Attachment 2 DD254.pdf

PDF 328 KB Posted

Attached to
Facility Related Control System Camera Documentation Project Federal contract opportunity
Solicitation number
HQ003424R0296
Issued by
DOD Washington Headquarters Service

About this file

This document is a DD Form 254, Department of Defense Contract Security Classification Specification, which outlines the security requirements for a federal contract opportunity. The key details are:

This DD Form 254 is for the "Facility Related Control System Camera Documentation Project" solicitation, which requires services to audit and document the existing CCTV camera and equipment/distribution system at the Raven Rock Mountain Complex. The contract involves access to classified data up to the SECRET level, and the contractor must possess and maintain a facility clearance granted by the Defense Counterintelligence and Security Agency. The contractor personnel performing work under this contract must have a minimum of an Interim SECRET clearance. Additional security requirements include restrictions on mobile devices, safeguarding classified information and CUI, and specific procedures for meetings and presentations involving classified material. The contracting activity is the DOD Washington Headquarters Service.

rep: The document appears to be a template or draft DD Form 254 for a pre-award contract opportunity, rather than details about a specific contract. It does not provide information about required products/services, response dates, award dates, pricing, set asides, incumbents, or key objectives. The document outlines extensive security requirements and guidance for this classified contract, but does not summarize a specific federal contract opportunity.

View the file

Other files for this federal contract opportunity

Other files attached to Facility Related Control System Camera Documentation Project, newest first.
File Type Posted
HQ003424R0296-0001.pdf PDF
HQ003424R0296.pdf PDF
Attachment 1 Site Survey Template.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Please wait...

If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.

You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.

For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.

Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.

DRAFT

SAMPLE

PREVIOUS EDITION IS OBSOLETE.

Page of

DD FORM 254, APR 2018

NEEDS DD67

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

May 31, 2022 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

b. REVISED (Supersedes all previous specifications.)

4. IS THIS A FOLLOW-ON CONTRACT?

If yes, complete the following:

Classified material received or generated under

5. IS THIS A FINAL DD FORM 254?

If yes, complete the following:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

e. NATIONAL INTELLIGENCE INFORMATION:

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

List of Attachments (All Files Must be attached Prior to Signing, i.e., for any digital signature on the form)

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

9.0.0.2.20120627.2.874785 DD 254, "DoD Contract Security Classification Specification"

CurrentPage:
PageCount:
Select classification from drop-down list.: Unclassified
SerialNum: TBD
a. Facility clearance level. Select one.: 2
b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 2
Select for "original.": 1
Select for "original.": 1
Enter prime contract number.: TBD
Select for "revised.": 0
Select for "revised.": 0
Enter subcontract number.:
Select for "final.": 0
Select for "final.": 0
Enter solicitation or other number.:
Enter due date in format YYYYMMDD.:
Enter date in format YYYYMMDD.: 20240710
Enter revision number.:
Enter date in format YYYYMMDD.:
Enter final specification.:
Enter date in format YYYYMMDD.:
Select for "no.": 1
Select for "no.": 1
Select for "no.": 0
Select for "no.": 1
Select for "yes.": 0
Select for "yes.": 0
Select for "yes.": 1
Select for "yes.": 0
Enter preceding contract number.:
Enter contractor's request date in format YYYYMMDD.:
Enter period.:
Enter typed name of certifying official (last, first, middle initial).:
Enter CAGE code of the prime contractor.:
Enter cognizant security office(s) (Name, Address, ZIP Code, Telephone required; Email Address optional).: RRMC Security Manager

450 Harbaugh Valley Road Fairfield, PA 17320-8922

(717) 878-2492

Select to add row to locations.:
Select to remove last row from locations.:
Select to delete all signatures.:
Enter location(s).: HQ0700

Raven Rock Mountain Complex (RRMC) 450 Harbaugh Valley Road Fairfield, PA 17320-8922

