About this file

This document is a Department of Defense Contract Security Classification Specification (DD Form 254) outlining classified information access requirements for a solicitation seeking Administrative and Operational Contractor Support Services. The solicitation number is N0001922R0036 and will be issued in Q1 FY2022 by the F-35 Joint Program Office to provide program management support to various directorates and integrated product teams. Contractors will require access to Secret and NATO information, and will execute processes involving personnel security and security guidance. Additional security requirements are identified in contract clauses. The Cognizant Security Office is the F-35 JPO, and the public release authority is the Public Affairs Officer. Inspections of classified information will be conducted by the relevant Special Access Program executive offices.

This document also includes addendums detailing specific handling requirements for UK Restricted, Australian Protected, and Norwegian Restricted information. Contractors will be required to follow storage, transmission, marking, destruction, and information technology security protocols according to the addendums.

View the file

Other files for this federal contract opportunity

Other files attached to Solicitation: Administrative and Operational Contractor Support Services (CSS) Support Knowledge Based Services (KBS), newest first.
File Type Posted
N0001922R0036 A003.docx.pdf PDF
Att_2_LCATs_and_Minimum_Quals A003.pdf PDF
AdminOps QAs 20211110.pdf PDF
Attachment_P1_Level_of_Effort 11102021.xlsx XLSX spreadsheet
N0001922R0036 A002 conformed.pdf PDF
Att P2_Past Performance Info (PPI) Form A002.pdf PDF
Attachment_P1_Level_of_Effort A002.xlsx XLSX spreadsheet
Admin KBS_Exhibit A002 - Transition In Plan 09132021.pdf PDF
Admin KBS_Exhibit A001 - In-Progress Review 09132021.pdf PDF
Admin KBS_Exhibit A001 - OPSEC Plan 09132021.pdf PDF
N0001922R0036 A002.pdf PDF
Admin KBS_Exhibit B001 - Monthly Expenditure Report 09132021.pdf PDF
Admin KBS_Exhibit_A001 - Program Management and Staffing Plan 09132021.pdf PDF
Admin KBS_Exhibit B001 - 45 Day Report 09132021.pdf PDF
Admin KBS_Exhibit A003 - Monthly Status Report 09132021.pdf PDF
Admin KBS_Exhibit C001 - Trip Report 09132021.pdf PDF
Admin KBS_Exhibit A003 - Hiring Status Report 09132021.pdf PDF
Admin KBS_Exhibit A002 - Quality Control Plan 09132021.pdf PDF
Admin KBS_Exhibit A004 - PNR 09132021.pdf PDF
Admin KBS_Exhibit A003 - Level of Effort 09132021.pdf PDF
Admin KBS_Exhibit A002 - Transition Out Plan 09132021.pdf PDF
N0001921R003600001.pdf PDF
Admin_Ops QAs Amendment 1.pdf PDF
Att_3_SAC.pdf PDF
Att_P2_Past_Performance_Matrix.doc.pdf PDF
Att_5_Travel Authorization Form.pdf PDF
Att_9_JPO_CUI_Information_Policy_May_2021.pdf PDF
Att_P4_Past Performance Questionnaire.pdf PDF
N0001922R0036_Admin_KBS_RFP 20211026.pdf PDF
Att_2_LCATS_and_Min_Quals.pdf PDF
Att_6_JPO_Visitor_Group_Security_Agreement.pdf PDF
Att_7_JPO_In-Processing Data Sheet.pdf PDF
Att_P1_Level_of_Effort 09092021.xlsx XLSX spreadsheet
Att_P5_Cost_Summary_Sheet_20211021.xls XLS spreadsheet
Att_P3_Subcontractor Teaming Partner Consent Form.pdf PDF
Att_1_DoD_Security_Regulations.pdf PDF
Att_8_Contractor_Employee_NDA.pdf PDF
Att_P6_Question_Submittal_Form.xlsx XLSX spreadsheet
Show all 38

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Please wait...

