M67854-19-R-2000_Attachment_5_DD_254.pdf
PDF 548 KB Posted
- Attached to
- Next Generation Troposcatter Federal contract opportunity
- Solicitation number
- M67854-19-R-2000
- Issued by
- United States Marine Corps
About this file
This document contains a Department of Defense Contract Security Classification Specification (DD Form 254) for the Next Generation Troposcatter (NGT) program under solicitation number M67854-19-R-2000 issued by the United States Marine Corps. The contractor will perform vulnerability scans on the NGT system and generate a report outlining the scans, and will provide input to the Program Office to create a plan of action and milestones outlining the timeline for fixing and patching identified vulnerabilities. The contractor facility requires a secret security clearance level and level 2 safeguarding for classified information. The contractor must comply with DoD, Navy, and Marine Corps operations security requirements. The point of contact for the contract is listed as Lisa Woerner of the Marine Corps Systems Command, with a performance period to be determined at time of award.
Attachment 5
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| NGT_Draft_RFP_Q&A.pdf | ||
| M67854-19-R-2000_Attachment_3_-_SB_Part_&_Comm_Strat.docx | DOCX document | |
| M67854-19-R-2000_Attachment_1_-_PSPEC_Compliance_Matrix_Template.xlsx | XLSX spreadsheet | |
| M67854-19-R-2000_Attachment_2_-_SB_Subk_Record.docx | DOCX document | |
| M67854-19-R-2000_Attachment_4_-_PSPEC.PDF | ||
| M67854-19-R-2000_Exhibit_1_CDRLs.docx | DOCX document | |
| M67854-19-R-2000_NGT_Draft_RFP.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Please wait...
If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.
You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.
For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.
Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.
Continuation Sheet for DD Form 254 Contract Number M67854-19-R-2000
ADDITIONAL GUIDANCE:
(a) Security classification guides (SCGs) required during this contract will be listed, if applicable, in Block 13 of the attached DD-254. A copy of these orders will be provided to the contractor by MARCORSYSCOM’s Government Contracting Agency (GCA) under separate cover. Only the SCGs listed will be provided.
(b) In the event classified mail is required for program support, provide the tracking number to the CMCC Custodian. The CLASSIFIED mailing address is listed below.
Outer Envelope: Inner Envelope:
COMMANDER MCSC COMMANDER MCSC
ATTN CMCC ATTN CMCC POC NAME
2200 LESTER STREET 2200 LESTER STREET
QUANTICO VA 22134 QUANTICO VA 22134
(c) In addition to the reporting requirements directed by the DoD 5220.22-M (NISPOM), the contractor will provide a concurrent report of loss or compromise of classified information to the CMCC Custodian. The UNCLASSIFIED mailing address is listed below.
COMMANDER MCSC
ATTN CMCC CUSTODIAN
2200 LESTER STREET
QUANTICO VA 22134-6050
(d) Contractors will conduct a security review and comply with MARCORSYSCOMO 5720.2A, “PUBLIC RELEASE
REVIEW PROCESS” prior to entering government information on a home page (contractor or government web page site). A copy of this order will be provided to the contractor by MARCORSYSCOM’s Government Contracting Agency (GCA) under separate cover.
(e) IAW Defense Security Service Industrial Security Letter (ISL) 2006-01, the Joint Personnel Adjudication System (JPAS) is the “CSA-designated database” referenced in the NISPOM (para 2-200b.) All contractor personnel performing on this contract will be correctly listed in JPAS, and JPAS will be utilized for classified visit certifications and shall not exceed a 12 month period.
(f) All MARCORSYSCOM Badges and Common Access Cards (CACs) issued under this contract must be returned immediately to the MARCORSYSCOM AC/S G-2 (Personnel Security, Room 145) upon termination of contract, or individual terminations. When an individual contractor is terminated, for any reason, it is the responsibility of the Facility Security Officer (FSO) to immediately notify the AC/S G-2. Failure to comply could result in the suspension of all contractor badge and network accounts.
(g) All SIPRNET Tokens issued under this contract must be returned immediately to AC/S G-6 (Bldg 2201A) upon termination of contract, or individual terminations. Same rules apply as badges and CACs.
(h) If additional contracting requirements exist where retention of classified information by the contractor facility is required after the contract has ended, a written request to retain material will be forwarded to the GCA. If approved, a Final DD-254 will be issued for a period not to exceed 2 years.
(i) All work performed within MARCORSYSCOM sites/spaces, will follow SECNAV M-5510.30 (Personnel Security Program), SECNAV M-5510.36 (Information Security Program), MARCORSYSCOMO 5530.4 (Key and Lock Security and Access Control Order), and MARCORSYSCOMO P5510.2B Security Manual for all security guidance and instructions. A copy of these orders will be provided to the contractor by MARCORSYSCOM’s Government Contracting Agency (GCA) under separate cover.
