeguarded as CUI. Proprietary information is information such as trade secrets and commercial or financial information obtained from a company on a privileged or confidential basis that, if released, would result in competitive harm to the company, impair the Government’s ability to obtain like information in the future, or impair the Government’s interest in compliance with program effectiveness. The contractor will immediately notify the COR of any conflicts of interests.
DOD INFORMATION ON NON-DOD INFORMATION SYSTEMS
GCA and appropriate GPM approval is needed to process DoD information on non-DoD information systems. Adequate security must be provided for all unclassified DoD information (which includes CUI) on non-DoD information systems. A non-DoD information system is any information system that is not owned, controlled, or operated by the DoD and that is not used or operated by a contractor or other non-DoD entity exclusively on behalf of the DoD. For additional information refer to DoD Instruction 8582.01 “Security of Unclassified DoD Information on Non-DoD Information Systems.”
ITEM 10k. OTHER
DOD COMPUTER SECURITY
The contractor will have access to government provided unclassified systems (NIPRNET). With approval from the GCA and appropriate GPM, the contractor will have access to classified systems (SIPRNET). The contractor must meet all requirements before accessing a particular information system. Information systems must be used only for the official government purpose specified in this contract. Although the contractor must comply with all government laws, rules, and regulations for use of information systems, common requirements include: do not process classified information on systems of a lower classification or unclassified level; complete mandatory initial and annual cyber awareness training; enforce need to know; do not allow others to use your CAC or password to access a system; do not introduce hardware/software/USB devices to a government system unless specifically approved by the owner of the information system; follow procedures to address suspicious email (e.g. phishing); do not introduce personal wireless hot spots or portable electronic devices (e.g. cell phone) into spaces where classified or sensitive information is processed/stored; do not post DoD information to publicly accessible web sites; do not process DoD information on personal devices (e.g. cell phone, laptop, camera, voice recorders); use of thumb drives is prohibited; Government equipment must be returned when no longer required for performance on this contract.
ITEM 11a / ITEM 11e.: Classified information covered under this contract is the property of the U.S. Government regardless of proprietary claims. Classified information and materials shall be protected in accordance with established policies and procedures. Specific classification guidance will be provided on individual tasks by the GCA, GPM and CORs / COTRs as needed to support this effort. In any case where classification guidance has not been provided, the contractor is to safeguard the information and seek written guidance from the GCA and GPM prior to release of the information. Upon completion /termination of this contract the U.S. Government will be contacted for the disposition of or distribution of classified materials.
- Contractors must restrict access to only those individuals who possess the necessary security clearance and who are actually providing services under the contract with a valid need-to-know. Further dissemination to other contractors, subcontractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the GCA, GPM and appropriate approving official. The designated custodian shall comply with NISPOM requirements for receipt or accounting of classified material received under this contract.
- Upon completion / termination of the classified contract the contractor will return all classified information. Within 30 days after the final product is received and accepted by the procuring agency, all classified materials released to the contractor, must be returned to the originating agency. Requests to retain materials shall be directed to the GCA and GPM in writing with a full justification for retention identified.
PERSONNEL SECURITY CLEARANCE
Personnel security clearances along with additional accesses if required (e.g. NATO), must be annotated in the DoD personnel security system of record (e.g. JPAS). Contractor will immediately notify the COR and WHS Security Office of any issues affecting a person’s eligibility for access to classified information. Cleared personnel with a minimum of an Interim Secret clearance are required to perform this service because access to classified information cannot be precluded. The contractor is not authorized to release classified information to any activity or person, including sub-contractors, without the government GCA's written approval. Only with the expressed permission of the GCA and GPM may the contractor reproduce any classified information / materials. All requirements for control and accounting for original documentation and copies apply.
IITEM 11m. OTHER
IN/OUT PROCESSING
The contractor must complete in-processing upon entry to the contract and out-processing prior to departing from this contract. All government property and information must be returned at or before out-processing.
COMMON ACCESS CARD (CAC)
If required by GPM, A CAC will be issued as required for access to facilities and/or information systems. Personnel must meet and maintain investigative and adjudicative requirements specified in DoDI 5200.46, and immediately report to the WHS Security Office any issues affecting eligibility to possess a CAC. Government issued credentials are the property of the United States Government and must be returned when no longer required for performance on this contract. Return CACs to: WHS Security Office, 4800 Mark Center Drive, Suite 03F09-02, Alexandria, VA 22350.
DESTRUCTION OF INFORMATION
Information not already formally approved for public release must be destroyed using approved methods.
PHOTOGRAPHY/RECORDING
The recording of DoD information, equipment, personnel, and facilities by any means is prohibited.