If this message is not eventually replaced by the proper contents of the document, your PDF viewer may not be able to display this type of document.

You can upgrade to the latest version of Adobe Reader for Windows®, Mac, or Linux® by visiting http://www.adobe.com/go/reader_download.

For more assistance with Adobe Reader visit http://www.adobe.com/go/acrreader.

Windows is either a registered trademark or a trademark of Microsoft Corporation in the United States and/or other countries. Mac is a trademark of Apple Inc., registered in the United States and other countries. Linux is the registered trademark of Linus Torvalds in the U.S. and other countries.

ADDENDUM 1 (REVISION 3)

POLICY GOVERNING RELEASE OF INTELLIGENCE TO CONTRACTORS

FOR OFFICIAL USE ONLY//REL TO USA

Addendum 2 (Revision 2)

UNITED KINGDOM

RESTRICTED CONDITIONS REQUIREMENTS CLAUSE

On January 27, 2003 the United States Department of Defense (DoD) and the United Kingdom (UK) Ministry of

Defence (MoD) signed a document known as the “Security Implementing Arrangement” that removed U.S.

Government oversight responsibility for protection of information marked UK RESTRICTED provided to U.S.

contractors. The UK Government implemented these changes effective April 1, 2003 with further clarification in a letter to the F-35 Lightning II Program Office dated 4 Dec 2009.

On April 1, 2014 the UK Government introduced revised security Protective Markings (PM). The PM UK

RESTRICTED has been replaced with UK OFFICIAL – SENSITIVE. This change is not retrospective so documents marked as UK RESTRICTED will remain in circulation for some time to come. The guidance below has been updated to reflect the changes to the UK PM schema.

In conjunction with this arrangement the following handling procedures apply to UK Restricted data and UK

Official – Sensitive data within the F-35 program areas.

1.0 PROTECTION

UK documents or material bearing the classification “UK OFFICIAL – SENSITIVE” or “UK RESTRICTED” shall be handled in the United States as U.S. UNCLASSIFIED information that is exempt from public release under one or more U.S. laws (similar to U.S. FOR OFFICIAL USE ONLY information). These laws include the Freedom of

Information Act (FOIA) and Title 10 U.S.C. Section 130(c), “Nondisclosure of Information: Certain Sensitive

Information of Foreign Governments and International Organizations.”

Also similar to US Government FOUO or US Contractor proprietary, neither a personnel nor facility security clearance is required for access to UK OFFICIAL – SENSITIVE or UK RESTRICTED information. However, the information must be confined to those members of the F-35 program whose access to the information is essential for the purpose of their duties. Except with the consent in writing of the UK MOD, F-35 personnel shall not make use of the UK OFFICIAL – SENSITIVE or UK RESTRICTED information issued or furnished by or on behalf of the

UK MOD otherwise than for the purpose of the F-35 contract.

An export license for UK OFFICIAL – SENSITIVE or UK RESTRICTED information should be processed as any other unclassified information would be processed. The information subject to export will not have to pass through government-to-government channels.

Contracts placed with U.S. contractors that involve the retention or production of UK OFFICIAL – SENSITIVE or

UK RESTRICTED information will include this Restricted Conditions Requirements Clause identifying the security protective measures to be applied to safeguard the information. This Restricted Conditions Requirements Clause will be included in any new revisions to the current F-35 DD254s in place for contractors requiring access to UK

OFFICIAL – SENSITIVE or UK RESTRICTED data.

2.0 STORAGE

During working hours, reasonable steps must be taken to minimize the risk of access to UK OFFICIAL –

SENSITIVE or UK RESTRICTED information by unauthorized personnel. After working hours, UK OFFICIAL –

SENSITIVE and UK RESTRICTED information will be locked in an office, overhead bins, desk or cabinet to preclude unauthorized access.