Enter general unclassified description of this procurement.: Survey of existing CCTV system and recommendations for transition to new network architecture.
Select for "a. CONTRACTOR.": 0
Select for "a. CONTRACTOR.": 0
Select for "a. CONTRACTOR.": 1
Select for "f. OTHER AS NECESSARY.": 0
Select for "f. OTHER AS NECESSARY.": 0
Select for "f. OTHER AS NECESSARY.": 1
Select for "b. SUBCONTRACTOR.": 0
Select for "b. SUBCONTRACTOR.": 0
Select for "b. SUBCONTRACTOR.": 0
Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 0
Select for "g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER.": 0
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 1
Select for "c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR.": 0
Select for "h. REQUIRE A COMSEC ACCOUNT.": 0
Select for "h. REQUIRE A COMSEC ACCOUNT.": 0
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0
Select for "d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION.": 0
Select for "i. HAVE A TEMPEST REQUIREMENT.": 0
Select for "i. HAVE A TEMPEST REQUIREMENT.": 0
Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (1) Sensitive Compartmented Information (SCI).": 0
Select for "e. NATIONAL INTELLIGENCE INFORMATION: - (2) Non-SCI.": 0
Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1
Select for "j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS.": 1
Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 1
Select for "k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE.": 0
Enter infomration for "other.": CAC, PFAC, Performance in Government Facilities.
Enter infomration for "other.": Courier Authorizations
Enter infomration for "other.": Contracting Officer Representative
Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 0
Select for "e. ADMINISTRATIVE CONTRACTING OFFICER.": 0
Select for "l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED INFORMATION (CUI). .": 1
Select for "m.OTHER.": 1
Select for "direct.": 0
Select for ": 1
Enter specification for "through".: Director Freedom of Information & Security Review, 3100

Defense Pentagon, Rm 2C757, Washington DC20301,Tell RRMC Enter public release authority.: RRMC Commander 717-878-2771, RRMC Security Office 717-878-2513

Select to add signature.:
Select to remove last signature.:
text: Block 13, Security Guidance: DD Form 254 for contract number: TBD. This DD254 is for pre-award so that interested contractors can review DD254 requirements before submitting a proposal.

General comments : This contract involves access to classified data/information up to and including SECRET. Contractors shall follow all applicable Standard Office Procedures.

*** No contractors shall have CAC access to RRMC DoD IT networks whether classified or unclassified.*** *** Prime Contractor's safeguarding locations (Whether Prime Contractor or Subcontractor locations) where DOR (Designer of Record) classified designs to occur ARE REQUIRED since DOR designs will NOT occur at Government locations. Contractor safeguarding locations must be provided by the contractor and listed in Block 8. The safeguarding location addresses to be listed in Block 8 may be different than what is listed in Block 6 and Block 7. Contractor shall possess and maintain a facility clearance for safeguarding locations, granted by the Defense Counterintelligence and Security Agency (DCSA), before any classified material is stored, and/or created in such locations.***

1) Any classified information generated in the performance of this contract shall be classified according to source markings.

All provisions of 32 CFR Part 117, National Industrial Security Program Operating Manual (NISPOM) apply. Effective date is 24 Feb 2021.

REQUIRED CLEARANCE LEVEL This contract involves access to classified data/information for contractor design personnel up to and including SECRET. To be unescorted, contractor personnel performing under this contract shall possess SECRET interim or a SECRET clearance prior to reporting to any assignment within RRMC (Exact location to be shown to contractor upon award).

For the construction area: The contractor must provide escorts for contractor personnel without SECRET or higher clearances for anywhere at RRMC including the construction area.

Outside of the construction area: Contractor is responsible for providing SECRET level escorts to all contractor personnel without SECRET or higher level clearances for anywhere at RRMC

SECURITY EXECUTIVE AGENT DIRECTIVE 3 The contractor must comply with “Reporting Requirements for Personnel with Access to Classified Information or Who Hold a Sensitive Position,” along with DoD Manual 5200.02 and NISPOM. See INDUSTRIAL SECURITY LETTER (ISL) 2021-02 dated 12 August 2021 for additional information.

SECURITY EXECUTIVE AGENT DIRECTIVE 4 The contractor will comply with “National Security Adjudicative Guidelines,” which became effective on June 08, 2017. See INDUSTRIAL SECURITY LETTER (ISL) 2019-01 for additional information.

ORIGINAL CLASSIFICATION AUTHORITY Original Classification is not authorized. If the contractor believes information not currently classified, requires classification, the contractor will immediately notify the GCA.

