HQ0858-21-R-0015_Attachment J-08 DD254 10Jun2021.pdf

PDF 523 KB Posted

Attached to
TEAMS-Next Security Operations and Counterintelligence Federal contract opportunity
Solicitation number
HQ0858-21-R-0015
Issued by
DOD Missile Defense Agency

About this file

This document is a solicitation notice for a contract to provide Security Operations and Counterintelligence services to the Missile Defense Agency (MDA). The contract will consist of supporting the MDA with advisory and assistance services related to security, emergency management, program protection, government review and disclosure of classified and controlled unclassified information, international visits and assignments, technology transfer, munitions export/import licensing, and declassification of MDA documents. The counterintelligence requirement supports integrating defensive counterintelligence activities, products and services into MDA research, development, acquisition programs, special access programs, test and evaluation activities, and worldwide deployment of the Missile Defense System.

The solicitation is for a single cost-plus-fixed-fee level-of-effort contract to be awarded through a full and open competition under North American Industry Classification System code 541690. The contract will have a base period of three years and two option periods, one for two years and one for six months. The proposal due date is September 21, 2021. Questions about the solicitation must be submitted by August 26, 2021 to the identified email addresses.

View the file

Other files for this federal contract opportunity

Other files attached to TEAMS-Next Security Operations and Counterintelligence, newest first.
File Type Posted
HQ0858-21-R-0015_TN-SecOps CI_Final Section M_25Oct2021.pdf PDF
HQ0858-21-R-0015_Attachment J-01 TN-SecOps CI SOW 27Oct2021.pdf PDF
HQ0858-21-R-0015_TN-SecOps CI_Final Section L_25Oct2021.pdf PDF
HQ0858-21-R-0015_Attachment L-05 EPW 25Oct2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_Attachment J-05 TERP Pricing Model 25Oct2021.xlsx XLSX spreadsheet
HQ085821R0015 Amendment 0002.pdf PDF
HQ085821R0015 Amendment 0002 Conformed.pdf PDF
HQ0858-21-R-0015_Attachment L-08 Offerors Library Index_20Sep2021.pdf PDF
HQ085821R0015 Amendment 0001.pdf PDF
HQ0858-21-R-0015_TN-SecOps CI_Final Section M_27Sep2021.pdf PDF
HQ0858-21-R-0015_Attachment L-05 EPW 15Sep2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_Attachment J-01 TN-SecOps CI SOW 20Sep2021.pdf PDF
HQ085821R0015 Amendment 0001 Conformed.pdf PDF
HQ0858-21-R-0015_TN-SecOps CI_Final Section L_27Sep2021.pdf PDF
HQ0858-21-R-0015_Attachment J-05 TERP Pricing Model 31Aug2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_TN-SecOps CI Direct Labor Rate Analysis.xlsx XLSX spreadsheet
HQ0858-21-R-0015_Attachment L-05 EPW 03Aug2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_Attachment L-06 Accounting System Checklist.pdf PDF
HQ0858-21-R-0015_Attachment J-02 G-06 Allotment of Funds 12Jul2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_Attachment J-05 TERP Pricing Model 03Aug2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_Attachment J-11 Cost Report Template 03Mar2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_Attachment J-13 Mnthly Manpower Report Template 03Mar2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_Attachment J-18 Mission Essential Contractor Serv 16Mar2021.pdf PDF
HQ085821R0015_TN_SecOps CI_Solicitation.pdf PDF
HQ0858-21-R-0015_Exhibit A CDRLs Combined 07Jul2021.pdf PDF
HQ0858-21-R-0015_Attachment J-01 TN-SecOps CI SOW 18Aug2021.pdf PDF
HQ0858-21-R-0015_Attachment J-03 TERP Procedures 23Jul2021.docx DOCX document
HQ0858-21-R-0015_Attachment J-04 TERP Form 23Jul2021.docx DOCX document
HQ0858-21-R-0015_Attachment J-14 Qrtrly Accomplishments Reporting Format 03Mar2021.pdf PDF
HQ0858-21-R-0015_TN-SecOps CI_Final Section L_11Aug2021.pdf PDF
HQ0858-21-R-0015_TN-SecOps CI_Final Section M_10Aug2021.pdf PDF
HQ0858-21-R-0015_Attachment L-07 OCI Disclosure Form 21Jul21.pdf PDF
HQ0858-21-R-0015_Attachment J-09 Authorized ODC Travel by CLIN 02Mar2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_Attachment J-15 SOFA Travel Clauses 02Mar2021.pdf PDF
HQ0858-21-R-0015_Attachment J-17 IMCP Supplier Comp Suppl 06Jul2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_TN-SecOps CI_FRFP Industry Comment Matrix_Blank 07Jul2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_Attachment L-08 Offerors Library Index_20Jul2021.pdf PDF
HQ0858-21-R-0015_Attachment J-06 NDA Individual Contractor_22Jul2021.pdf PDF
HQ0858-21-R-0015_Attachment J-12 Travel and ODC Report 02Mar2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_TN_SecOps CI_DRFP Industry Comment Matrix_26Jul2021.xlsx XLSX spreadsheet
HQ0858-21-R-0015_Attachment J-21 TEAMS-Next OCI Guiding Principles 15Sep2020.pdf PDF
Show all 41

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

For the best experience, open this PDF portfolio in

Acrobat X or Adobe Reader X, or later.

