Attachment 9 - DD254 Environmental IDIQ FSD.pdf
PDF 127 KB Posted
- Attached to
- Environmental Services Federal contract opportunity
- Solicitation number
- HQ003420R0003
- Issued by
- DOD Washington Headquarters Service
About this file
This document is a DD Form 254, which outlines security requirements for a federal contract. The contract will provide environmental services to the Washington Headquarters Service and Pentagon Facilities, including environmental compliance, incident response and recovery planning, natural resource management, energy management, and outreach events. Classified information up to the Secret level may be involved, requiring facility and personnel security clearances. Contractors will need access to SIPRNet and handle CUI, requiring associated training. Additional requirements include compliance with policies for classified meetings and briefings, reporting security incidents, original classification and destruction of information. The Defense Office of Prepublication and Security Review listed as the public release authority.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 6 - Past Performance Questionnaire.v2.docx | DOCX document | |
| Attachment 4 - Key Personnel Qualification Table.v2.docx | DOCX document | |
| HQ003420R0003-0001 Conformed Copy.pdf | ||
| Attachment 1 - IDIQ Basic Performance Work Statement. v2.pdf | ||
| Attachment 7 - Pricing Submission Worksheet.v2.xlsx | XLSX spreadsheet | |
| HQ003420R0003-0001 Amendment.pdf | ||
| Attachment 6 - Past Performance Questionnaire.docx | DOCX document | |
| Attachment 5 - Past Performance Data Sheet.docx | DOCX document | |
| Attachment 2 - PWS - Sample Task Order.pdf | ||
| Attachment 8 - Non-Disclosure Agreement (NDA).docx | DOCX document | |
| Attachment 3 - QASP for Environmental Services.pdf | ||
| RFP - HQ003420R0003 - Environmental Services.pdf | ||
| Attachment 4 - Key Personnel Qualification Table.docx | DOCX document | |
| Attachment 1 - PWS - IDIQ Basic.pdf | ||
| Attachment 7 - Pricing Submission Worksheet.xlsx | XLSX spreadsheet |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of AEM LiveCycle Designer
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List of Attachments (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)
| CurrentPage: |
| PageCount: |
| Classification: |
| SerialNum: |
| a. Facility clearance level. Select one.: 2 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Choose Yes or No: 1 |
| Choose Yes or No: 1 |
| Prime: TBD |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Soli: |
| DueDate: |
| dateA: 2019-06-26 |
| RevisionNum: 1 |
| dateB: |
| Final: |
| dateC: |
| No: 1 |
| No: 1 |
| No: 1 |
| No: 1 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 0 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: TBD |
| Cage: TBD |
| CSO: TBD |
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: See item 13 |
| Block9: Fulfill a need of the Environmental, Sustainability, and Energy Branch (ESEB) and the SCD within the Facilities Services Directorate at the Pentagon, as well as the Environmental, Safety, and Health Division at RRMC. Support efforts include multimedia environmental compliance, sustainability, natural resources, energy management, and communications. |
| a: 0 |
| a: 0 |
| a: 0 |
| f: 0 |
| f: 0 |
| f: 0 |
| b: 0 |
| b: 0 |
| b: 0 |
| g: 0 |
| g: 0 |
| c: 0 |
| c: 0 |
| c: 0 |
| h: 0 |
| h: 0 |
| d: 0 |
| d: 0 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 0 |
| NonSCI: 0 |
| j: 1 |
| j: 0 |
| k: 1 |
| k: 0 |
| Enter your name here.: See item 13 |
| Enter your name here.: See item 13 |
| e: 0 |
| e: 0 |
| l: 0 |
| m: 1 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: Defense Office of Prepublication and Security Review (DOPSR) |
1155 Defense Pentagon Washington, DC 20301
| PublicAuthority: Defense Office of Prepublication and Security Review (DOPSR) |
| AddSig: |
| RemoveSig: |
| text: ITEM 10.j. CUI |
The contractor will have access to CUI which is not classified information, but does require protection from unauthorized disclosure. Refer to DoDM 5200.01, Volume 4, “DoD Information Security Program: Controlled Unclassified Information (CUI), available at: http://www.esd.whs.mil/DD/
PERSONALLY IDENTIFIABLE INFORMATION (PII)
The contractor will likely have access to PII (e.g. social security number). PII must be safeguarded as CUI. The Contractor:
- Will ensure PII is safeguarded as required by existing statutory; regulatory; and policy requirements.