ITEM 12 PUBLIC RELEASE
Release of DoD information to the public or other unauthorized recipient is prohibited. All DoD information intended for publication or dissemination must undergo a security and policy pre-publication review. This material includes, but is not limited to: books, manuscripts and theses, biographies, articles, book reviews, audio/video materials, speeches, press releases, conference briefings, research papers, gaming materials and other media. The Government must initiate the release process and the proposed information must be reviewed by the WHS Security Office. Unauthorized releases must be reported to the WHS Security Office. For more information visit the DOPSR website: http://www.esd.whs.mil/DOPSR/
ORIGINAL CLASSIFICATION AUTHORITY IS NOT AUTHORIZED
If the contractor believes information not currently classified, requires classification, the contractor will immediately notify the GCA and appropriate GPM.
DERIVITIVE CLASSIFICATION
Is not authorized unless pacifically approved by the GCA and appropriate GPM for each person who has a demonstrated need for the requirement; training must be completed.
DECLASSIFICATION AND DOWNGRADING OF CLASSIFIED INFORMATION IS NOT AUTHORIZED
SAFEGUARDING COMPONENT INFORMATION, INCLUDING BY COMPILATION
Contractor must ensure information collected from any DoD Component is safeguarded as prescribed by that component (e.g. classified, CUI). Contractor must also ensure proper safeguarding of Component information as it is compiled with information collected from other DoD Components. For example: compilations of information that are individually unclassified, may be classified if the information [combined] qualifies for classification. Classification by compilation requires an original classification decision by an authorized Original Classification Authority.
Contractor must consider compilation initially and continually to ensure information is processed on appropriate computer systems (to prevent data spills) and information is not released to unauthorized persons
HAND CARRYING CLASSIFIED INFORMATION
If required, hand carrying is limited to the NCR; a courier card must be issued by the WHS Security Office; couriers must complete required training. Travel with classified information via aircraft is prohibited.
TELEWORK
Use of classified information is prohibited. Unclassified information must be accessed via Government approved equipment and DoD network.
DESTRUCTION OF DOD INFORMATION
Information not already formally approved for public release must be destroyed using approved burn bags.
DISPOSITION OF DOD INFORMATION
All information must be returned to the Government when no longer required for performance on this contract.
PHOTOGRAPHY/RECORDING
The recording of DoD information, equipment, personnel, and facilities by any means is prohibited.
HAZARDOUS MATERIAL & WEAPONS ARE PROHIBITED FROM ENTRY ON/INTO GOV’T FACILITIES
SECURITY INCIDENTS
- Any issues/concerns of workplace violence must be reported immediately to the WHS Security Office and Pentagon Force Protection Agency (PFPA).
- Any known or suspected failure to safeguard DoD information, equipment, facilities, or personnel must be reported to the WHS Security Office.
- Incidents involving computer systems/networks must be reported to the Pentagon Computer Incident Response Team (PENTCIRT), and WHS Security Office.
- Comply with instructions provided by PFPA, PENTCIRT, and WHS Security Office.
- If DoD information is found unprotected (e.g. unattended in a common area) take possession of the information, safeguard it, provide the information to the WHS Security Office.
- If classified information or CUI is found on publicly accessible websites, STOP and immediately notify the WHS Security Office. Report the website address; do not continue to look at the information; do not share the website with co-workers; do not acknowledge the validity of the information to inquiries from unauthorized persons (e.g. the media).
- If a data spill is encountered (e.g. secret information sent and received on unclassified email) STOP and immediately notify PENTCIRT. Follow instructions provided.
- Provide only unclassified information when reporting.
*Pentagon Force Protection Agency: Emergency: 703.697.5555 or 911 from Office Landline; Non-Emergency Phone: 703.697.1001 *WHS Security Office: Whs.pentagon.em.mbx.security-officers@mail.mil, or 571-372-0940.
*PENTCIRT: Hotline (703) 695-CIRT(2478)
| attachmentsList: |
| AddAttachment: |
| ViewAttachment: |
| RemoveAttachment: |
| rep: |
| Sig: |
| Enter your name here.: |
| GCAName: Washington Headquarters Services (WHS) |
| AAC: HQ0034 |
| Address: Acquisition Directorate |
4800 Mark Center Drive, Suite 09F09-02 Alexandria, VA 22350 Address: WHS Security Office 4800 Mark Center Drive Suite 10G07 Alexandria, Va 22350
| POCName: |
| Phone: 5713720940 |
| Email: thomas.e.prudhomme.civ@mail.mil |
| Title: Security Manager |
| Enter the date using the format DD-Mon-YYYY: |
File details come from the government source that posted it.