OPERATIONS_SECURITY_REQUIREMENTS_JUNE_2009.pdf
PDF 26 KB Posted
- Attached to
- GCCS-TCO/JTCW T&E Contractor Service Support Federal contract opportunity
- Solicitation number
- M6890916Q7600
- Issued by
- United States Marine Corps
About this file
Operations Security Requirements
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 16-Q-7600_Amendment_0002.pdf | ||
| Q As-GCCS-TCO-JTCW_T E_v1.pdf | ||
| GCCS_TCO_JTCW_PWS_30_Nov_2015_-_Final_v1.pdf | ||
| GCCS-TCO-JTCW_T E_Past_Performance_Questionnaire.doc | DOC document | |
| RFQ_16-Q-7600-0001.pdf | ||
| DOL_WD_05-2057_(Rev.-17)_dtd_11172015.pdf | ||
| GCCS-TCO-JTCW_T E_Past_Performance_Questionnaire.doc | DOC document | |
| Format_for_Q A_-_GCCS-TCO-JTCW_T E.xls | XLS spreadsheet | |
| GCCS_TCO_JTCW_PWS_7_Oct_2015_-_Final.pdf | ||
| RFQ_Main_16-Q-7600.pdf | ||
| Draft_DD254_GCCS-TCO-JTCW_T E.pdf | ||
| FOUO_Information.pdf | ||
| GCCS-TCO__JTCW_QASP_7_Oct_2015_-_Final.pdf | ||
| Specific_OnSite_Security_Requirements_MASTER_doc_Apr_2010.pdf | ||
| RFQ_Cover_16-Q-7600.pdf |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FOR OFFICIAL USE ONLY (FOUO)
OPERATIONS SECURITY REQUIREMENTS
All work is to be performed in accordance with DoD and Navy Operations Security (OPSEC) requirements, per the following applicable documents:
- National Security Decision Directive 298
- National Operations Security Program (NSDD) 298
- DoD 5205.02
- DoD Operations Security (OPSEC) Program
- OPNAVINST 3432.1
- DON Operations Security
- MCTSSA Operations Security Policy
The contractor will accomplish the following minimum requirements in support of Marine Corps Tactical Systems Support Activity (MCTSSA) Operations Security (OPSEC) Program:
- The contractor will practice OPSEC and implement OPSEC countermeasures to protect DOD Critical Information. Items of Critical Information are those facts, which individually, or in the aggregate, reveal sensitive details about MCTSSA or the contractor’s security or operations related to the support or performance of this SOW, and thus require a level of protection from adversarial collection or exploitation not normally afforded to unclassified information.
- Contractor must protect Critical Information and other sensitive unclassified information and activities, especially those activities or information which could compromise classified information or operations, or degrade the planning and execution of military operations performed or supported by the contractor in support of the mission. Protection of Critical Information will include the adherence to and execution of countermeasures which the contractor is notified by or provided by MCTSSA for Critical Information on or related to the
SOW.
- Sensitive unclassified information is that information marked FOR OFFICIAL USE ONLY (or FOUO), Privacy Act of 1974, COMPANY PROPRIETARY, and also information as identified by MCTSSA or the MCTSSA COR.
MCTSSA has identified the following items as Critical Information that may be related to this SOW:
Known or probable vulnerabilities to any U.S. system and their direct support systems.
Details of capabilities or limitations of any U.S. system that reveal or could reveal known or probable vulnerabilities of any U.S. system and their direct support systems.
Details of information about military operations (numbers of systems deployed, deployment timelines, locations, effectiveness, unique capabilities, etc.)
Operational characteristics for new or modified weapon systems (Probability of Kill (Pk), Countermeasures, Survivability, etc.).
Required performance characteristics of U.S. systems using leading edge or greater technology (new, modified or existing).
Telemeter or data-linked data or information from which operational characteristics can be inferred or derived.
Test or evaluation information pertaining to schedules of events during which Critical Information might be captured (advances greater than days).
Details of MCTSSA unique Test or Evaluation capabilities (disclosure of unique capabilities).
Existence and/or details of intrusions into or attacks against DoD Networks or Information
Systems, including, but not limited to, tactics, techniques and procedures used, network vulnerabilities exploited, and data targeted for exploitation.
Network User ID’s and Passwords.
Counter-IED capabilities and characteristics, including success or failure rates, damage assessments, advancements to existing or new capabilities.
Vulnerabilities in Command processes, disclosure of which could allow someone to circumvent security, financial, personnel safety, or operations procedures.
Force Protection specific capabilities or response protocols (timelines/equipment/numbers of personnel/training received/etc).
Command leadership and VIP agendas, reservations, plans/routes etc.
Detailed facility maps or installation overhead photography (photo with annotation of Command areas or greater resolution than commercially available).
Details of MCTSSA emergency evacuation procedures, or emergency recall procedures.
Government personnel information that would reveal force structure and readiness (such as recall rosters or deployments lists).
Compilations of information that directly disclose Command Critical Information.
The above Critical Information and any that the contractor develops, regardless if in electronic or hardcopy form, must be protected by a minimum of the following countermeasures:
All emails containing Critical Information MUST BE DOD Public Key Infrastructure (PKI) signed and PKI encrypted when sent.
Critical Information may not be sent via unclassified fax.
Critical Information may not be discussed via non-secure phones.
Critical Information may not be provided to individuals that do not have a need to know in order to complete their assigned duties.
Critical Information may not be disposed of in recycles bins or trash containers.
Critical Information may not be left unattended in uncontrolled areas.
Critical Information in general should be treated with the same care as FOUO or proprietary information.
Critical Information must be destroyed in the same manner as FOUO.
Critical Information must be destroyed at contract termination or returned to the government at the government’s discretion.
The contractor shall document items of Critical Information that are applicable to contractor operations involving information on or related to the SOW. Such determinations of Critical Information will be completed using the DoD OPSEC 5 step process as described in the National Security Decision Directive (NSDD) 298, “National Operations Security Program”.
OPSEC training must be included as part of the contractor’s ongoing security awareness program conducted in accordance with Chapter 3, Section 1, of the NISPOM. NSDD 298, DoD 5205.02, “DoD Operations Security (OPSEC) Program”, and OPNAVINST 3432.1, “Operations Security” should be used to assist in creation or management of training curriculum.
If the contractor cannot resolve an issue concerning OPSEC, they will contact the MCTSSA COR, who will consult with the MCTSSA OPSEC Manager.
All above requirement must be passed to all Sub-contractors.
File details come from the government source that posted it. Updated .