Get Adobe Reader Now!

http://www.adobe.com/go/reader

MDA SCI Supplement (Item 10.e (1)) for DD Form 254

This supplement applies to Prime Contract Number: HQ0858-21-R-0015

Delivery/Task Order Number: ________. Expiration date: Date/Month/Year

A. The following controls will apply to SCI provided under this contract:

1. DoD 5105.21, “Sensitive Compartmented Information Administrative Manual;” ICD 503, “Intelligence Community Information Technology Systems Security Risk Management, Certification and Accreditation;” ICD 704, ICPG 704-1 – 704-5, “Personnel Security Standards and Procedures Governing Eligibility for access to SCI;” ICD 705, ICS 705-1 – 705-2, “Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities;” DoDM 5200.01, “DoD Information Security Program;” DoD Manual 5200.02, “Procedures for the DoD Personnel Security Program” provide the necessary guidance for physical, personnel, and information security measures, to include proper marking requirements, and is part of the SCI security specifications for the contract.

2. Direct inquiries pertaining to classification guidance to the responsible MDA Contracting Officer’s Representative (COR/DTOR). The name/phone number for the MDA COR/DTOR is:

(Additionally, identify the Company Security POC (FSO/CSO) & phone number and email address at the contractor’s/subcontractor’s location): _________________________________.

3. All SCI furnished to the contractor in support of this contract/delivery/task order remains the property of the Department of Defense, or the agency or command that releases it. Upon completion of the contract, SCI furnished to the prime contractor will be returned to MDA or destroyed as directed by the MDA COR/DTOR. NOTE: Prime contractor and subcontractor company security officers who destroy derivative or MDA generated SCI material are required to provide a copy of the destruction certificate to the MDA COR/DTOR.

4. It is the Prime Contractor’s responsibility to ensure that all Sub-contractors requesting access to SCI have been properly cleared in accordance with the National Industrial Security Program.

The Prime Contractor will provide this SCI Supplement to their Sub-contractors as necessary according to the Sub-contractor’s clearance requirements. The Prime Contractor is further advised that SCI Billets used by the Sub-contractor will be subtracted from the total authorized billets allocated for this contract in paragraph 5 below. The COR/DTOR, the Prime Contractor FSO, and the Sub-contractor FSO will sign SCI nomination requests. A continuing access memo must be completed annually and submitted to the MDA SSO by 30 September.

5. The contract/delivery/task order requires the following SCI access(es): COR/DTOR are required to mark with an "X" the SCI accesses needed to effectively fulfill the SCI contractual obligation) SI X , TK X , G X , HCS X . Access will be granted by the government agency. Upon completion or cancellation of the contract the MDA COR/DTOR will provide a by name list of all contractors required to be debriefed from SCI to the MDA SSO before contract close-out. All debriefed contractors will be removed from MDA SCI billets immediately by the SSO. Based on mission requirements, this contract may authorize up to _81_ SCI billets.

6. Contractor personnel requiring access to SCI will be initiated by the company’s security officer with validation by the COR/DTOR. The CSO/FSO should submit a SCI nomination package on those contractor employees who have a completed (within the last 6 years) TIER 5 or a Single Scope Background Investigation (SSBI). This includes a Nom Memo, most recent SF86, a SCI nomination questionnaire, and a copy of DD Form 254 (Prime & Sub, as required).

Submit only personnel that have a real day-to-day need-to-know requirement. NOTE: The MDA SSO will not accept SF86 questionnaires dated prior to the 2016 version.

7. The CSO/FSO shall advise the MDA SSO, through the contracting officer's representative, upon reassignment of personnel to other duties not associated with this contract. NOTE:

Individual contractors who no longer support a MDA SCI contract will be debriefed from SCI access immediately. Company security officers are required to coordinate with the MDA SSO to get their individual contractors debriefed.

8. The CSO must coordinate with the MDA COR/DTOR prior to subcontracting any portion of the SCI efforts involved in their MDA SCI prime contract. A separate DD Form 254, utilizing this SCI Supplement, for the subcontractor will be processed and a copy provided to MDA SSO.

NOTE: The SSO will not provide any SCI administration support to prime contractors or subcontractors who do not have a signed active DD 254 for an MDA SCI contract.

9. The contractor shall not use references to SCI accesses, even by unclassified acronyms, in advertising, promotional efforts, or recruitment of employees.

10. All SCI work will be performed in a DIA accredited MDA SCIF unless otherwise authorized. Is there a SCIF required at the Contractor’s Facility? _____ Yes or __X__ No (COR/DTOR required to mark and “X” in the appropriate space).

11. AIS SCI Processing. Electronic processing of SCI requires accreditation of the equipment in accordance with ICD 503.

12. Visit Cert. The contractor FSO/CSO will submit the request for SCI visit certifications through the COR/DTOR for approval of the visit. The certification request must arrive at MDA Special Security at least five (5) working days prior to the visit.

13. The contractor will not reproduce or disseminate any SCI material without prior written permission of the COR/DTOR.

14. MDA has exclusive security oversight for all SCI released to the contractor or developed under this contract. Defense Intelligence Agency (DIA) and MDA SSO are the cognizant security authority for inspections of MDA-sponsored contractor SCIFs to ensure compliance of SCI Directives and Regulations. MDA Special Security will conduct self-inspections of MDA-sponsored SCIFs.