(j) In addition to this DD-254, the contractor shall comply with the Federal Acquisition Regulation (FAR) clauses 52.204-2, “Security Requirements” and 52.204-21, “Basic Safeguarding of Covered Contractor Information Systems.”
Continuation Sheet for DD Form 254 Contract Number M67854-19-R-2000
ATTACHMENT A
INFORMATION SYSTEMS (IS)
PERSONNEL SECURITY PROGRAM REQUIREMENTS
The U.S. Government conducts trustworthiness investigations of personnel who require access to controlled unclassified information, those who perform IT position duties, and those requiring access to classified material.
Requirements for these investigations are outlined in Chapter 5, SECNAV M-5510.30. Falsification of information submitted for any government-conducted investigation may result in contract default. The contractor shall include all of these requirements in any subcontracts involving IT level support.
In order to provide the appropriate level of background investigation and suitability adjudication, positions are designated according to potential risk. Office of Management and Budget (OMB) provides the criteria for determining IT position risk levels, considering the level of automated privileges afforded, the level of fiscal privileges afforded, the scope of responsibilities, the level of independence and oversight afforded, and the ability to access sensitive information. The DON’s national security mission is a primary consideration in all DON IT position designations. There are three IT position levels:
IT-I - Privileged access. Favorably adjudicated Tier 5 (formerly SSBI) level investigation. Filled by U.S citizens only. Positions in which the incumbent is responsible for the planning, direction, and implementation of a computer security program; has a major responsibility for direction, planning, and design of a computer system, including the hardware and software; or can access a system during the operation or maintenance in such a way, and with relatively high risk for causing grave damage or realizing significant personal gain.
IT-II – Limited Privilege, sensitive information access. Favorably adjudicated Tier 3 (formerly NACLC or ANACI) level investigation. Filled by U.S. citizens only. Positions in which the incumbent is responsible for the direction, planning, design, operation or maintenance of a computer system, and whose work is technically reviewed by a higher authority to insure the integrity of the system.
IT-III – No Privilege, no sensitive information access. Favorably adjudicated Tier 1 (formerly NACI) (SF85) level investigation. This is anyone accessing Government systems. May be filled by non-U.S citizen, however, users will be strictly limited, have access only to that information to which they are specifically entitled, and will be limited to need-to-know
"THIS PORTION INTENTIONALLY LEFT BLANK"
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of AEM LiveCycle Designer
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List of Attachments [1] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form) M19-R-2000_CONT_SHEETS.pdf
| CurrentPage: |
| PageCount: |
| Classification: Unclassified |
| SerialNum: M19-R-2000 |
| a. Facility clearance level. Select one.: 2 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 2 |
| Choose Yes or No: 0 |
| Choose Yes or No: 1 |
| Prime: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 1 |
| Choose Yes or No: 0 |
| Soli: M67854-19-R-2000 |
| DueDate: 20190217 |
| dateA: 2018-09-25 |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 1 |
| No: 1 |
| No: 0 |
| No: 1 |
| Yes: 0 |
| Yes: 0 |
| Yes: 1 |
| Yes: 0 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: This DD-254 is for SOLICITATION purposes only. |
The COR must contact the Security Officer designated in Block 17 with a prime contractor name, CAGE Code and contract number as soon as possible to ensure a revised DD-254 is prepared and ready for contract award.
| Name: Forward a copy of all DD-254 SUB-CONTRACTS to the Security Officer designated in Block 17. |
| Name: DANA M. NEWTON |
| Cage: 7L030 |
| CSO: Defense Security Services |
Chantilly Field Office (IOFCC2) 13873 Park Center Road, Suite 225 Herndon, VA 20171
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: MARCORSYSCOM |
Quantico & Stafford Locations (678545) Location: MCTSSA Camp Pendleton, CA Location: The MITRE Corp 7515 Colshire Drive McLean, VA 22102
| Location: Additional locations TBD at time of award. |
| Block9: The contractor will be performing vulnerability scans on the Next Generation Troposcatter (NGT) System, and will have to generate a report outlining the scans. Additionally, they will provide input for the Program Office (PO) to create a POA&M outlining the time-line associated with fixing & patching said vulnerabilities. |
| a: 0 |
| a: 0 |
| a: 1 |
| f: 0 |
| f: 0 |
| f: 0 |
| b: 0 |
| b: 0 |
| b: 0 |
| g: 0 |
| g: 0 |
| c: 0 |
| c: 1 |
| c: 1 |
| h: 0 |
| h: 0 |
| d: 0 |
| d: 0 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 0 |
| NonSCI: 0 |
| j: 1 |
| j: 1 |
| k: 0 |
| k: 0 |
| Enter your name here.: INVESTIGATION REQUIREMENTS |
| e: 0 |
| e: 1 |
| l: 1 |
| m: 1 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: Commander, Marine Corps Systems Command (AC/S G-2) |
2200 Lester Street, Quantico, VA 22134-6050
| PublicAuthority: All requests must be approved by AC/S G-2, OPSEC, & Office of Public Affairs & Communication (OPAC): MCSCPEO@usmc.mil |
| AddSig: |
| RemoveSig: |
| text: |
The Security Classification Guides (SCG's) utilized for this effort are:
(U) Information Assurance (IA) Vulnerabilities and Weaknesses, dated 8 Jul 05 Headquarters U.S. CENTCOM Regulation Number 380-14, dated 15 Mar 14
10.j. The contractor shall comply with the requirements of the SECNAV M-5510.36 and DoD M5200.01, Volume 4 for guidance when access to Controlled Unclassified Information (CUI) is required in performance of this contract.