SECURITY CLASSIFICATION GUIDANCE (SCGs) Specific SCGs, to include subsequent upgrades/revision(s), applying to classified performance on this contract, shall be provided by the Contracting Officer Representative (COR) or Technical Point of Contact, identified in Block 16 or Block 18, as Government Furnished Information (GFI); and shall be executed by the Contractor without obligation to modify this DD Form 254. If additional security classification is required, contact the COR identified in Block 16 or Block 18.

CLASSIFIED INFORMATION OR CUI IN THE PUBLIC DOMAIN If the contractor discovers classified information or CUI on a publicly accessible website, the contractor must immediately notify the GCA. The contractor must not continue to view the information; do not share the information with co-workers; do not print or save the information; do not email the information to anyone or to a personal device; and do not acknowledge the validity of the information to unauthorized persons who may inquire (e.g. the media).

NOT APPROVED: TELEWORK If approved by the GCA to telework, use of classified information is prohibited. Unclassified information and CUI must be accessed via Government approved equipment and DoD network. Personal software/equipment must not be introduced/connected to DoD equipment or used to process DoD information. Connection of personal devices to a DoD computer is prohibited.

DESTRUCTION OF DoD INFORMATION The contractor must comply with on-site security procedures and DoD Manual 5200.02 and NISPOM to dispose of DoD Information.

DISPOSITION OF DOD INFORMATION & EQUIPMENT All information/equipment must be returned to the Government when no longer required for performance on this contract.

AUDIO/VISUAL RECORDINGS The recording of DoD information, equipment, personnel, or facilities by any means is prohibited.

The use of cellular phones, hand-held radios, beepers, pagers, cordless phones, fitness trackers, or any other device capable of storing memory, and/or transmitting/receiving data, and cordless microphones shall be addressed in the Standard Operating Procedures & RRMC Security Guidance where classified information processing is accomplished and for the entire RRMC location. The use of cellular phones, hand-held radios, beepers, pagers, cordless phones, fitness trackers, or any other device capable of storing memory, and/or transmitting/receiving data, and cordless microphones cannot be brought inside RRMC and must be left in vehicles (Parked outside) or not brought onto RRMC at all.

HAZARDOUS MATERIALS & WEAPONS Hazardous materials and weapons are prohibited from entry on/into government facilities to include any weapon, the possession of which, is prohibited under the laws of the state in which the facility is located.

References:

18 U.S. Code § 930. Possession of firearms and dangerous weapons in Federal facilities https://www.law.cornell.edu/uscode/text/18/930 Title 32 - National Defense, Part 234 - CONDUCT ON THE PENTAGON RESERVATION https://www.govinfo.gov/app/details/CFR-2011-title32-vol2/CFR-2011-title32-vol2-part234/summary Security requirements of RRMC

SECURITY INCIDENTS The contractor will immediately report to the GCA any known or suspected incident in which government information/equipment is not properly safeguarded or has been disclosed to unauthorized persons; electronic data spills on information systems; or concerns of workplace violence.

- Notify RRMC Assistant Security Manager 717-878-2492 or RRMC Desk Sergeant 717-878-3500 (After hours)

- Notify the Facility Security Officer (FSO)

- Notify the GCA security office as appropriate (Government Security Manager).

- For PFPA: Industrial Security Program Manager, pfpa.ncr.ssd.mbx.industrial-security@mail.mil

- For Electronic Spillage, Notify the FSO, RRMC Assistant Security Manager 717-878-2492 or Desk Sergeant 717-878-3500 (After hours) Initial report should be UNCLASSIFIED.

- Law Enforcement needed: Notify the RRMC Desk Sergeant 717-878-3500 : Emergency: 911 from Office Landline; Non-Emergency Phone: RRMC Desk Sergeant 717-878-3500

COMPUTER SECURITY Contractor personnel are NOT for this project “Authorized Users” of the DoD networks and must comply with responsibilities identified in DoDI 8500.01. Contractor “Privileged User” access must be specifically authorized, otherwise the contractor will not have access to system control, monitoring, administration, criminal investigation, or compliance functions unless specifically authorized.

Contractor personnel must:

- Comply with laws, rules, and regulations for use of information systems.

- Meet all requirements before accessing a particular information system.

- Use information systems only for the official purpose specified in this contract.

