M19-R-2000_DD_254_CONT_Sheets.pdf
PDF 376 KB Posted
- Attached to
- Next Generation Troposcatter Federal contract opportunity
- Solicitation number
- M67854-19-R-2000
- Issued by
- United States Marine Corps
About this file
This document contains continuation sheets for a DD Form 254 associated with Federal Contract Number M67854-19-R-2000. The contract requires support for a Next Generation Troposcatter system, including classified work within Marine Corps Systems Command sites. The contractor must comply with various security orders and regulations regarding classified information handling, personnel security, visits to government facilities, and destruction of classified materials. Additional requirements include reviewing public releases for compliance, returning badges and credentials upon termination, and retaining classified materials for up to two years with approval. The continuation sheets provide supplemental security guidance for contractor generated communications security materials, including restrictions on access, dissemination, transportation, and destruction. Personnel security program requirements are also outlined, designating IT position risk levels and required background investigation tiers.
DD 254, Continuation Sheet (Attachment A to the DD 254 form)
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Continuation Sheet for DD Form 254 Contract Number M67854-19-R-2000
ADDITIONAL GUIDANCE:
(a) Security classification guides (SCGs) required during this contract will be listed, if applicable, in Block 13 of the attached DD-254. A copy of these orders will be provided to the contractor by MARCORSYSCOM’s Government Contracting Agency (GCA) under separate cover. Only the SCGs listed will be provided.
(b) In the event classified mail is required for program support, provide the tracking number to the CMCC Custodian. The CLASSIFIED mailing address is listed below.
Outer Envelope: Inner Envelope:
COMMANDER MCSC COMMANDER MCSC
ATTN CMCC ATTN CMCC POC NAME
2200 LESTER STREET 2200 LESTER STREET
QUANTICO VA 22134 QUANTICO VA 22134
(c) In addition to the reporting requirements directed by the DoD 5220.22-M (NISPOM), the contractor will provide a concurrent report of loss or compromise of classified information to the CMCC Custodian. The UNCLASSIFIED mailing address is listed below.
COMMANDER MCSC
ATTN CMCC CUSTODIAN
2200 LESTER STREET
QUANTICO VA 22134-6050
(d) Contractors will conduct a security review and comply with MARCORSYSCOMO 5720.2A, “PUBLIC RELEASE
REVIEW PROCESS” prior to entering government information on a home page (contractor or government web page site). A copy of this order will be provided to the contractor by MARCORSYSCOM’s GCA under separate cover.
(e) IAW Defense Security Service Industrial Security Letter (ISL) 2006-01, the Joint Personnel Adjudication System (JPAS) is the “CSA-designated database” referenced in the NISPOM (para 2-200b.) All contractor personnel performing on this contract will be correctly listed in JPAS, and JPAS will be utilized for classified visit certifications and shall not exceed a 12 month period.
(f) All MARCORSYSCOM Badges and Common Access Cards (CACs) issued under this contract must be returned immediately to the MARCORSYSCOM AC/S G-2 (Personnel Security, Room 145) upon termination of contract, or individual terminations. When an individual contractor is terminated, for any reason, it is the responsibility of the Facility Security Officer (FSO) to immediately notify the AC/S G-2. Failure to comply could result in the suspension of all contractor badge and network accounts.
(g) All SIPRNET Tokens issued under this contract must be returned immediately to AC/S G-6 (Bldg 2201A) upon termination of contract, or individual terminations. Same rules apply as badges and CACs.
(h) If additional contracting requirements exist where retention of classified information by the contractor facility is required after the contract has ended, a written request to retain material will be forwarded to the GCA. If approved, a Final DD-254 will be issued for a period not to exceed 2 years.
(i) All work performed within MARCORSYSCOM sites/spaces, will follow SECNAV M-5510.30 (Personnel Security Program), SECNAV M-5510.36 (Information Security Program), COMMAND ORDER 5530.2A (Access Control Order), and MARCORSYSCOMO P5510.2B Security Manual for all security guidance and instructions.
A copy of these orders will be provided to the contractor by MARCORSYSCOM’s GCA under separate cover.
(j) In addition to this DD-254, the contractor shall comply with the Federal Acquisition Regulation (FAR) clauses 52.204-2, “Security Requirements” and 52.204-21, “Basic Safeguarding of Covered Contractor Information Systems.”
ATTACHMENT A
ADDITIONAL SECURITY GUIDELINES FOR COMSEC
Contractor Generated Communications Security (COMSEC) Material: Any material generated by the contractor (including, but not limited to: correspondence, drawings, models, mockups, photographs, schematics, status programs and special inspection reports, engineering notes, computations and training aides) will be classified according to its own content.
If the contractor is authorized to receive Government furnished cryptographic equipment, the guidance will state that fact, see paragraph 11h. Non-accountable COMSEC information may still require a level of control within a document control system. If access to COMSEC information is required at Government facilities, contractor personnel will follow the security requirements of the host government activity.