11c. Receive, store, and generate classified information or material. The contractor requires access to classified source data up to and including the classification levels identified in item 1.a. of this DD-254 in support of this work effort. In addition, the contractor’s facility will receive classified information and/or derivatively classify information. As identified in item 1.b. is the classification level of safeguarding (storage), receiving, generating, and/or fabricating of classified information approved at the contractor’s facility. If the contractor will be co-located in MARCORSYSCOM spaces during anytime within the full performance of this contract, they will comply with and be held accountable for the requirements of SECNAV M-5510.30, SECNAV M-5510.36, and any additional security requirements provided by MARCORSYSCOM’s Government Contracting Agency (GCA), the Industrial Security Office, and the CMCC Custodian. The contractor shall comply with the requirements of the Information Systems Security Programs as described in the DoD 5220.22-M, OPNAVINST 5239.1C, and local command information systems security instructions. All classified systems, regardless of the level of data processed, will be accredited in accordance with the above instructions. The contractor will reference the appropriate security classification guidance when generating or deriving classified material or hardware. Classified material received, generated, fabricated, or modified by this contract may be destroyed prior to the end of the contract with written Government approval. Prior to any destruction of classified material a full listing of documents will be provided to the MARCORSYSCOM’s GCA and the CMCC Custodian for review and approval. A destruction report shall be submitted listing what was destroyed and a listing of all remaining classified material. All (remaining) classified material must be returned within 30 days after completion of contract, or destroyed per the guidance above. All classified information will be physically sighted by the facility security officer (FSO), or designee, and will be forwarded to the CMCC Custodian by 31 December annually, and whenever there is a custodian turnover. The contractor will ensure all articles (including graphics) intended for public release or posting on Internet/World Wide Web sites will be processed through the Public Affairs Office as listed in Item 12.
11.l. Receive, Store, or Generate Controlled Unclassified Information (CUI). In addition to classified information, certain types of unclassified information also require distribution controls and protective measures for a variety of reasons. Refer to DoD M5200.01, Volume 4 for guidance with identification and protection of CUI.
11.m. Investigation requirements set forth by the U.S. Government are found in the SECNAV M-5510.30, Chapter 5. In order to provide the appropriate level of background investigation and suitability adjudication, positions are designated according to potential risk. Those risks are highlighted and explained in Attachment A.
"See Continuation Sheets" text: POINT OF CONTACT FOR THIS CONTRACT IS:
PHONE: (703) 432-9963
EMAIL: lisa.woerner@usmc.mil
| attachmentsList: |
| AddAttachment: |
| ViewAttachment: |
| RemoveAttachment: |
| rep: Ms. Lisa Woerner |
Project Officer, NGT
| Sig: |
| Enter your name here.: 11j. OPSEC Requirements. While performing aboard NAVY/USMC sites, the contractor shall comply with the provisions of DoD Directive 5205.02E, "DoD Operations Security (OPSEC) Program," SECNAV 3070.2, Marine Corps Order 3070.2A and the MARCORSYSCOMO P5510.2B Security Manual, at all other sites the contractor shall comply with the local command and/or program OPSEC plan. |
| GCAName: Next Generation Troposcatter (NGT) |
| AAC: M67854 |
| AAC: M67854 |
| Address: MARCORSYSCOM |
2200 LESTER STREET
QUANTICO VA 22134-6050
Address: MARCORSYSCOM
2200 LESTER STREET
QUANTICO VA 22134-6050
| POCName: Mr. Steven Batts |
| Phone: 7034329868 |
| Phone: 7034324140 |
| Email: steven.batts@usmc.mil |
| Email: dana.newton@usmc.mil |
| Title: INDUSTRIAL SECURITY SPECIALIST |
| Enter the date using the format DD-Mon-YYYY: 20180925 |
File details come from the government source that posted it. Updated .