UNCLASSIFIED//REL TO USA AND UK MOD

3.0 TRANSMISSION

UK OFFICIAL – SENSITIVE and UK RESTRICTED documents may be single wrapped and transmitted by First

Class Mail within the United States. Transmission outside the United States must be double wrapped with the inner envelope marked “UK OFFICIAL – SENSITIVE” or “UK RESTRICTED” as appropriate. International transfers shall be by one of the means authorized for U.S. classified information, by international airmail, or by express commercial courier services. Government-to-government transmission procedures are not required.

UK OFFICIAL – SENSITIVE and UK RESTRICTED information may only be transmitted or accessed electronically via a public network like the Internet when using government or commercial encryption devices which must meet U.S. FIPS 140-2 encryption standards at a minimum. If any additional/differing requirement

(outside of FIPS140-2 approved devices) is identified, F-35 Joint Program Office (JPO) Security must be contacted.

4.0 MARKING

All F-35 unclassified documents containing UK OFFICIAL – SENSITIVE or UK RESTRICTED information shall have “UK OFFICIAL – SENSITIVE” or” UK RESTRICTED”, as appropriate, - Exempt from Public Disclosure under Title 10 U.S.C. Section 130(c)” typed, stamped or printed in capital letters centered at the bottom on the outside of the front cover (if any), on each page containing UK OFFICIAL – SENSITIVE or UK RESTRICTED information and on the outside of the back cover (if any). In addition, the UK OFFICIAL – SENSITIVE or UK

RESTRICTED information shall be identified in the documents as well. This can be accomplished with the portion marking “(UK O-S)” or “(UK-R)” on the applicable paragraphs and/or charts/pictures/graphs. Other records, such as diskettes, photographs, films, cassette tapes, movies and slides, shall be marked “UK OFFICIAL – SENSITIVE” or “UK RESTRICTED”, as appropriate,- Exempt from Public Disclosure under Title 10 U.S.C. Section 130(c)” as well.

(Note: Any UK OFFICIAL – SENSITIVE or UK RESTRICTED material received or generated prior to Revision 2 to this Addendum does not have to be remarked until it is being used, reproduced or transmitted.

5.0 DESTRUCTION

Where available the use of shredders, burn barrels, burn bags or other protected destruction methods should be used to destroy UK OFFICIAL – SENSITIVE or UK RESTRICTED information. DO NOT place any UK OFFICIAL –

SENSITIVE or UK RESTRICTED information in the trash.

6.0 USE OF IT SYSTEMS

The following accreditation requirements describe the general security requirements for processing and accessing

UK OFFICIAL – SENSITIVE or UK RESTRICTED information on IT systems. For specific guidance addressing

UK OFFICIAL – SENSITIVE or UK RESTRICTED information to be managed by Signal Interface Management

Systems (SIMS), Dimensions, Livelink or in a collaborative working environment refer to Enclosure (1) of this

Addendum.

(1) Control of physical access to all hardware elements of the IT system.

(2) Identification and authentication (ID&A). All systems should have the following functionality:

(a) Up-to-date lists of authorized users

(b) Positive identification of all users at the start of each processing session

(c) An agreed means of transmitting the UK OFFICIAL – SENSITIVE or UK RESTRICTED data as described in Section 3.0 above

(3) Passwords are part of most ID&A security measures. Passwords should be nine characters long and should include numeric and “special” characters (if permitted by the system) as well as alphabetic characters. Note:

Lockheed Martin will configure passwords for privileged and non-privileged accounts in accordance with Lockheed

Martin policy.

(4) Internal Access Control – All systems should have internal access controls to prevent unauthorized users from accessing or modifying the data.

(5) Security accounting and audit – Security relevant events fall into two categories, namely legitimate events and violations.

(a) The following events should always be recorded:

i. All log on attempts whether successful or failed.

ii. Log off (including time out where applicable).

iii. The creation, deletion or alternation of access rights and privileges.

iv. The creation, deletion or alteration of passwords

(b) For each of the events listed above, the following information is to be recorded:

i. Type of event

ii. User ID

iii. Date and Time

iv. Device ID

The accounting records should have a facility to provide the System Manager with a hard copy of all or selected activity. There should also be a facility for the records to be printed in an easily readable form. All security records are to be inaccessible to users without a need to know.