- Not process classified information on unclassified systems or systems of a lower classification.

- Complete mandatory initial and annual cyber awareness training.

- Complete Privacy Act training.

- Enforce need to know.

- Not share system access tokens (e.g. CAC) or passwords, with other individuals.

- Follow procedures to address suspicious email (e.g. phishing).

- Not introduce personal wireless hot spots or portable electronic devices (e.g. cell phone) into spaces where classified or sensitive information is processed/stored.

- Not post DoD information to publicly accessible web sites.

- Not process DoD information on personal devices (e.g. cell phone, laptop, camera, voice recorders).

- Not use thumb drives or other storage devices.

- Not introduce or use software, firmware, equipment, hardware, or USB devices, to the DoD network that has not been approved by the Government Network Authorizing Official (Defense Information Systems Agency/Joint Service Provider).

- Not connect any personal devices/equipment to DoD equipment/network.

- Not connect Government issued equipment (e.g. local desk top printer; government issued iPhone) before obtaining approval from the information system owner.

- Return Government equipment when no longer required for performance on this contract.

ADDITIONAL SECURITY REQUIREMENTS FOR PERFORMANCE IN GOVERNMENT FACILITIES The contractor will comply with RRMC specific security procedures and complete required security training. Additional security requirements may be imposed by the Department Of Defense imposed during the contract.

MOBILE DEVICES (Prohibited Electronic Devices (PEDs)) The introduction of mobile devices (personal or government issued) into facilities where classified information is processed, handled, stored, or discussed, is prohibited. Prohibited devices normally feature the ability to receive or transmit data, record audio/video, make cellular phone calls, and have Wi-Fi technology. Examples of prohibited devices include but are not limited to: cell phones; laptops; smart watch; camera; MP3 player. Medical devices may be acceptable but require individual assessment.

SAFEGUARDING CLASSIFIED INFORMATION & CUI DURING MEETINGS and/or PRESENTATIONS Classified information must be protected from unauthorized disclosure. Classified meetings/training/conferences (presentations) must be pre-approved by the GCA; must serve a specific U.S. Government purpose; dissemination of classified information by other means is not sufficient; must take place only at an approved U.S. Government facility or cleared contractor facility meeting appropriate safeguard requirements. The contractor must comply with all safeguarding requirements during classified presentations. Classified presentations at non approved Government locations (e.g. hotel) is prohibited. CUI must be protected from unauthorized disclosure. CUI presentations must be pre-approved by the GCA and must serve a specific U.S. Government purpose. CUI presentations must take place at Government approved locations and must not occur in locations where there is risk of unauthorized disclosure to foreign personnel/governments or others who do not have an official “need to know.” For additional information refer to the NISPOM, DoDM 5200.01 Volumes 1 through 3 and DoDI 5200.48.

RRMC Additional Specific Requirements:

1) Facility Security Clearance: The Contractor shall possess and maintain a facility clearance granted by the Defense Counterintelligence and Security Agency (DCSA). The DD 254 will be housed within the NCCS through the life of the contract. The Contractor shall be registered within NCCS at time of award to gain access to the DD 254. It is incumbent upon the Contractor to ensure that the necessary security paperwork is submitted in sufficient time to enable each individual to be cleared prior to beginning work on this contract. In the event that the NCCS is superseded by another System of Record, the same requirements apply. The Contracting Officer will maintain the DD254 in the Official Contracts Records.

• Contractor personnel performing or assigned under this contract must be U.S. citizens. Security Classification Guide requests should be presented to the Government Sponsor, if required, subsequent to contract award. All classified information received or generated under this contract is the property of the U. S. Government. The U. S. Government shall provide disposition instructions. No release of classified information or controlled unclassified information under this contract is authorized. All requirements for control and accounting of original documentation and copies apply. All applicable provisions of the NISPOM and its supplements and 32 CFR, part 117 (National Industrial Security Program Operating Manual (NISPOM)) apply. Effective date is 24 Feb 2021. Any classified information shall be transmitted IAW DOD 5200.1M, Volume #3 DOD Information Security Program Manual. The contractor shall adhere to Chapter 8, NISPOM, which applies to non-DoD IT systems.