B. The Missile Defense Agency is designated as the User Agency for SCI requirements.

MDA SSO: Scott T. Jones, Special Security Officer

MDA SSO Signature: __________________________________________________

Phone: (256) 450-4097

COR/TM/DTOR/Directorate designation: _____________________________

COR/TM/DTOR Signature: ___________________________________________

Phone: _____________

Directorate Technical Oversight Representative: _____________________________

DTOR Signature: _______________________________________________________

Phone: ______________

Please wait...

If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.

You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.

For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.

Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.

HQ0858-21-R-0015 (RFI)

SECURITY GUIDANCE (BLOCK 13) CONTINUATION PAGES:

Special Requirements:

The contractor shall provide the following to the MDA Industrial Security (contact information listed in block 13 of page two of the DD Form 254):

• Prime contractors shall report events that will impact the status of subcontractors supporting a MDA mission; change of facility clearance (FCL); capability to properly safeguard classified information; adverse reports impacting an employee's personnel security clearance (PCL); indicators of an Insider Threat; classified information lost or compromised.

• Any loss, compromise or suspected compromise of classified information (foreign or domestic) by the Prime shall report to the Defense Counterintelligence and Security Agency (DCSA) and MDA Industrial Security within 24 hours.

• Immediately upon receipt of a possible loss, compromise, or suspected compromise of classified information, the contractor shall initiate a preliminary inquiry to ascertain all of the circumstances surrounding the reported loss, compromise or suspected compromise.

• Prime contractors shall provide a copy of submitted DCSA initial and final report(s) (without redaction) to the MDA Industrial Security Office, Contracting Officer or/and Contracting Officer’s Representative.

• Contractors shall promptly submit a written report to the nearest field office of the FBI regarding information coming to the contractor's attention concerning actual, probable or possible espionage, sabotage, terrorism, or subversive activities at any of its locations.

• Prime contractors shall provide a complete initial and final report (without redaction) to the MDA Industrial Security Office involving a cyber-intrusion of MDA program information sent to United States Computer Emergency Readiness Team (US-CERT), Federal Bureau of Investigation and the Defense Counterintelligence and Security Agency per NISPOM Chapter 1, Section 301to include Industrial Security Letter 2013-05 and NIST 800-61.

• Contractors shall provide a copy of the initial/final report (without redaction) to the MDA Industrial Security Office of any Defense Counterintelligence and Security Agency letter that indicates a less than satisfactory security rating and/or that negatively impacts the Facility Clearance Level (FCL) of the company within 24-hours of receipt.

• Prime contractors shall provide an electronic copy of issued subcontractor DD Form 254s to the MDA Industrial Security Office.

• Contractors sending classified mail shall actively (daily) track each classified package(s) throughout the entire transit process until the shipment is confirmed as received by the intended organization. The sender should monitor the transit process via the mail carrier's tracking process. If the last transit status entry on the mail carrier's tracking website was made more than one business day after the estimated delivery date, the sender will notify and provide the relevant details to their Facility Security Officer and the Missile Defense Agency in accordance with DD254 requirements.

• Information transported externally to a cleared facility shall be encrypted. The encryption of all MDA Controlled UNCLASSIFIED and CLASSIFIED removable media while in transit via authorized means of transmission including Couriers, Hand Carriers, and Escorts; the United States Postal Service (USPS); or other mail services (e.g., Federal Express, United Parcel Service, etc.). Contract direction shall incorporate the following tenants: All removable media (Hard Disk Drive (HDD), optical disk, Flash Media (USB HDD),Solid-state Drives (SDD), etc.) shall utilize data-at-rest (DAR) encryption:

- Classified data shall be encrypted using a FIPS 140-2 or more current NIST validated technology.

- Unclassified data to include Personal Identifiable Information (PII)/ For Official Use

Only (FOUO)/ Covered Defense Information (CDl)/Controlled Unclassified Information (CUI)/ Unclassified Controlled Technical Information (UCTI) shall use at least a FIPS 140-2 compliant technology, validated is recommended.

- Operating system, software, and hardware updates do not require encryption.

Any waiver requests for this requirement must be made by the contractor to the responsible Contracting Officer for approval consideration.

In accordance with NISPOM Chapter 1, Section 300, the contractor and its subcontractors shall notify the Contracting Officer, the Contracting Officer’s Representative, and MDA Industrial Security in writing within 24 hours of becoming aware of adverse information regarding an employee, who works within a Government/MDA facility, which could affect their access to classified information.

Subcontractor Classified Access Approvals:

The prime contractor and subcontractor are authorized to flow access to and/or dissemination of classified information to the TOP SECRET level to their subcontractor. Dissemination is only authorized and applicable for information safeguarded at the contractor’s facility. This authorization includes access to Critical Nuclear Weapon Design Information (CNWDI) (NISPOM Chapter 9, Section 204), Non-SCI Intelligence Information and North Atlantic Treaty Organization (NATO) (NISPOM Chapter 10, Section 708) information. The contractor shall provide the appropriate accesses to its subcontractors as required per NISPOM 5-502. The prime contractor and subcontractor must verify Facility Clearance, Safeguarding Capability and Access Authorizations prior to the dissemination of classified information. The following require specific authority: SCI - not authorized to flow without prior approval from MDA/Special Security Office (refer to SCI Supplement) and Special Access Program (SAP) - not authorized to flow without prior approval from MDA/Special Programs (refer to SAP Supplement).

