HT0011-14-R-0021-Attachment_5-DD254.pdf

PDF 407 KB Posted

Attached to
Other Health Insurance Federal contract opportunity
Solicitation number
HT0011-14-R-0021
Issued by
Defense Health Agency

About this file

Attachment 5- DD254. See attached document for more information.

View the file

Other files for this federal contract opportunity

Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the DoD Industrial Security Manual apply to all security aspects of this effort.)

1. CLEARANCE AND SAFEGUARDING

a. FACILITY CLEARANCE REQUIRED

b. LEVEL OF SAFEGUARDING REQUIRED

2. THIS SPECIFICATION IS FOR: (X and complete as applicable)

a. PRIME CONTRACT NUMBER

b. SUBCONTRACT NUMBER

c. SOLICITATION OR OTHER NUMBER DUE DATE (YYYYMMDD)

3. THIS SPECIFICATION IS: (X and complete as applicable)

a. ORIGINAL (Complete date in all cases)

REVISION NO.

c. FINAL (Complete Item 5 in all cases)

DATE (YYYYMMDD)

b. REVISED (Supersedes all previous specs)

DATE (YYYYMMDD)

DATE (YYYYMMDD)

4. IS THIS A FOLLOW-ON CONTRACT? YES NO. If Yes, complete the following:

Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.

5. IS THIS A FINAL DD FORM 254? YES NO. If Yes, complete the following:

In response to the contractor's request dated , retention of the classified material is authorized for the period of

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

7. SUBCONTRACTOR

a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

8. ACTUAL PERFORMANCE

a. LOCATION b. CAGE CODE c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

9. GENERAL IDENTIFICATION OF THIS PROCUREMENT

10. CONTRACTOR WILL REQUIRE ACCESS TO: 11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL:YES NO YES NO

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION

b. RESTRICTED DATA

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION

d. FORMERLY RESTRICTED DATA

e. INTELLIGENCE INFORMATION

(1) Sensitive Compartmented Information (SCI)

(2) Non-SCI

f. SPECIAL ACCESS INFORMATION

g. NATO INFORMATION

h. FOREIGN GOVERNMENT INFORMATION

i. LIMITED DISSEMINATION INFORMATION

j. FOR OFFICIAL USE ONLY INFORMATION

k. OTHER (Specify)

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER

CONTRACTOR'S FACILITY OR A GOVERNMENT ACTIVITY

b. RECEIVE CLASSIFIED DOCUMENTS ONLY

c. RECEIVE AND GENERATE CLASSIFIED MATERIAL

d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

e. PERFORM SERVICES ONLY

f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES

g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION

CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER

h. REQUIRE A COMSEC ACCOUNT

i. HAVE TEMPEST REQUIREMENTS

j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE

l. OTHER (Specify)

DD FORM 254, DEC 1999 PREVIOUS EDITION IS OBSOLETE. Adobe Professional 7.0

12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the Industrial Security Manual or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for approval prior to release

a. TYPED NAME OF CERTIFYING OFFICIAL

Direct Through (Specify)

d. ADDRESS (Include Zip Code)

Yes No to the Directorate for Freedom of Information and Security Review, Office of the Assistant Secretary of Defense (Public Affairs)* for review.

*In the case of non-DoD User Agencies, requests for disclosure shall be submitted to that agency.

13. SECURITY GUIDANCE. The security classification guidance needed for this classified effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Add additional pages as needed to provide complete guidance.)

14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to ISM requirements, are established for this contract.

(If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the cognizant security office. Use Item 13 if additional space is needed.)

Yes No15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the cognizant security office.

(If Yes, explain and identify specific areas or elements carved out and the activity responsible for inspections. Use Item 13 if additional space is needed.)

16. CERTIFICATION AND SIGNATURE. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.

b. TITLE c. TELEPHONE (Include Area Code)

e. SIGNATURE

17. REQUIRED DISTRIBUTION

a. CONTRACTOR

b. SUBCONTRACTOR

c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION

e. ADMINISTRATIVE CONTRACTING OFFICER

f. OTHERS AS NECESSARY

DD FORM 254 (BACK), DEC 1999

fac_clear: SECRET
safe_level: SECRET
prime_no: TBD
xprime: Off
sub_no:
xsub: Off
xsolic: Off
solic_no: TBD
due_date:
xspec3: Orig
orig_date:
rev_no:
rev_date:
final_date:
xfollowon: No
prec_no:
xfinal: No
req_dated:
period:
ctr_name: TBD upon contract award
ctr_cage:
ctr_ofc:
sub_name:
sub_cage:
sub_ofc:
perf_loc: Defense Health Agency

Defense Health HeadQuarters Health Information Technology 7700 Arlington Blvd Falls Church, Va 20042

perf_cage:
perf_ofc:
gen_id: This procurement is in support of the Defense Health Discovery and Validation of Other Health Insurance
x10a: No
x10b: No
x10c: No
x10d: No
x10e1: No
x10e2: No
x10f: No
x10g: No
x10h: No
x10i: No
x10j: Yes
x10k: Yes
other10k:
x11a: Yes
x11b: Yes
x11c: Yes
x11d: Yes
x11e: Yes
x11f: Yes
x11g: Yes
x11h: Yes
x11i: Yes
x11j: Yes
x11k: Yes
x11l: Yes
other11l:
xrelease: Yes
release_thru:
guidance: See TRICARE Systems Manual 7950.2-M Section 7.0 Personnel Security ADP/IT Requirements; Section 8.3 Verification Process for Contractor Employees Requiring CACs; an Section 10.0 Public Key Infrastruction for technical specifications.

The Contractor shall establish appropriate administrative, technical, and physical safeguards to protect any and all Government data, to ensure the confidentiality, integrity, and availability of Government data. As a minimum, this shall include provisions for personnel security, electronic security and physical security. The Contractor shall implement and maintain information security in its project, enterprise, or company-wide unclassified information technology system(s) in accordance with the requirements set forth in DoD Instruction 8582.0 I, Security of Unclassified DoD Information on Non-DoD Information Systems, June 6, 2012. The Contractor shall, at a minimum, comply with the security controls specified by National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, Revision 3, dated August 2009, Privacy Act Program Requirements (DoD 5400, 11-R), the Personnel Security Program (DoD 5200.2-R) and OMB M-06-16, Protection of Sensitive Agency Information. In addition, the Contractor shall comply with DoD Minimum security requirements as outlined in the TRICARE Systems Manual, Chapter 1, Section 1.1 (except for paragraphs 3.4 and 3.5 through 3.5.1.7). Government validation of the Checklist and Certification for Minimum Level of Enhanced Safeguarding for Unclassified DoD Information is required prior to accessing DoD data or inter-connectivity with the Government systems and testing. If a control is not implemented, the Contractor shall prepare a written determination that explains how either the required security control is not applicable or how an alternative control or protective measure is used to achieve equivalent protection in accordance with the Contract Deliverable Requirements List (CDRL).

xaddlsec: No
addl_sec:
xinsp: No
inspections:
cert_name:
cert_title:
cert_phone:
cert_addr:
cert_sign:
x17a: Yes
x17b: Off
x17c: Off
x17d: Off
x17e: Yes
x17f: Off
other_dist:
Reset:

File details come from the government source that posted it. Updated .