If the operating system is unable to provide this then the equipment should be protected by physical means when not in use (i.e., locked away or the hard drive removed and locked away).

(6) Integrity & Availability – The following supporting measures should be implemented:

(a) Provide general protection against normally foreseeable accidents/mishaps and known recurrent problems

(e.g., viruses and power supply variations)

(b) Defined Business Contingency Plan

(c) Data backup with local storage

(d) Anti Virus Software (Implementation, with updates, of an acceptable industry standard Anti-virus software.)

(7) Logon Banners – Wherever possible, a logon banner should be provided to summarize the requirements for access to a system which may be needed to institute legal action in case of any breach occurring.

(8) Unattended Terminals – Users are to be automatically logged off the system if their terminals have been inactive for some predetermined period of time, to prevent an attacker making use of an unattended terminal.

(9) Computer systems should not be connected direct to the Internet unless protected by a firewall.

(10) Before IT storage media (e.g. disks) are disposed an erasure product should be used to overwrite the data. This is a more thorough process than deletion of files which does not remove the data.

7.0 INTERPRETATION

Advice regarding the interpretation of the above requirements or waivers to the requirements must be sought from the UK MOD.

Addendum 3 (Revision 2)

AUSTRALIAN

PROTECTED HANDLING REQUIREMENTS CLAUSE AND CLEARANCES REQUIRED FOR ACCESS TO

AUSTRALIAN SPECIAL ACCESS PROGRAM FACILITIES

1.0 PROTECTION OF “PROTECTED INFORMATION”

PROTECTED is the lowest level of Australian security classification for which a security clearance is required for access. AUSTRALIAN PROTECTED information must be confined to those members of the F-35 program whose access to the information is essential for the purpose of their duties. Except with the consent in writing of the AUSTRALIAN DOD, F-35 personnel shall not make use of the AUSTRALIAN PROTECTED information issued or furnished by or on behalf of the AUSTRALIAN DOD otherwise than for the purpose of the F-35 contract.

An export license for AUSTRALIAN PROTECTED information should be processed as any other unclassified information would be processed.

Contracts placed with U.S. contractors that involve the retention or production of AUSTRALIAN PROTECTED information will include this PROTECTED Handling Requirements Clause identifying the security PROTECTED measures to be applied to safeguard the information. This PROTECTED Handling Requirements Clause will be included in any new revisions to the current F-35 DD254s in place for contractors requiring access to AUSTRALIAN PROTECTED data.

2.0 STORAGE

During working hours, reasonable steps must be taken to eliminate the risk of access to AUSTRALIAN PROTECTED information by unauthorized personnel. After working hours, AUSTRALIAN PROTECTED information will be locked in an office, overhead bins, desk or cabinet to preclude unauthorized access.

3.0 TRANSMISSION

AUSTRALIAN PROTECTED material must be protected in the United States of America as if it were CONFIDENTIAL material. Should the United States of America transmit CONFIDENTIAL material, Australia shall mark it as

CONFIDENTIAL.

AUSTRALIAN PROTECTED documents may be single wrapped and transmitted by First Class Mail within the United States. Transmission outside the United States must ONLY be by government to government channels, double wrapped with the inner envelope marked “AUSTRALIAN PROTECTED.”

AUSTRALIAN PROTECTED information may only be transmitted or accessed electronically via an accredited US DoD classified network. Transmission via a public network would require the approval of the AUSTRALIAN DOD Defense Security Authority. Contact F-35 Joint Program Office (JPO) Security if this requirement is identified.

AUSTRALIAN PROTECTED information is not to be transmitted by telephone, video conferencing or facsimile transmissions within the United States.

