SE4 - Attachment 4 - DD 254.pdf

PDF 635 KB Posted

Attached to
SPAWAR ASHORE GLOBAL C4ISR INSTALLATIONS CONTRACT Federal contract opportunity
Solicitation number
N00039-18-R-0060
Issued by
Department of the Navy Information Warfare Systems Command

About this file

This document outlines security requirements for contractors supporting the Space and Naval Warfare Systems Command (SPAWAR) Ashore Global C4ISR Installations contract. Key details include:

  • The contract supports classified and unclassified IT systems and networks processing Department of Defense information. Contractors must comply with security regulations and procedures from directives including DoD 5200.2-R and SECNAVINST 5510.36.

  • Requirements cover personnel security investigations, handling and transmitting classified materials, information systems security, visitor control, cellular phone usage, personal electronic media restrictions, intelligence information access, TEMPEST compliance, operations security protocols, and specific on-site security controls.

  • Contractors must protect critical information as defined, which includes details on U.S. military capabilities and vulnerabilities, operations, testing, and network and facility security. Countermeasures require encrypting and protecting emails and documents containing critical information.

View the file

Other files for this federal contract opportunity

Other files attached to SPAWAR ASHORE GLOBAL C4ISR INSTALLATIONS CONTRACT, newest first.
File Type Posted
Q and A - N00039-18-R-0060 - Shore - 02 MAY 2018.pdf PDF
SE4 - Attachment 8 - Small Business Participation Data (01MAY2018).xlsx XLSX spreadsheet
N00039-18-R-0060-0005.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 01 MAY 2018.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 27 APR 2018.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 26 APR 2018.pdf PDF
N00039-18-R-0060-0004.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 20 APR 2018.pdf PDF
N00039-18-R-0060-0003.pdf PDF
SE4 - Attachment 5 - QASP (29MAR2018).pdf PDF
SE4 - Exhibit A - DD 1423 (11APR2018).pdf PDF
N00039-18-R-0060-0002.pdf PDF
INDUSTRY DAY II Sign In Sheet 20180402.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 05 APR 2018.pdf PDF
GIC SE 4 Industry Day Presentation.pptx PPTX presentation
SE4 - Attachment 3 - Statement of Work (SOW) 11APR2018.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 12 APR 2018_FINAL.pdf PDF
N00039-18-R-0060-0001.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 26 MAR 2018.pdf PDF
SE4 - Attachment 14 - Price Risk Math Model 26 MAR 2018.pdf PDF
SE4 - Attachment 11 - Proposal Ratings Guide.pdf PDF
N00039-18-R-0060.pdf PDF
SE4 - Exhibit A - DD 1423 (13MAR2018).pdf PDF
SE4 - Attachment 9 - Past Performance Questionnaire.docx DOCX document
SE4 - Attachment 10 - Proposal Checklist.pdf PDF
SE4 - Attachment 1B - Final Fee or Profit Determination Formula (09NOV2017).xlsx XLSX spreadsheet
SE4 - Attachment 1A - Incentive Plan 24OCT2017.pdf PDF
SE4 - Attachment 13 - CENTCOM Clauses Afghanistan (JAN 2018).pdf PDF
SE4 - Attachment 5 - QASP (03NOV2017).pdf PDF
SE4 - Attachment 7 - Reference Information Sheet (RIS).docx DOCX document
SE4 - Attachment 8 - Small Business Participation Data (22FEB2018).xlsx XLSX spreadsheet
SE4 - Attachment 12 - Gate Review Matrix.xlsx XLSX spreadsheet
SE4 - ATTACHMENT 6 - Ceiling Distribution Proposal (26JAN2018).xlsx XLSX spreadsheet
SE4 - Attachment 3 - Statement of Work (SOW) 09MAR2018.pdf PDF
SE4 - Attachment 2 - Personnel Qualifications (06NOV2017).pdf PDF
Industry_Day_2_Information.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 13 MAR 2018.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 14 FEB 2018.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 14 FEB 2018.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 10 JAN 2018.pdf PDF
Q and A - N00039-18-R-0060 - Shore - 10 JAN 2018.pdf PDF
Show all 41

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

INFORMATION TECHNOLOGY (IT) SYSTEMS PERSONNEL SECURITY PROGRAM

REQUIREMENTS

The U.S. Government conducts trustworthiness investigations of personnel who are assigned to positions that directly or indirectly affect the operation of unclassified IT resources and systems that process Department of

Defense (DoD) information, to include For Official Use Only (FOUO) and other controlled unclassified information.