This section concerns the release of classified information to the contractor regarding the Government’s Request for Information; MDA classified information may only be released to the contractor for submission preparation purposes following verification of the contractor’s facility clearance and safeguarding. The DD Form 254 shall act as security guidance for the safeguarding of Security Operations and Counterinetelligence related classified information at the Contractor facility. The Defense Counterintelligence and Security Agency maintains security cognizance of classified information stored at a Contractor facility. However, the following stipulations apply:

• IAW NISPOM paragraphs 5-200 and 5-600, contractors shall ensure full written accounting and control over all MDA classified information provided to the contractor by MDA or created as copies by the contractor.

• IAW NISPOM paragraphs 5-501 and 5-502, distribution of MDA classified information shall only be made to those cleared Contractor personnel working on the contractor’s response to the request for information, unless otherwise authorized by the Program Manager

(PM).

• IAW NISPOM paragraph 5-509, for purposes of this submission request, further distribution of MDA classified information shall only be authorized by the MDA PM overseeing this request for information.

• IAW NISPOM paragraphs 5-702, 5-703, and 5-704, all classified information provided for use in submission preparation shall be returned to MDA or destroyed.

• For contractor responses to Request for Information, offerors are advised that IAW DOD Instruction 5200.48 "Controlled Unclassified Information" dated March 6, 2020, MDA is transitioning to the use of "Controlled Unclassified Information" (CUI) instead of "For Official Use Only" (FOUO). Offerors shall rely on the guidance provided in the DOD Instruction and the Department of Defense (DOD) Office of Prepublication and Security Review (DOPSR20-S-2093), dated September 15, 2020 to obtain implementation guidance for the corresponding Defense Federal Acquisition Regulation (DFARS) Sections 252.204- 7008 and 252.204-7012. Contractors will be required to implement this guidance effective January 4, 2021.

Reference Item 8.a. (continued) Government Locations: Classified performance will occur at various MDA and/or Government locations as directed by the contract via the Performance Work Statement, Statement of Work, or Statement of Objectives or other agreement. The contractor shall abide by the host Government security requirements per NISPOM Chapter 1, Section 200 and Chapter 6, Section 105c. The cognizant security office at the performance location is MDA or the host installation.

Reference Item 10.a: The contractor shall comply with the requirements of NISPOM Chapter 9, Section 4 and National Security Agency/Central Security Service Policy Manual Number 3-16, Control of Communications Security (COMSEC) Material, for access to and safeguarding of COMSEC information.

Reference Item 10.b &10.d: Contractors shall adhere to the requirements of DoDI 5210.02, “Access to and Dissemination of Restricted Data (RD) and Formerly Restricted Data (FRD),” 3 June 2011, for access and training requirements. Flow this requirement and training materials to subcontractors when applicable.

1. Contractors shall possess a valid DoD security clearance at a level commensurate with the information concerned and shall have a need-to-know for access. DoD contractors require a final Secret security clearance for access to Secret RD information. Contractors shall have a final Top Secret security clearance for access to Top Secret RD information. NISPOM section 2-211a. applies.

The prime contractor and its subcontractors shall be required to complete training for access to RD/FRD material and for derivative classification of RD/FRD information. This training is provided by the Department of Energy (DOE) and shall be arranged by the MDA Contracting Officer Representative (COR) whom will coordinate with the DEI, Associate Restricted Data Management Official (mda_rdmo@mda.mil) to schedule training. The company’s Facility Security Officer (FSO) shall maintain a record of the training for each individual with access to RD/FRD. These records shall be made readily available during security inspections or for other Government purposes. Records shall be maintained for two years after an individual no longer requires access to RD/FRD information.

a. For individuals with access to RD/FRD information, personnel shall complete the “Classification of Nuclear Weapons-Related Information (Restricted Data and Formerly Restricted Data)” course, “RD Derivative Classifier” course and TFNI Briefing. The contractor company shall maintain a record of the training for each individual with access to RD/FRD. These records shall be made readily available during security inspections or for other Government purposes. Records shall be maintained for two years after an individual no longer requires access to RD/FRD information.

b. For individuals who will conduct derivative classification, personnel shall complete the “Classification of Nuclear Weapons-Related Information (Restricted Data and Formerly Restricted Data)” course, “RD Derivative Classifier” course and TFNI Briefing. The training course shall be arranged by the MDA Contracting Officer Representative (COR) whom will coordinate with the DEI, Associate Restricted Data Management Official (mda_rdmo@mda.mil) to schedule training and will be certified as a Derivative Classifier IAW MDA procedures. The contractor company shall maintain a record of the training for each individual designated as a RD Classifier. These records shall be made readily available during security inspections or for other Government purposes. Records shall be maintained for two years after an individual is no longer designated as a RD Classifier.

Reference Item 10.c: NISPOM Chapter 9, Section 2 requirements apply. Access to Critical Nuclear Weapons Design Information requires a final clearance.