• Contractor is not authorized to subcontract on this effort without an approved subcontracting plan with written GCA/COR authorization

• All Common Access Cards (CACs), building access badges, and parking passes must be returned immediately at the end of the period of performance date.

• The Contractor shall comply with (1) Security Agreement (DD Form 441/DD Form 441-1), including the National Industrial Security Program Operating Manual (NISPOM), DoD 5220.22-M and any revisions and (2) 32 CFR, Part 117.Provisions of the Privacy Act apply to all records and reports maintained by the contractors.

• All programs and materials developed at government expense during the performance period of this contract are the property of the US Government.

• Prior to granting an employee access to classified information and/or materials, the contractor shall brief employees with regard to their obligation to comply with the NISPOM, to include any changes and/or amendments, and 32 CFR, Part 117. The contractor’s employees shall be debriefed when access to the material is no longer needed or is terminated. A list of all employees who have had access to classified information during the period of this contract shall be maintained by the contractor company and be available for Defense Counterintelligence and Security Agency inspection

• Access to General Protection/Security Policies and Procedures. All contractor employees, including subcontractor employees stationed or assigned on a US Government facility shall comply with applicable installation, facility access procedures and local security policies (provided by the US Government security personnel). The contractor workforce shall comply with all personal identification verification requirements as directed by local policy. In addition to the changes otherwise authorized by the changes clause in this contract, should the Force Protection Condition (FPCON) at any individual facility or installation change, the US Government may require changes in the contractor security processes or procedures.

• Contractors requiring access to US Government Information Technology (IT) systems (NO DoD IT ACCESS ALLOWED FOR THIS CONTRACT) must adhere to all US Government requirements. All contractor employees and any associated subcontractor employees shall annually complete the DoD Information Assurance Training and sign an Acceptable Use Policy (AUP). The training certificate and AUP must be provided to the designated personnel at US Government facilities before issuance of network access and annually thereafter.

• Contractor employees shall abide by US Government Security Regulations and Security Standard Operating Procedures when working on-site at US Government facilities/installations and shall annually attend Government mandatory training including Operational Security, Security Awareness, Subversion and Espionage, Ethics and Prevention of Sexual Harassment, and any/all other training as directed by the US Government.

• Common Access Cards (CACs) are authorized for contractor employees that work on-site at Government facilities. CACs are the property of the US Government and shall be given to the Contractor Facility Security Officer upon termination of employment with the company, expiration of the CAC, replacement of a CAC, or upon contract completion. The FSO shall immediately return the CACs to the Government Security Office, Government Contracting Officer, or Contracting Officer Representative. The loss of a CAC shall be reported on the first business day following the discovery of the lost CAC to your chain of command and to the issuing agency. Unauthorized possession of a CAC can be prosecuted criminally under section 701, title 18, United States Code. Photocopying of US Government Identification (CAC) is a violation of Title 18, US Code Part 1, Chapter 33, Section 01 and punishable by both fine and imprisonment. Although the asking for military/government identification is totally permissible by commercial establishments, there is a prohibition on duplication of government identification. A state issued driver license or other form of photo identification should be provided to be photocopied if an establishment insists on a photocopy of the traveler’s identification. Contractor is required to ensure that all employees are aware of this law.

• Contractor personnel shall utilize US Government or official company e-mail for transmitting official US Government business. Official US Government business shall NOT be transmitted via personal, private, and/or commercial e-mail accounts, i.e., YAHOO, HOTMAIL, GMAIL, VERIZON, etc.

• Contractor is prohibited from using reference to this contract, classification, clearances, accesses (collateral and/or SCI), even by unclassified acronyms, in advertisements, websites, capabilities fliers, promotional efforts, or recruitment of employees.

Escorts for Collateral Classified Locations:

Contractor is responsible for escorts that must possess a minimum of an Interim SECRET security clearance to escort contractor employees (Who do not possess a security clearance) for the entire RRMC location including construction area, who will not need access to classified information.

For contractor personnel that will require access to classified information:

The contractor escorts must possess a minimum of an Interim SECRET Clearance level. All personnel must be United States Citizens and have a SECRET or Interim SECRET security clearance to gain access to RRMC (Encompasses RRMC, and Alternate Location) without an escort.

All Contractor Designers shall hold a minimum of an Interim SECRET security clearance.