4.0 MARKING

All F-35 unclassified documents containing AUSTRALIAN PROTECTED information shall have “AUSTRALIAN PROTECTED” typed, stamped or printed in capital letters centered at the bottom on the outside of the front cover (if any), on each page containing AUSTRALIAN PROTECTED information and on the outside of the back cover (if any).

Other records, such as diskettes, photographs, films, cassette tapes, movies and slides, shall be marked

“AUSTRALIAN PROTECTED.”

5.0 DESTRUCTION

Shredders, burn barrels, burn bags or other protected destruction methods are to be used to destroy AUSTRALIAN PROTECTED information. DO NOT place any AUSTRALIAN PROTECTED information in the trash.

6.0 CLEARANCES REQUIRED FOR ACCESS TO AUSTRALIAN SPECIAL ACCESS PROGRAM FACILITIES

(SAPF)

Contractors primarily working in Special Access Program Facilities (SAPF) in Australia and having access to Secret//Special Access Required information must have a U.S. Top Secret (TS) clearance or Australian Government Negative Vetting 2 (NV2).

FOR OFFICIAL USE ONLY //REL TO USA AND AUS

Addendum 4

NORWEGIAN

RESTRICTED HANDLING REQUIREMENTS CLAUSE

In accordance with the security procedures for Industrial Operations between the Ministry of Defense of Norway and The Department of Defense of the United States (Industrial Security Annex), paragraph 2.g, Footnote 3; the handling of Norwegian Restricted Data should be as follows:

Norwegian documents or material bearing the classification “BEGRENSET” shall not be marked with any US security classification marking but shall be marked or stamped in English, “RESTRICTED.” In addition, the following notation shall be entered: “To be safeguarded in accordance with Department of Defense Industrial

Security manual (DoDISM), DoD 5220.22-M, or “Department of Defense Information Security Program

Regulation, DoD 5200.1-R, as appropriate.” Documents or material so marked shall be stored in locked filing cabinets, desks, or similar closed spaces or areas that will prevent access by unauthorized personnel.

Documents or material on hand and marked “To be treated as CONFIDENTIAL” or “Modified Handling

Authorized” will have these US markings obliterated or excised as they are withdrawn for use. They shall be remarked and safeguarded as in 1, above.

Norwegian RESTRICTED documents shall be handled in a manner that will preclude open publication, access or use for other than the official Government purposes of the United States or the releasing country.

Documents and materials containing Norwegian RESTRICTED information shall be released only to contractors and individuals that have been cleared to the level of CONFIDENTIAL by the US Government.

Both facilities and individuals must also have a need for the information in the course of official business.

Norwegian RESTRICTED documents shall be transmitted in two secure covers, the inner cover marked

“RESTRICTED.” Transmission outside the United States shall be by one of the means authorized for United

States classified information.

Unclassified US documents originated by a US Government agency which contain information that Norway has classified “BEGRENSET” shall bear on the cover and the first page the marking “RESTRICTED.” In addition, the following notation shall be entered: “To be safeguarded in accordance with Department of

Defense Industrial Security Manual (DoDISM), DoD 5220.22-M, as appropriate.” The Norwegian

RESTRICTED information shall be identified in the documents.

Norwegian RESTRICTED information transmitted electronically shall be encrypted.

UNCLASSIFIED//REL TO USA AND NOR MOD

DRAFT

SAMPLE

PREVIOUS EDITION IS OBSOLETE.

Page of AEM LiveCycle Designer

DD FORM 254, APR 2018

NEEDS DD67

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

b. REVISED (Supersedes all previous specifications.)