Reference Item 10.e.(1): This contract requires access to Sensitive Compartmented Information (SCI) material. The contractor is not required to have an accredited SCI Facility but requires access to SCI at other locations. Additionally, the Facility Security Officer will ensure that when a contractor with access to SCI is due for a Periodic Reinvestigation, the Periodic Reinvestigation request is conducted to meet SCI standards. Written U.S. Government approval by MDA/Special Security is required prior to giving SCI access to a subcontractor. Additional requirements are included in the attached SCI Supplement.

Reference Item 10.e.(2): NISPOM Chapter 9, Section 3 requirements apply. Non-SCI Intelligence Information (SCI) is intelligence information existing at the collateral level and is typically, but not always, identified by the NOFORN caveat. The ODNI defers to the 32 CFR 2001 and as stated in the ICS 703-01 for classified national intelligence information and only requires government (i.e. MDA) determination for prime contractor to subcontractor flow-down.

Reference Item 10.f: Requirements are included in the attached SAP Supplement.

Reference Item 10.g: NISPOM Chapter 10, Section 7 requirements apply.

Reference Item 10.h: NISPOM Chapter 10, Section 3 requirements apply.

Reference Item 10.j:

1. The contractor shall adhere to the requirements in the DoD Instruction 5200.48, Controlled Unclassified Information (CUI) and Information Security Oversight Office Notice 2019-03 “Destroying Controlled Unclassified Information in Paper Form” (15 July 2019) for safeguarding, marking, transmission, dissemination, and disposition of all CUI and For Official Use Only (FOUO) information.

2. Access.

a. Access to CUI and legacy FOUO should be limited to U.S. Nationals that have either a current U.S. security clearance (minimum interim SECRET clearance) or have been the subject of a favorably completed National Agency Check with Inquiries (i.e., Standard Form (SF) 85 Position of Trust investigation) or equivalent investigation (i.e., approved contractor equivalent).

(1) Definitions:

(a) A U.S. Person is defined as any form of business enterprise or entity organized, chartered or incorporated under the laws of the United States or its possessions and trust territories, and any person who is a citizen or national of the United States

(b) A U.S. National is defined as a citizen of the U.S., or a person who, though not a citizen of the U.S., owes permanent allegiance to the U.S. Also see 8 USC 1101(a) (22) or 8 USC 1401 paragraphs (a) through (g) for further clarification on those who may qualify as nationals of the United States.

(2) Contractor Equivalent: Contractor equivalent includes various background checks such as those performed by employers during hiring process. At a minimum, the Contractor Equivalent Background Plan (CEBP) will include citizenship, Personal Identification (Social Security Number), and criminal background checks. The contractor shall submit a list of their procedures on company letterhead through the Contracting Officer or their representative for concurrence by the designated MDA approving office.

b. Contractor personnel with dual or foreign citizenship (including but not limited to those with permanent resident status) will be subject to an additional review; and found favorable by MDA prior to access to CUI and legacy FOUO. (Note: Contractor personnel with dual citizenship that have an active U.S. security clearance (interim Secret or higher) may have access to CUI and legacy FOUO material without additional review.)

3. See Reference Item 11.l. for safeguarding of CUI and legacy FOUO on a contractor’s unclassified information system(s).

4. The contractor shall flow-down this requirement to all subcontractors requiring access to CUI and legacy FOUO information regardless if the subcontractor has a facility security clearance or not. For those uncleared subcontractors, the prime contractor shall ensure this section exists within the language of the subcontract/purchase order.

Reference Item 11.a: Classified contract performance is restricted to MDA/Government facilities and/or other contractor company facilities. The host contractor/Government activity will provide required security classification guidance for the performance of this contract, consistent with work performed at that location. The Prime Contractor, as listed in Item 6.a, shall be required to follow all security policies and procedures and use Security Classification Guides of the host activity. This requirement shall be imposed on all subcontracts.

Reference Item 11.f:

1. The contractor shall require access to classified information overseas at areas designated in the Statement of Work, Performance Work Statement, or Statement of Objectives.

2. Contractor personnel traveling on DoD-sponsored (official) travel overseas shall complete all training and messaging requirements outlined within the DoD Foreign Clearance Guide (FCG) for the foreign country being visited and support administrative reporting requirements specified by their program Country Clearance Message (CCM) Coordinator within 45-days prior to travel.

Contractor personnel should review U.S. Department of State (DoS) Travel Warnings, Travel Alerts, and individual country specific information located at U.S. Department of State (DoS) Travel Warnings web address and are encouraged to enroll in the U.S. DoS Smart Traveler Enrollment Program (STEP) prior to commencing official travel overseas.

3. The contractor shall submit foreign visit requests as dictated by the NISPOM, Chapter 10, Section 5. A contractor shall submit the visit request through the Defense Counterintelligence and Security Agency-designated security official.

4. The contractor is not authorized per the NISPOM to establish a contractor facility outside of the U.S., its possessions, or its territories. Storage, custody, and control of classified information required by a U.S. contractor employee abroad is the responsibility of the U.S. Government.

Storage of classified information shall be at a U.S. military facility, a U.S. Embassy or Consulate, or another location occupied by a U.S. Government organization.

Reference Item 11.j: Have Operations Security (OPSEC) Requirements.

This contract requires the application of Operations Security (OPSEC):

1. The contractor supporting specific event-oriented activities shall comply with OPSEC requirements and briefings as defined in the Statement of Work (SOW)/Performance Work Statement (PWS).