The numbered paragraphs below have all been deemed “Applicable” by the COR.

Prior approval of the contracting activity and concurrence of the COR/CM is required for any subcontracting.

The use of cellular phones, hand-held radios, beepers, pagers, cordless phones, fitness trackers, or any other device capable of storing memory, and/or transmitting/receiving data, and cordless microphones shall be addressed in the Standard Operating Procedures & RRMC Security Guidance where classified information processing is accomplished and for the entire Site. The use of cellular phones, hand-held radios, beepers, pagers, cordless phones, fitness trackers, or any other device capable of storing memory, and/or transmitting/receiving data, and cordless microphones can not be brought onto Site and must be left in vehicles (Parked outside) or not brought onto Site at all.

The following Security Classification Guide applies. Raven Rock Mountain Complex (RRMC), & Alternate Location Security Classification Guide (SCG) January 1, 2017, issued by the Commander of RRMC. Additional classification guidance will be provided by the on-location Government representative. Classified information will be handled IAW the National Industrial Security Program, DoD 5220.22-M (Change 1 March 28, 2013).

CLASSIFICATION

8A. Actual Performance, Locations.

Design Location(s): Reference section 8A above for prime contractor and/or subcontractor locations Construction Location: Raven Rock Mountain Complex

10.j. Controlled Unclassified Information (CUI) - CUI data will be handled or created during this contract. Controlled Unclassified Information including Covered Defense Information (meeting the definition of 48 CFR 252.204–7012(a)) generated and/or provided under this contract shall be marked and safeguarded as specified in DoD Instruction 5200.48 Controlled Unclassified Information (CUI). Any product containing Covered Defense Information shall be assigned the appropriate distribution statement using the criteria set forth in DoDI 5230.24 Distribution Statements on Technical Documents. All Covered Defense Information (CDI), and program Controlled Unclassified Information (CUI) data transmitted and safeguarded via electronic means shall use approved encryption. The Freedom of Information Act applies. Please reference below section titled "CUI REQUIREMENTS FOR DOD CONTRACTORS".

10.k. Performance in Government Facilities: Other: Common Access Cards. This contract requires personnel to obtain the Government issued Common Access Card (CAC) in order to provide identification for physical access to facilities (No contractors shall have DoD IT Access at RRMC whether classified or unclassified for this contract). Personnel must meet and maintain investigative and adjudicative requirements specified in DoDI 5200.46, and immediately report to the GCA any issues affecting CAC eligibility. Government issued credentials are the property of the United States Government and must be returned when no longer required for performance on this contract. Return CACs to: RRMC Security Office. CACs will not be used to access information systems (No contractors shall have DoD IT Access at RRMC), facilities, or installations that are outside the performance requirements of this contract. CACs will be used only by the individual to whom it was issued and will not be used for or by any other person. The contractor will immediately notify the GCA if a CAC is lost, stolen, or otherwise missing. Replacement CACs will require the contractor employee to obtain a signed memo from the Defense Health Agency Security Office, requesting a new CAC be issued.

10.k. Other Continued: PENTAGON FACILITY ACCESS CARD (PFAC). A PFAC may be issued when a CAC is not appropriate. The PFAC allows access to facilities only, and does not grant access to the DoD IT networks. Applicants for a PFAC must be able to favorably pass a law enforcement check of the National Crime Information Center. Government issued credentials are the property of the United States Government and must be returned when no longer required for performance on this contract. Return PFACs to: RRMC Security Office. PFACs will not be used to access facilities, or installations that are outside the performance requirements of this contract. PFACs will be used only by the individual to whom it was issued and will not be used for or by any other person. The contractor will immediately notify the GCA if a PFAC is lost, stolen, or otherwise missing. Replacement PFACs will require the contractor employee to obtain a signed memo from the RRMC Security Office, requesting a new PFAC be issued.

11.c. Receive, Store and Generate Classified Information Or Material. This contract requires the contractor to generate or perform work in support of creating classified documents. Classified information and materials shall be protected in accordance with the policies and procedures established by DoDM 5200.01 Volumes 1-3, the National Industrial Security Program Operating Instruction (NISPOM) and all other applicable Executive Orders. Specific classification guidance will be provided on individual tasks by the COR or CM. The contractor must ensure that applicable classification guidance and marking provisions are complied with IAW the NISPOM. In any case where classification guidance has not been provided, the contractor is to safeguard the information and seek written guidance from the COR or CM prior to release of the information to anyone except the COR or CM.