REQUIREMENTS:
1. Refer to DoD 5220.22-M (NISPOM) and NSA/CSS Policy Manual 3-16, “Control of Communications Security Material” and the Committee on National Security Systems Instruction (CNSSI) 4001, “Controlled Cryptographic Items,” for guidance.
2. All contractor personnel to be granted access to classified COMSEC information must be U.S. citizens granted FINAL clearance by the government prior to being given access. Contractor personnel granted CONFIDENTIAL or INTERIM SECRET clearance are not eligible for access to COMSEC information released or generated under this contract without the express permission of the Director, NSA.
3. Contractor personnel or cleared commercial carriers shall not carry classified COMSEC material on commercial passenger aircraft anywhere in the world without the approval of the procuring contracting officer.
4. No contractor generated COMSEC or government furnished COMSEC material may be provided to the Defense Technical Information Center (DTIC).
5. Classified paper COMSEC material may be destroyed by burning, disintegration, chopping or high security cross-cut shredding. Cryptographic key tapes must be “terminally” destroyed (destroyed to the point where it cannot be reconstructed) utilizing devices listed on the Evaluated Products List (EPL) for Punched Tape Destruction Devices or the EPL for High-Security Disintegrators. A listing of EPLs can be found at http://www.nsa.gov/ia/government/mdg.cfm. When a method other than burning is used, all residue must be reduced to pieces 5mm or smaller in any dimension. When classified COMSEC material other than paper is to be destroyed, specific guidance must be obtained from the User Agency.
6. Unclassified COMSEC information released or generated under this contract shall be restricted in its dissemination to personnel involved in the contract. Release in open literature or exhibition of such information without the express written permission of the Director, NSA, is strictly prohibited.
7. Further disclosure of COMSEC information by a contractor, to include subcontracting, requires prior approval of the GCA.
8. Additional notices to be affixed to the cover and title or first page of contractor generated COMSEC documents:
a. “COMSEC MATERIAL – ACCESS BY CONTRACTOR PERSONNEL RESTRICTED TO U.S. CITIZENS HOLDING FINAL
GOVERNMENT CLEARANCE.”
b. “THIS PUBLICATION OR INFORMATION IT CONTAINS MAY NOT BE RELEASED TO FOREIGN NATIONALS WITHOUT PRIOR SPECIFIC APPROVAL FROM THE DIRECTOR, NSA. ALL APPROVALS WILL IDENTIFY THE SPECIFIC INFORMATION AND COPIES OF THIS PUBLICATION AUTHORIZED FOR RELEASE TO SPECIFIC FOREIGN HOLDERS.
ALL REQUESTS FOR ADDITIONAL ISSUANCES MUST RECEIVE PRIOR SPECIFIC APPROVAL FROM THE DIRECTOR, NSA.”
ATTACHMENT B
http://www.nsa.gov/ia/government/mdg.cfm
INFORMATION SYSTEMS (IS)
PERSONNEL SECURITY PROGRAM REQUIREMENTS
The U.S. Government conducts trustworthiness investigations of personnel who require access to controlled unclassified information, those who perform IT position duties, and those requiring access to classified material.
Requirements for these investigations are outlined in Chapter 5, SECNAV M-5510.30. Falsification of information submitted for any government-conducted investigation may result in contract default. The contractor shall include all of these requirements in any subcontracts involving IT level support.
In order to provide the appropriate level of background investigation and suitability adjudication, positions are designated according to potential risk. Office of Management and Budget (OMB) provides the criteria for determining IT position risk levels, considering the level of automated privileges afforded, the level of fiscal privileges afforded, the scope of responsibilities, the level of independence and oversight afforded, and the ability to access sensitive information. The DON’s national security mission is a primary consideration in all DON IT position designations. There are three IT position levels:
IT-I - Privileged access. Favorably adjudicated Tier 5 (formerly SSBI) level investigation. Filled by U.S citizens only. Positions in which the incumbent is responsible for the planning, direction, and implementation of a computer security program; has a major responsibility for direction, planning, and design of a computer system, including the hardware and software; or can access a system during the operation or maintenance in such a way, and with relatively high risk for causing grave damage or realizing significant personal gain.
IT-II – Limited Privilege, sensitive information access. Favorably adjudicated Tier 3 (formerly NACLC or ANACI) level investigation. Filled by U.S. citizens only. Positions in which the incumbent is responsible for the direction, planning, design, operation or maintenance of a computer system, and whose work is technically reviewed by a higher authority to insure the integrity of the system.
IT-III – No Privilege, no sensitive information access. Favorably adjudicated Tier 1 (formerly NACI) (SF85) level investigation. This is anyone accessing Government systems. May be filled by non-U.S citizen, however, users will be strictly limited, have access only to that information to which they are specifically entitled, and will be limited to need-to-know
"THIS PORTION INTENTIONALLY LEFT BLANK"
File details come from the government source that posted it. Updated .