- Will ensure all employees complete Privacy Act training provided via icompass.
- Will not intentionally view PII of any individual unless officially needed in performance of this contract.
- Will not share PII with anyone who does not have an official need to know.
- Will process PII only on government approved systems/equipment.
- Will report immediately to the Government owner of the system storing PII and to the WHS Security Office any known or suspected failure to safeguard PII.
The contractor must ensure DoD unclassified information/CUI is processed under NIST SP800-171 standards when not on government systems. Although the contractor must comply with all requirements to safeguard CUI, common requirements include: Enforce need to know; access CUI only for an official purpose; do not store CUI on removable media; keep CUI at authorized work locations; encrypt email containing CUI; lock CUI in desk drawers/file cabinets when not in use; dispose of CUI using burn bags; do not post CUI to publicly accessible websites.
ITEM 10.k. OTHER
SECURE FACILITIES
Contractor will comply with site specific security procedures.
Introduction of mobile devices (personal or government issued) into facilities where classified information is processed, handled, stored, or discussed, are prohibited. Prohibited devices normally feature the ability to receive or transmit data, record audio/video, make cellular phone calls, and have wi-fi technology. Examples of prohibited devices include: cell phones; laptops; smart watch; camera; mp3 player. Key fobs for medical alert, motor vehicle, or home security are generally acceptable provided they have no features similar to prohibited devices. Medical devices may be acceptable but require individual assessment.
DOD COMPUTER SECURITY
With GCA/GPM approval the contractor personnel will have access to government provided unclassified systems (NIPRNET). With approval from the GCA/GPM, the contractor will have access to classified systems (e.g. SIPRNET). The contractor must meet all requirements before accessing a particular information system. Information systems must be used only for the official government purpose specified in this contract. Although the contractor must comply with all government laws, rules, and regulations for use of information systems, common requirements include: do not process classified information on systems of a lower classification or unclassified level; complete mandatory initial and annual cyber awareness training; enforce need to know; do not allow others to use your access card or password to access a system; do not introduce hardware/software/USB devices to a government system unless specifically approved by the owner of the information system; follow procedures to address suspicious email (e.g. phishing); do not introduce personal wireless hot spots or portable electronic devices (e.g. cell phone) into spaces where classified or sensitive information is processed/stored; do not post DoD information to publicly accessible web sites; do not process DoD information on personal devices (e.g. cell phone, laptop, camera, voice recorders); use of thumb drives is prohibited; Government equipment must be returned when no longer required for performance on this contract.
Contractor personnel must not introduce or use software, firmware, or hardware to the DoD network or equipment, that has not been approved by the Government network Authorizing Official (Defense Information Systems Agency/Joint Service Provider). Before connecting any Government equipment (e.g. local desk top printer; government issued iphone) to the network, each person must submit a USB Exception Request through the GCA/COR to Joint Service Provider for approval. Each person must have approval even if sharing the Government equipment with a co-worker, i.e. approval for one is not approval for all. Refer to DoD 8500.01 for additional information.
Connection of personally owned equipment to the DoD network is prohibited. Exceptions will not be approved.
Do not assume Government issued equipment is approved for connection to the network. Joint Service Provider will suspend the individual’s account access for a minimum of 14 days if a device is connected without their approval.
All requests for information technology and telephone/landline services must be submitted to the Help Desk, Joint Service Provider.
SIPRNET – NATO – DERIVATIVE CLASSIFICATION
Contractor personnel will require access to information systems classified Secret (SIPRNET).
NATO: Actual knowledge of, generation, or production of NATO information is not required for performance on this contract. But, a NATO awareness briefing is required as a condition of access to SIPRNET. NATO access must be posted to the DoD system of record (e.g. JPAS). Annual training is required. A final U.S. Government security clearance is required.
DERIVATIVE CLASSIFICATION training is required as a condition of access to SIPRNET. The contractor will maintain training certificates and provide copies to the GCA when requested. Annual training is required.