1) The contractor must restrict access to only those individuals who possess the necessary security clearance and who are actually providing services under the contract with a valid need-to-know. Further dissemination to other contractors, subcontractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the originating agency through the COR/CM.

2) In cases where classified information is authorized to be stored or generated at the vendor facility, the contractor must ensure each employee having access to classified material is fully aware of the special security requirements for this material and shall maintain records in a manner that will permit the contractor to furnish, on demand, the names of individuals who have had access to this material in their custody.

3) Upon completion or termination of the classified contract, or sooner when the purpose of the release has been served, the contractor will return all classified information (furnished or generated) to the source from which received unless retention or other disposition instructions are authorized in writing by the COR.

4) The contractor must designate an individual who is working on the contract as custodian. The designated custodian shall be responsible for receipting and accounting for all classified material received under this contract. This does not mean that the custodian must personally sign for all classified material. The inner wrapper of all classified material dispatched should be marked for the attention of a designated custodian and must not be opened by anyone not working directly on the contract.

5) Within 30 days after the final product is received and accepted by the procuring agency, classified intelligence materials released to or generated by the contractor, must be returned to the originating agency through the contract monitor unless written instructions authorizing destruction or retention are issued. Requests to retain material shall be directed to the CM for this contract in writing and must clearly indicate the justification for retention and identity of the specific document to be retained.

6) Classification, re-grading, or declassification markings of documentation produced by the contractor shall be consistent with that applied to the information or documentation from which the new document was prepared. If a compilation of information or a complete analysis of a subject appears to require a security classification other than that of the source documentation, the contractor shall assign the tentative security classification and request instructions from the contract monitor. Pending final determination, the material shall be safeguarded as required for its assigned or proposed classification, whichever is higher, until the classification is changed or otherwise verified.

11.j: Operations Security (OPSEC) Requirements: Refer to Section 14. Additional Security Requirements which states: OPSEC requirements are contained in the contract or addendum. All contractors performing work on this contract must have completed DoD Antiterrorism Level 1 training within the previous 12 months. Training is online at: http://atlevel1.dtic.mil/at/

11.l. Receive, Store, and Generate CUI Information. (Applies if block 10j is checked) Controlled Unclassified Information under this contract shall be safeguarded as specified in DoDI 5200.48, "DoD Controlled Unclassified Information (CUI)" and per "CUI REQUIREMENTS FOR DOD CONTRACTORS" below. Contractor will have access to unclassified information requiring safeguarding and dissemination control in alignment with specific laws, regulations, or government-wide policies (Formerly identified as For Official Use Only (FOUO), Privacy Act information, Sensitive but Unclassified, or Law Enforcement Sensitive). Contractor shall follow the safeguarding requirements in DoDI 5200.48. DoDM 5400.07, DoD Freedom of Information Act Program applies. Legacy marked U//FOUO must be protected in the same manner as CUI until it is decontrolled.

11.m. Courier authorizations. This contract requires personnel to obtain the Government issued Courier Authorization DD-2501 or letter; couriers must complete required training; double lockable courier bags or equivalent will be used; travel via aircraft is prohibited; classified information will not be viewed during transit; couriers will use the most direct routes to the approved destination; couriers will report any failure to safeguard classified information to their FSO and GCA Security Manager. All contractor courier personnel are required to in-process with the Security Office to obtain courier cards. All personnel issued Courier Cards are required to ensure the card is returned to the Security Office or the CAC Coordinator upon removal from the contract or termination of employment under this contract.

CUI REQUIREMENTS FOR DOD CONTRACTORS

The following procedures will be used to protect Controlled Unclassified Information (CUI) documents and materials:

1) HANDLING: Access to CUI material shall be limited to those employees needing the material to perform their duties. The CUI marking is assigned to documents and material created by a DoD User Agency. CUI is not a classification, but requires extra precautions to ensure it’s properly safeguarded and disseminated and is not released to the public without government authorization.