4. IS THIS A FOLLOW-ON CONTRACT?

If yes, complete the following:

Classified material received or generated under

5. IS THIS A FINAL DD FORM 254?

If yes, complete the following:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

e. NATIONAL INTELLIGENCE INFORMATION:

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List of Attachments [2] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form) DD254 ADDENDUMS_updated 2018.pdf 2019 DD254 STILO Memorandum 15MAY2019.pdf

CurrentPage:
PageCount:
Classification: Controlled Unclassified Information (CUI)
SerialNum: N00019-21-R-0036
a. Facility clearance level. Select one.: 1
b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4
Choose Yes or No: 0
Choose Yes or No: 1
Prime:
Choose Yes or No: 0
Choose Yes or No: 0
Sub:
Choose Yes or No: 1
Choose Yes or No: 0
Soli: N00019-21-R-0036
DueDate: 20220122
dateA: 2021-08-05
RevisionNum:
dateB:
Final:
dateC:
No: 1
No: 1
No: 0
No: 0
Yes: 0
Yes: 0
Yes: 1
Yes: 1
Enter your name here.:
ReqDated:
Enter your name here.:
Name: TBD
Name: N/A
Name: Rhodes, John
Cage: TBD
Cage: N/A
Cage: 81755
Cage: N/A
Cage: N/A
Cage: N/A
CSO: TBD
CSO: N/A
CSO: Defense Counterintelligence Security Agency

2250 West John Carpenter Freeway, Suite 450 Irving, TX 75063 Phone: (469) 329-6367

CSO: N/A
CSO: N/A
CSO: N/A
addrow:
Removerow:
Click to delete a row:
Location:

Lockheed Martin Aeronautics Company - Fort Worth 1 Lockheed Boulevard Fort Worth, TX 76108 Location: Wright Patterson Air Force Base 5160 Pearson Road Wright Patterson AFB, OH 45433 Location: F-35 Joint Strike Fighter Office 200 12th Street Arlington, VA 22202 Location: F-35 Joint Strike Fighter Office 2725 South Clark Street Arlington, VA 22202 Block9:

FOR SOLICITATION PURPOSES ONLY!

The purpose of this contract is to provide the F-35 Joint Program Office (JPO) with Administrative and Operational Contractor Support Services (CSS) in support of the Follow-on Development (FoD), the Low Rate Initial and Full Rate Production (LRIP/FRP), as well as the sustainment efforts for the F-35 Program.

Period of Performance Dates: TBD

COR/PM: Jeremy Hodgkin - (703) 568-0978, jeremy.hodgkin@jsf.mil CS: Justen Brown - justen.brown@jsf.mil TPOC: Brigid O'Hearn - brigid.ohearn@jsf.mil

a: 1
a: 1
a: 1
f: 1
f: 0
f: 1
b: 0
b: 0
b: 0
g: 1
g: 0
c: 0
c: 0
c: 1
h: 1
h: 0
d: 1
d: 0
d: 0
i: 0
i: 0
SCI: 1
NonSCI: 1
j: 1
j: 1
k: 1
k: 0
Enter your name here.: SIPRNET Required
Enter your name here.: Execute PPDP and PPP
e: 1
e: 1
l: 1
m: 1
direct: 0
thru: 1
Enter your name here.: F-35 Joint Program Office (JPO)

200 12th Street, Suite 600, Arlington, VA 22202 PublicAuthority: Public Affairs Officer Continuation (See Section 13)

AddSig:
RemoveSig:
text: FOR SOLICITATION ONLY!

Collateral classified information will be protected using the policies and guidelines established in 32 Code of Regulations, Part 117, National Industrial Security Program Operating Manual, 24 February 2021 and JSF Collateral SCG dated 11/10/05 (and subsequent revisions).

Item 8a: Contractor is authorized to have access to Collateral and SAP information at approved and identified locations in block 8a.

Item 10a: Contractor is authorized to have access to classified COMSEC information up to Secret. Contract must have a final US Government clearance at the appropriate level. Further disclosure of COMSEC information by a contractor, to include sub-contracting, requires prior approval of the GCA. Non-accountable COMSEC information, though not tracked in the COMSEC material control system may still require a level of control within a document control system. Refer to NSA/CSS Manual 3-16, "Control of Communications Security Material," and the Committee on National Security Systems Instruction (CNSSI) 4001, "Controlled Cryptographic Items" for guidance.