COMMON ACCESS CARD (CAC)
With GCA/COR approval a CAC will be issued as required for access to facilities and/or information systems. Personnel must meet and maintain investigative and adjudicative requirements specified in DoDI 5200.46, and immediately report to the WHS Security Office any issues affecting CAC eligibility. Government issued credentials are the property of the United States Government and must be returned when no longer required for performance on this contract. Return CACs to: WHS Security Office, 4800 Mark Center Drive, Suite 10G07, Alexandria, VA 22350.
ITEM 11.m. OTHER
DoD REGULATION DoD security requirements can be found on the DoD issuances website: http://www.esd.whs.mil/DD/
SITE SECURITY
The contractor will comply with government security requirements specific to authorized locations of performance.
SECURITY EXECUTIVE AGENT DIRECTIVE 3
The contractor must comply with “Reporting Requirements for Personnel with Access to Classified Information or Who Hold a Sensitive Position,” along with DoD Manual 5200.02.
IN/OUT PROCESSING
The contractor personnel must complete security in-processing upon entry to the contract and security out-processing prior to departing from this contract. All government property and information must be returned at or before out-processing.
ORIGINAL CLASSIFICATION AUTHORITY
Original Classification is not authorized. If the contractor believes information not currently classified, requires classification, the contractor will immediately notify the GCA/GPM/WHS SO.
DERIVITIVE CLASSIFICATION
Derivative Classification is not authorized unless specifically approved by the GCA/GPM/WHS SO for each person who has a demonstrated need for the requirement; initial training must be completed using the Defense Security Service website and bi-annually thereafter. Training certificates must be provided to the WHS SO.
DECLASSIFICATION AND DOWNGRADING
Declassification and Downgrading of classified information is prohibited.
SAFEGUARDING COMPONENT INFORMATION, INCLUDING BY COMPILATION
Contractor must ensure information collected from any DoD Component is safeguarded as prescribed by that component (e.g. classified, CUI). Contractor must also ensure proper safeguarding of Component information as it is compiled with information collected from other DoD Components. For example: compilations of information that are individually unclassified, may be classified if the information [combined] qualifies for classification. Classification by compilation requires an original classification decision by an authorized Original Classification Authority.
Contractor must consider compilation initially and continually to ensure information is processed on appropriate computer systems (to prevent data spills) and information is not released to unauthorized persons.
For additional information refer to DoD Manual 5200.01-V1 “DoD Information Security Program: Overview, Classification, and Declassification.”
SAFEGUARDING CLASSIFIED INFORMATION & CUI DURING MEETINGS/PRESENTATIONS
Classified information must be protected from unauthorized disclosure. Classified meetings/training/conferences (presentations) must be pre-approved by the GCA/GPM/WHS SO; must serve a specific U.S. Government purpose; dissemination of classified information by other means is not sufficient; must take place only at an approved U.S. Government facility or cleared contractor/subcontractor facility meeting appropriate safeguard requirements. A prime contractor not having safeguard requirements may not grant safeguarding to a subcontractor. The contractor must comply with all safeguarding requirements during classified presentations. Classified presentations at non approved Government locations (e.g. hotel) is prohibited.
CUI must be protected from unauthorized disclosure. CUI presentations must be pre-approved by the GCA/GPM, and must serve a specific U.S. Government purpose. CUI presentations must take place at Government approved locations and must not occur in locations where there is risk of unauthorized disclosure to foreign personnel/governments or others who do not have an official “need to know.”
For additional information refer to the NISPOM and DoDM 5200.01 Volumes 1 through 4.
HAND CARRYING CLASSIFIED INFORMATION
If required, hand carrying is limited to the National Capitol Region; a courier card must be issued by the WHS SO; couriers must complete required training. Travel with classified information via aircraft is prohibited.
CLASSIFIED INFORMATION or CUI IN THE PUBLIC DOMAIN If the contractor discovers classified information or CUI on a publically accessible website, the contractor must immediately notified the GCA/GPM/WHS SO. The contractor must not continue to view the information; do not share the information with co-workers; do not print or save the information; do not email the information to anyone or to a personal device; and do not acknowledge the validity of the information to unauthorized persons who may inquire (e.g. the media).