2. Contractor personnel assigned shall receive initial and annual OPSEC Awareness Education as directed in the SOW.

3. The contractor shall plan for and implement OPSEC supply chain processes and practices that restricts information flow-down (manufacturing need-to-know) and limits information listed on commodity Purchase Orders for critical information and critical components.

4. The contractor shall apply OPSEC during flight test activities in accordance with specific test plans.

Reference Item 11.l: The contractor shall adhere to the requirements in the DoD Manual 5200.01, DoD Information Security Program, Volume 4, Controlled Unclassified Information (CUI) and Information Security Oversight Office Notice 2019-03 “ Destroying Controlled Unclassified Information in Paper Form”(15 July 2019) for safeguarding, marking, transmission, dissemination, and disposition of all CUI/For Official Use Only (FOUO) information.

**PLEASE NOTE -- DoD Manual 5200.01, Volume 4, "DoD Information Security Program:

Controlled Unclassified Information," dated February 24, 2012, as amended will be replaced by DoDI 5200.48 "Controlled Unclassified Information," dated March 6, 2020.**

Reference Item 11.m: Contractor’s Unclassified Automated Information System:

1. DoD information systems processing, storing, or transmitting CUI will be categorized at the “moderate” confidentiality impact level and follow the guidance in DoDIs 8500.01 and 8510.01.

Non-DoD information systems processing, storing, or transmitting unclassified nonpublic DoD information will provide adequate security, and the appropriate requirements must be incorporated into all contracts, grants, and other legal agreements with non-DoD entities in accordance with DoDI 8582.01.

2. The Contractor shall safeguard and protect nonpublic information provided by or generated for the Government that transits, resides, or is processed on any non-Government information technology system IAW the procedures in DoDI 8582.01, “Security of Non-DOD Information Systems Processing unclassified nonpublic DoD Information”. Additionally, if the contract includes the DFARS Clause 252.204-7012, Safeguarding of Covered Defense Information and Cyber Incident Reporting, then the contractor must comply with its requirements. If the DFARS Clause 252.204-7012 does not exist on contract, the contractor shall comply with the requirements of the Office of Management and Budget Circular A-130 and the DoD Directive

8100.2 until such time as the DFARS Clause 252.204-7012 may be added.

3. MDA reserves the right to conduct compliance inspections of Contractor unclassified and classified information systems and other repositories to verify the protection of unclassified nonpublic DoD information.

4. The contractor shall flow this reference item to all subcontractors that process and access unclassified nonpublic DoD information regardless if the subcontractor has a facility security clearance or not. For those uncleared subcontractors, the prime contractor shall ensure this section exists within the language of the subcontract/purchase order.

Reference Item 12: Refer to Contracts Clause H-08 Public Release of Information.

DRAFT

SAMPLE

PREVIOUS EDITION IS OBSOLETE.

Page of

AEM LiveCycle Designer

DD FORM 254, APR 2018

NEEDS DD67

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567

OMB approval expires:

October 31, 2020

The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

b. REVISED (Supersedes all previous specifications.)

4. IS THIS A FOLLOW-ON CONTRACT?

If yes, complete the following:

Classified material received or generated under

5. IS THIS A FINAL DD FORM 254?

If yes, complete the following:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors

-- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

e. NATIONAL INTELLIGENCE INFORMATION:

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

9.0.0.2.20120627.2.874785

DD 254, DoD Contract Security Classification Specification

List of Attachments [1] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)

DD 254 (HQ0858-21-R-0015 (RFI) Continued Security Guidance.pdf

CurrentPage:

PageCount:

Classification: Unclassified

SerialNum:

a. Facility clearance level. Select one.: 1

b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4

Choose Yes or No: 0

Choose Yes or No: 1

Prime:

Choose Yes or No: 0

Choose Yes or No: 0

Sub:

Choose Yes or No: 1

Choose Yes or No: 0

Soli: HQ0858-21-C-0015

DueDate:

dateA: 2021-06-10

RevisionNum:

dateB:

Final:

dateC:

No: 1

No: 1

No: 0

No: 1

Yes: 0

Yes: 0

Yes: 1

Yes: 0

Enter your name here.:

ReqDated:

Enter your name here.:

Name:

Name: Amanda Behel

Cage:

CSO:

addrow:

Removerow:

Click to delete a row:

Location:

Block9:

TEAMS Next Security Operations and Counterintelligence a: 1 a: 1 a: 1 f: 1 f: 1 f: 1 b: 1 b: 0 b: 0 g: 1 g: 0 c: 1 c: 0 c: 1 h: 1 h: 0 d: 1 d: 0 d: 0 i: 0 i: 0

SCI: 1

NonSCI: 1 j: 1 j: 1 k: 0 k: 0

Enter your name here.: Additional Requirements for Contractor’s Unclassified Automated Information Systems

Enter your name here.: MDA Industrial Security e: 0 e: 1 l: 1 m: 1 direct: 0 thru: 1

Enter your name here.: MDAPressOperations@mda.mil and simultaneously provide courtesy copy to the appropriate PCO.

PublicAuthority: Missile Defense Agency, Public Affairs Office is the public release approval authority.

AddSig:

RemoveSig:

text: The prime contractor shall flow-down all applicable requirements of the DD Form 254 to its subcontractor(s).