Item 10d: Formerly Restricted Data will be handled and controlled as indicated in the NISPOM. Secret classified information will be protected using the policy and guidelines established in the NISPOM (DoD 5220-22.M) dated February 2006 (and subsequent revisions). the JSF collateral security classification guide (SCG) dated 11/10/05 (and subsequent revisions) will be used. Classified material generated in the performance of this contract will require that the contractor apply derivative security classification and markings consistent with the source material and/or SCG.

Item 10e(1): SCI billets will be obtained as required. Requests for SCI billets will be sent to the NAVAIR SSO (Patuxent River). The attached Scientific and Technical Intelligence Liaison Officer (STILO) Memorandum dated 15 May 2019 must be followed for access to SCI in the performance of their contract.

Item 10e(2): Non-SCI Intelligence Information is not releasable to contractor employees who have not received a Clearance at the appropriate security level. Written concurrence of the Contracting Officer's Security Representative (COSR) is required prior to subcontracting. Access to Intelligence information required for performance. Contractor shall comply with Naval Air Warfare Center Aircraft Division Scientific and Technical Intelligence Liaison Officer Memorandum dated 15 May 2019 (see Addendum 1).

Item 10f: Contractor is authorized to have access to SAP information at approved and identified locations in block 8a for all programs listed in the DD FM 254 Classified Addendum (JSF SAP 2021-25) and each of these programs must be in its own dedicated space unless shared use and periods processing is approved by the OSI PJ PSO, in accordance with the policy and guidelines established in the Air Force Instructions (AFI) 16-701 and the SAF/AAZ Implementing Memorandum dated 4 April 2016, the DoD Manual 5205.07, Volumes 1-4 are the authoritative SAP Security Policy documents:

- Risk Management Framework (RMF), dated 18 Dec 2013

- Joint Special Access Program Implementation Guide (JSIG) Rev 4, dated 11 Apr 2016

- DoD Standards and Reciprocity for Sanitization of SAP Information Technology Devices, dated 20 Apr 20

The Security Classification Guides (SCGs) for each of these programs will be forwarded under separate cover due to their level of classification.

Item 10g: Use of NATO information is authorized and special briefings are required for access to NATO. See NISPOM Chapter 10, Section 7, for details. Disclosure to foreign nationals will be in accordance with established ITAR and J-35 JPO Policy and Procedures.

Item 10h: Foreign disclosure of JSF program information will be in accordance with established ITAR and JSF program policy and procedures. Handling, processing and storage of United Kingdom Restricted Data will be in accordance with the procedures outlined in Addendum 2 of this DD254. Handling, processing and storage of Australian Protected Data will be in accordance with the procedures outlined in Addendum 3 of this DD 254. Handling, processing and storage of Norwegian Restricted Data will be in accordance with the procedures outlined in Addendum 4 of this DD254. Note: All national/sovereign information will be handled IAW the appropriate US and sovereign regulations to include Special Security Agreements and Industrial Security Agreements.

Item 10j and 11l: CUI will be handled in accordance with guidance provided in the DoDI 5200.48 and guidance provided in the JSF Collateral SCG dated 11/10/05 (and subsequent revisions).

Item 10k: Secret Internet Protocol Network (SIPRNET) access required at government locations. Prior to access, contractor personnel are required to have final Secret U.S. Government Security Clearance.

Item 11a: Access to SAP information is limited to the sites identified in Item 8a above. All SAP classified information will be protected using the policies and guidelines established in the AIR FORCE INSTRUCTION (AFI) 16-701 (LATEST ISSUE) and DoDM 5205.07 Volume 1-4. In addition to the SAP guidance listed in Item 10f above, the JSF Collateral SCG dated 11/10/05 (and subsequent revisions) will be used. Any subcontractor DD254s authorizing access to SAP must be sent through the JSFPO in Arlington, VA and through the PSO for review and concurrence prior to issuance is required.