TELEWORK
If approved by the GCA to telework, use of classified information is prohibited. Unclassified information/CUI must be accessed via Government approved equipment and DoD network. Personal software/equipment must not be introduced/connected to DoD equipment or used to process DoD information.
DESTRUCTION OF DOD INFORMATION
The contractor must comply with on-site security procedures to dispose of DoD Information. Destruction is normally by use of approved burn bags.
DISPOSITION OF DOD INFORMATION/EQUIPMENT
All information/equipment must be returned to the Government when no longer required for performance on this contract.
PHOTOGRAPHY/RECORDING
The recording of DoD information, equipment, personnel, and facilities by any means is prohibited.
HAZARDOUS MATERIAL & WEAPONS
Hazardous materials and weapons are prohibited from entry on/into government facilities. Examples of items prohibited include but are not limited to: firearms; knives/daggers; billy clubs/black jacks; brass knuckles; martial arts weapons; explosive or explosive parts; irritant gases; any other weapon, device, instrument, material, or substance animate or inanimate that is used for or is readily capable of causing death or serious bodily injury. Any weapon the possession of which is prohibited under the laws of the state in which the facility is located.
CONTINUED RESPONSIBILITY
Safeguarding classified information and CUI is a lifelong obligation. Contractor personnel will continue to safeguard DoD information to which they had access to/knowledge of.
ITEM 12 PUBLIC RELEASE
Defense Office of Prepublication and Security Review (DOPSR) 1155 Defense Pentagon Washington, DC 20301
Release of DoD information to the public or other unauthorized recipient is prohibited. All DoD information intended for publication or dissemination must undergo a security and policy pre-publication review. This material includes, but is not limited to: books, manuscripts and theses, biographies, articles, book reviews, audio/video materials, speeches, press releases, conference briefings, research papers, gaming materials and other media. The Government must initiate the release process and the proposed information must be reviewed by the WHS Security Office. Unauthorized releases must be reported to the WHS Security Office. For more information visit the DOPSR website: http://www.esd.whs.mil/DOPSR/
SECURITY INCIDENTS
The contractor will immediately report to the GCA/COR, appropriate security office, or law enforcement agency: any known or suspected incident in which government information/equipment is not properly safeguarded or has been disclosed to unauthorized persons; data spills on information systems; or concerns of workplace violence.
-On site host security office as appropriate.
-WHS Security Office: Whs.pentagon.em.mbx.security-officers@mail.mil, or 571-372-0921/0938/0936/0940.
-PENTCIRT: Hotline (703) 695-CIRT(2478) to report dataspills.
-Pentagon Force Protection Agency: Emergency: 703.697.5555 or 911 from Office Landline; Non-Emergency Phone: 703.697.1001
- Any issues/concerns of workplace violence must be reported immediately to the WHS Security Office and Pentagon Force Protection Agency (PFPA).
- Any known or suspected failure to safeguard DoD information, equipment, facilities, or personnel must be reported to the WHS Security Office.
- Incidents involving computer systems/networks must be reported to the Pentagon Computer Incident Response Team (PENTCIRT), and WHS Security Office.
- Comply with instructions provided by PFPA, PENTCIRT, and WHS Security Office.
- If DoD information is found unprotected (e.g. unattended in a common area) take possession of the information, safeguard it, provide the information to the WHS Security Office.
- If classified information or CUI is found on publicly accessible websites, STOP and immediately notify the WHS Security Office. Do not continue to look at the information; do not download/save the information to your computer; do not share the website with co-workers; do not acknowledge the validity of the information to inquiries from unauthorized persons (e.g. the media).
- If a data spill is encountered (e.g. secret information sent and received on unclassified email) STOP and immediately notify PENTCIRT. Follow instructions provided.
- Provide only unclassified information when reporting.
| attachmentsList: |
| AddAttachment: |
| ViewAttachment: |
| RemoveAttachment: |
| rep: Brandon Mikolic |
Security Specialist
| Sig: |
| Enter your name here.: |
| GCAName: |
| AAC: |
| Address: |
| POCName: |
| Phone: |
| Email: |
| Title: |
| Enter the date using the format DD-Mon-YYYY: |
File details come from the government source that posted it. Updated .