Prime contractors with questions regarding their DD254 should contact their Contracting Office Representative (COR) or the MDA Industrial Security office at (256) 450-0939, by email at MDAIndustrialSecurity@mda.mil, or by mail to MDA, ATTN: Industrial Security Office (DEI), Building 5222 Martin Road, Redstone Arsenal, AL 35898.

text: Missile Defense Agency Bldg. 5222 Martin Road Redstone Arsenal, AL 35898 attachmentsList:

AddAttachment:

ViewAttachment:

RemoveAttachment:

rep:

Sig:

Enter your name here.: See Reference Items; 10.e.(1), 10.f, 10.j, 11.j, 11.l., and 11.m.

GCAName: Missile Defense Agency

AAC: HQ0858

AAC: HQ0858

Address: Missile Defense Agency Bldg. 5222 Martin Road Redstone Arsenal, AL 35898

Address: Missile Defense Agency Bldg. 5222 Martin Road Redstone Arsenal, AL 35898

POCName: Amanda Behel

Phone: 2564501511

Phone: 2564501511

Email: amanda.behel@mda.mil

Email: amanda.behel@mda.mil

Title: Contracting Officer

Enter the date using the format DD-Mon-YYYY:

Approved for Public Release

21-MDA-10929 (18 Aug 21)

Attachment J-08 – DD254

TEAMS-Next Security Operations and Counterintellignce

HQ0858-21-R-0015

DA SAPCO Form 24 (January 21, 2021) Previous Editions are Obsolete

CUI

(U) DD FORM 254 SPECIAL ACCESS PROGRAM (SAP) SUPPLEMENT

Contract No:

1. Item 10f:

a. This contract involves DoD SAPs. Strict requirements for need-to-know, special handling, physical security measures, and administrative controls beyond the requirements of the National Industrial Security Program are required. SAP participants must comply with the enhanced security procedures outlined in this document.

b. Access to MDA SAP information or material is authorized only at facilities and locations specifically approved by MDA Special Programs. The government program security officer (PSO) will contact the contractor facility security officer (FSO) to obtain security information on facilities and personnel required to perform on this contract. Access to SAP information requires a final U.S.

Government:

(1) Secret SAP requires a final SECRET (S) clearance based on a NACLC, ANACI, T3 or T3R investigation current within 6 years (or reinvestigation deferment with enrollment in continuous evaluation), an approved SAP nomination, and a signed SAP non-disclosure agreement prior to access.

(2) Top Secret SAP requires a final TOP SECRET (TS) clearance based on a PPR, SSBI, SSBI-

PR, T5, or T5 investigation current within 6 years (or reinvestigation deferment with enrollment in continuous evaluation), an approved SAP nomination, and a signed SAP non- disclosure agreement prior to access.

c. The contractor will perform all SAP work, regardless if in a prime or subcontractor’s location, in an MDA-approved SAP facility (SAPF). If there is a requirement to discuss, store, or process SAP information in an existing sensitive compartmented information facility (SCIF), SAPF, or closed area, the cognizant security representatives for the MDA SAP and the other existing area will execute a memorandum of understanding (MOU) or a co-use agreement (CUA). The contractor will prepare a standard operating procedure (SOP) for each SAPF and coordinate its approval with MDA Special Programs.

2. Item 11h: Consult with MDA Special Programs prior to ordering encryption devices or COMSEC keying material to support SAP data transmissions.

3. Item 11i: TEMPEST requirements may be necessary in the performance of this contract in accordance with program requirements, Committee on National Security Systems Advisory Memorandum (CNSSAM) TEMPEST 01-13, DoD Manuals, and applicable MDA SAP Central Office (SAPCO) policies. Consult with MDA Special Programs to confirm the requirements.

4. Item 11j: OPSEC requirements are necessary in the performance of this contract. MDA Special Programs will provide specific guidance.

Controlled by: DEZ CUI Categories: OPSEC Limited Dissemination Control: FEDCON POC: Daniel Knott, (256) 450-5302

5. Item 12:

d. Public release of SAP information is prohibited. Do not release documents or other materials related to this SAP to the Defense Technical Information Center (DTIC) or any other such information service. SAP-briefed personnel will seek pre-publication and/or presentation(s) review and approval through the contractor program security officer (CPSO) to the MDA PSO prior to the use of any classified or unclassified information which is either directly or tangentially related to any SAP. The MDA SAPCO must approve these requests in writing.

e. The contractor must not use references to SAP accesses (nicknames, di/tri-graphs, etc.) or information, even by unclassified acronyms, in advertising, promotional efforts, or employee recruitment.

6. Item 13: The Government PSO will provide additional security classification guides (SCGs) specific to the SAPs under this contract. Contractors will classify SAP material in accordance with the provided SCGs and applicable publications listed in Item14.

f. Prior to processing, storing, transmitting, transferring, or communicating MDA SAP information on any information system (IS) or network, the contractor must comply with the latest statutory, regulatory, as well as national, DoD, and MDA policy guidance, to include those references listed in Item 14. The contractor must obtain the requisite authorization to test, connect, or to operate from the MDA authorizing official (AO).

g. The contractor must employ physical security safeguards for IS and/or networks involved in processing or storage of government information to prevent unauthorized access, disclosure, modification, destruction, use, and to otherwise protect the confidentiality and ensure use conforms with DoD regulations.