Item 11e: The contractor will provide support services to the F-35 program such as: administrative management, facility and infrastructure management, travel management, and human resource management.

Item 11j: OPSEC applies to the CUI, Collateral, Special Access, and SCI portions of this contract and will be conducted in accordance with Air Force Instructions (AFI) 16-701 and DoDM 5205.07 Volume 1-4 and as described in the Special Access Program's SCG. Specifically, an OPSEC orientation must be provided to newly assigned personnel in concert with the Special Access Program indoctrination. OPSEC will also be covered in annual refresher training. Areas to be briefed include vulnerabilities to program information and compensatory measures used, significance of unclassified data, appropriate actions/respones to requests for information and any lessons learned. Emphasis should center on security as integral element of day-to-day activities.

Item 11m:

1. F-35 JPO Program Protection Planning will be executed in accordance with the F-35 JPO Program Protection Development Plan (PPDP) dated November 2008 and any subsequent revisions. Both the PPP and PPDP apply to both Industrial Security and System Security Engineering.

2. Foreign disclosure of program information will be in accordance with established ITAR and F-35 JPO program policy and procedures. Disclosure/release of U.S. government developed/generated information to foreign subcontractors must have the prior approval of the F-35 JPO Security Directorate.

3. The contractor will staff DD Form 254s issued to subcontractors requiring access to SAP information to the F-35 JPO Security Directorate for concurrence prior to subcontracting.

Item 12: Public Release Authority

Public release of data related to classified information is NOT authorized without prior coordination through the F-35 JPO Security Directorate; submit requests to the Government Program Manager (GPM) and the F-35 JPO Security Directorate via email: pa@jsf.mil. Consult the "release of program information" section of the classified SCG protecting the classified information you would like released. Submit all requests for review a minimum of 60 days before the date needed.

text:

10f SAP Approval text:

10e(1) SCI Approval

attachmentsList:
AddAttachment:
ViewAttachment:
RemoveAttachment:
rep: Aaron Garcia

F-35 Program Security Officer, PSO rep: Rebecca Ahne

NAVAIR SIO

Kim Cristaudo

NAVAIR SSO

Sig:
Enter your name here.: Special Access Program requirements and procedures will be governed by the Air Force Instructions (AFI) 16-701 and DoD Manual 5205.07 volumes I – IV include but not limited to, Intelligence Community Directives (ICDs) of a security relevant nature. In accordance with the DoD SAPCO Memorandum, Transition to the Risk Management Framework, dated December 18, 2013, certification and authorization of any information system after December 18, 2016 must be accomplished utilizing the Risk Management Framework (RMF), Joint Special Access Implementation Guide (JSIG), Rev 4, dated January 21, 2016 and DoD Standards and Reciprocity for Sanitization of SAP Information Technology Devices, dated 20 Apr 20. All new Special Access Required information systems must utilized RMF and JSIG for certification and authorization as they are created. OPSEC requirements apply.
Enter your name here.: OSI PJ Executive Security Director will maintain inspection authority and security cognizance for all classified material and/or information within accredited Special Access Facilities (SAPF’s) used in support of this contract. F-35 JPO Arlington, VA will have security cognizance over collateral material classified by the JSF SCG located at the LM F-35 facility (FSC 4AWR6). “NAVAIR SSO (PAX River) is cognizant authority for SCI material.” “US Army CUSR will maintain security cognizance over NATO material”.
GCAName: F-35 Program Office
AAC: N00019
AAC: N00019
Address: F-35 Joint Program Office (JPO)

200 12th Street, Suite 600 Arlington, VA 22202 Address: F-35 Joint Program Office (JPO) 200 12th Street, Suite 600 Arlington, VA 22202

POCName: Jeremy Hodgkin
Phone: 7036015477
Email: jeremy.hodgkin@jsf.mil
Email: john.rhodes@jsf.mil
Title: Collateral Security Manager
Enter the date using the format DD-Mon-YYYY: 20210909

File details come from the government source that posted it. Updated .