2) MARKING: Mark unclassified documents containing CUI: “CUI" at the top and bottom of each page, include the CUI warning box, and the CUI Designation Indicator Block as required in DoDI 5200.48. In a classified document:

a) Mark individual paragraph containing only CUI, but not classified material by placing “(CUI)" at the beginning of the portion.

b) Mark top and bottom of each page with classified material with the highest security classification of the material on the page.

c) If the document or material contains CUI under the category of Controlled Technical Information (CTI), use of distribution statements is required. See DoDI 5200.48.

d) If a classified document contains CUI material or if the classified material becomes CUI when declassified, place the following statement on the bottom of the cover or the first page under the classification marking: “NOTE: If declassified, review the document to make sure the material is not still CUI. If it does, then it must have the appropriate safeguarding, dissemination controls, and CUI markings applied.

e) Mark other records such as computer print outs, photographs, films, tapes, or slides in accordance with DoDI 5200.48 so the receiver or viewer knows the it contains CUI material.

f) Mark a message containing material in accordance with DoDI 5200.48. Unclassified messages containing CUI material must show the abbreviation (CUI) before the text begins.

g) Ensure documents transmitting CUI material call attention to any attachments containing CUI.

h) CUI material released to a contractor by a DoD user agency must have the following statement on the front page or cover:

THIS DOCUMENT CONTAINS CUI MATERIAL AND MUST BE REVIEWED BY A GOVERNMENT REPRESENTATIVE UNDER THE REQUIREMENTS OF DODI 5200.48, DODI 5230.09, and DODI 5230.29.

3) STORAGE: During normal duty hours, place CUI material in an out-of-sight location if your work area is accessible to persons who do not have an authorized government purpose for access to the material. After normal duty hours, store CUI material to prevent unauthorized access. File with other unclassified records in unlocked files or desks when internal building security is provided and the file is marked as CUI. When there is no internal security, locked buildings or rooms usually provide adequate after hours protection. For additional protection, store CUI material in locked containers such as file cabinets.

4) TRANSMISSION: CUI documents and materials may be transmitted via first class mail, parcel post or for bulky shipments-fourth class mail. Within the CONUS discussion of CUI material on the telephone is authorized if necessary for the performance of the contract and no alternative is available. Electronic transmission of CUI (voice, data, or facsimile) should be by approved secure communications systems whenever practical. If there is a fax transmission, the sender must ensure the intended receiver is available to receive it or a cover sheet will be used to allow carrying it to the final recipient to avoid unauthorized disclosure of the CUI.

5) RELEASE: CUI material shall not be released outside of the contractor’s facility except to the representative of DoD.

6) DESTRUCTION: When the CUI material no longer meets the threshold for safeguarding and dissemination, it shall be immediately decontrolled, be processed through the records management process, and destroyed by the approved methods identified in DoDI 5200.48 precluding its disclosure to unauthorized individuals by rendering it unreadable, indecipherable, and irrecoverable.

CLOUD STORAGE:

Where applicable, DFARS clause 252.204-7012 requires any contractor that uses an external cloud service provider to store, process, or transmit any covered defense information in performance of a DoD contract to "require and ensure" that the cloud service provider:

• Meets security requirements equivalent to the FedRAMP (Federal Risk and Authorization Management Program) (https://www.fedramp.gov) Moderate baseline and

• Complies with DF ARS 252.204-7012 requirements for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

Click on this button to attach a file(s).:
rep: James Caton McMichael

IT Project Manager rep: Cynthia R. Carr Alternate Security Manager, RRMC rep: Katherine R. Cobos Industrial Security, PFPA

Enter signature.:
Explain and identify specific areas and government activity responsible for inspections.: OPSEC requirements are contained in the contract or addendum. All contractors performing work on this contract must have completed DoD Anti-terrorism Level 1 training within the previous 12 months. Training in on-line at https://jkodirect.jten.mil
Enter GCA name.: WHS Acquisition Directorate
Enter AAC of the contracting office.: HQ0034
Enter address (include zip code).: 4800 Mark Center Dr STE 09F09

Alexandria, VA 22350

Enter POC name.: Keisha Simmons
Enter telephone number (include area code).: 7035451581
Enter email address.: keisha.l.simmons.civ@mail.mil
Enter title.:
Enter the datesigned in format YYYYMMDD.:

File details come from the government source that posted it. Updated .