7. Item 14: Contractors performing under this contract will use the following publications unless exempted by MDA Special Programs. MDA Special Programs will provide the contractor these publications if requested.

a. Applicable PSO-approved facility-specific SOPs, treaty plans, and OPSEC guides.

b. DoD Directive 5205.07, “Special Access Program (SAP) Policy.”

c. DoD Directive 5205.16, “Insider Threat Program.”

d. DoD Instruction 4140.01, “DoD Supply Chain Material Management Policy.”

e. DoD Instruction 5205.11, “Management, Administration, and Oversight of DoD Special Access

Programs (SAPs).”

f. DoD Instruction 8510.01, “Risk Management Framework (RMF) for DoD Information Technology

(IT).”

g. DoD Instruction 8582.01, “Security of Non-DoD Information Systems Processing Unclassified

Nonpublic DoD Information.”

h. DoD Joint Special Access Program (SAP) Implementation Guide (JSIG) and applicable MDA

Implementation guidance, to include JSIG errata, “Data at Rest (DAR) encryption for SAP material.”

i. DoD Manuals 5200.01, Volumes 1 through 3, “DoD Information Security Program.”

j. DoD Manual 5200.48, "Controlled Unclassified Information (CUI)."

k. DoD Manuals 5205.07, Volumes 1 through 4, “DoD Special Access Program (SAP) Security Manuals,” and MDA Implementation Guidance.

l. DoD 5220.22-M, “National Industrial Security Program Operating Manual.”

m. DoD Memo, “Transition to the Risk Management Framework.”

n. DoD “Security Marking Implementation Guide for Special Access Programs.”

o. MDA Special Programs "Assured File Transfer Process."

p. MDA Special Programs “SAP Nomination Process (SAPNP).”

q. MDA Special Programs "Top Secret Control Officer's (TSCO) Guide."

r. National Security Agency/Central Security Service (NSA/CSS) Policy Manual 9-

12, “NSA/CSS Storage Device Sanitization Manual.”

s. NSA/CSS Policy Manual 3-16, “Control of COMSEC Material.”

t. OMB Memorandum, “Management and Oversight of Federal Information Technology.”

u. Security Executive Agent Directive (SEAD) 3, “Reporting Requirements for Personnel with

Access to Classified Information or Who Hold a Sensitive Position.”

8. Item 15: MDA Special Programs will conduct program/security reviews of all SAPFs, material, and operations related to this contract. Defense Counterintelligence and Security Agency (DCSA)oversight over SAP portions of this contract is carved-out.

9. Contract Number: The contractor may be required to establish internal procedures and charge numbers that will be documented in their MDA Special Programs-approved business financial management processes as necessary for cost accumulation by un-cleared personnel.

10. Subcontracting: Subcontracting must have prior approval from MDA Special Programs. Any classified program activity requiring the use of a subcontractor facility must meet DoD Manual 5205.07-V3, the MDA Implementation guide, and be approved by MDA Special Programs.

11. Communications and Transmissions:

a. All material relating to this contract and its administration must be classified in accordance with MDA and SAP-specific SCGs and this DD Form 254, or as directed by MDA Special Programs.

b. Program-related communications will be conducted on secure communication devices.

12. Vouchers: All invoices submitted under this contract must be unclassified and free of any details that, when combined with other information in the document, result in its classification by compilation or an OPSEC concern. Invoices/vouchers will be processed IAW Section G of the contract, equivalent agreement or payment instructions, or as directed by the procuring contracting officer (PCO).

13. Legal Counsel: Notify the PCO and MDA Special Programs, in writing, should the contractor require private counsel to represent corporate interests in matters related to or associated with SAP-sponsored activities. The private counsel must be treated as a subcontractor.

In those incidents where the issues are not program-specific, it is the responsibility of appropriately indoctrinated contractor personnel to prevent inadvertent disclosure of SAP-related information and/or sensitive administrative or operational details.

14. Retention of Program-Related Documentation, Software, and Hardware: Upon completion of this contract and government acceptance of final deliverables, the contractor must:

a. Conduct an inventory/audit of all SAP material received and/or generated under this contract and forward it to MDA Special Programs.

b. In accordance with MDA Special Programs direction, the contractor must destroy administrative security records and related documents using an approved destruction method and maintain certificates of destruction for final close-out review. Retention of SAP information at the contractor facility is not generally authorized beyond contract close-out unless a follow-on contract or task is anticipated. The contractor will send a written request for document, software, and hardware retention to the PCO and MDA PSO for approval.

15. Issues/Conflict Reporting:

a. Refer any questions on classification, access, or any other security-related issue regarding the SAP portion of this contract to MDA Special Programs.

b. Report any conflict between instructions contained in this DD Form 254 and the contract to MDA Special Programs by the most expedient and secure means available.

Contracting Representative SAP Security Representative Missile Defense Agency Missile Defense Agency

CUI

1. Item 10f:

CUI

CUI

11. Communications and Transmissions:

CUI

15. Issues/Conflict Reporting:

Contracting Representative SAP Security Representative

CUI

Text1: HQ0858-21-R-0015

Check Box2: Off

Check Box3: Yes

Text4:

Text5: Ricky Tullock

File details come from the government source that posted it. Updated .