The United States Office of Personnel Management (OPM), Federal Investigations Processing Center (FIPC) process all requests for U.S. Government trustworthiness investigations. Requirements for these investigations are outlined in paragraph C3.6.15 and Appendix 10 of DoD 5200.2-R, available at http://www.dtic.mil/whs/directives/corres/dir.html. Personnel occupying an IT Position shall be designated as filling one of the IT Position Categories listed below. The contractor shall include all of these requirements in any subcontracts involving IT support. (Note: Terminology used in DoD 5200.2-R references “ADP” vice “IT”.

For purposes of this requirement, the terms ADP and IT are synonymous.)

The Program Manager (PM), Contracting Officer’s Representative (COR) or Technical Representative (TR) shall determine if they or the contractor shall assign the IT Position category to contractor personnel and inform the contractor of their determination. If it is decided the contractor shall make the assignment, the PM, COR, or TR must concur with the designation.

DoDD Directive 8500.01, Subject: Information Assurance (IA), paragraph 4.8 states "Access to all DoD information systems shall be based on a demonstrated need-to-know, and granted in accordance with applicable laws and DoD 5200.2-R for background investigations, special access and IT position designations and requirements. An appropriate security clearance and non-disclosure agreement are also required for access to classified information” in accordance with DoDM 5200.01 Vol. 1. DoD 5200.2-R and DoDD 5200.2 require all persons assigned to sensitive positions or assigned to sensitive duties be U.S. citizens. All persons assigned to

IT-I and IT-II positions, as well as all persons with access to controlled unclassified information (without regard to degree of IT access) or performing other duties that are considered "sensitive" as defined in DoDD 5200.2 and

DoD 5200.2-R must be U.S. citizens. Furthermore, access by non-U.S. citizens to unclassified export controlled data will only be granted to persons pursuant to the export control laws of the U.S. The categories of controlled unclassified information are specified in DoDM 5200.01 Vol. 4. These same restrictions apply to

"Representatives of a Foreign Interest" as defined by DoD 5220.22-M (National Industrial Security Program

Operating Manual, NISPOM). DoD 8570.01-M further stipulates additional training and/or certification that is required by all persons assigned to Information Assurance functions.

Criteria For Designating Positions: updated per OPM Federal Investigations Notice No. 16-02, dated

October 6, 2015:

Tier 5/5R is for Top Secret and/or SCI – Critical or Special Sensitive Positions = IT-I Position (Privileged)

Responsibility or the development and administration of Government computer security programs, and including direction and control of risk analysis an/or threat assessment.

Significant involvement in life-critical or mission-critical systems.

Responsibility for the preparation or approval of data for input into a system, which does not necessarily involve personal access to the system, but with relatively high risk for effecting grave damage or realizing significant personal gain.

Relatively high risk assignments associated with or directly involving the accounting, disbursement, or authorization for disbursement from systems of (1) dollar amounts of $10 million per year or greater, or http://www.dtic.mil/whs/directives/corres/dir.html

(2) lesser amounts if the activities of the individual are not subject to technical review by higher authority in the IT-I category to ensure the integrity of the system.

Positions involving major responsibility for the direction, planning, design, testing, maintenance, operation, monitoring, and/or management of systems hardware and software.

Other positions as designated by Space and Naval Warfare Systems Center Pacific (SSC Pacific) that involve relatively high risk for effecting grave damage or realizing significant personal gain.

Personnel whose duties meet the criteria for IT-I Position designation require a favorably adjudicated Single

Scope Background Investigation (SSBI) or SSBI Periodic Reinvestigation (SSBI-PR) or Tier 5/5R. The

SSBI or SSBI-PR or Tier 5/5R shall be updated every 5 years by using the Electronic Questionnaire for

Investigation Processing (eQIP) web based program (SF86 format).

Tier 3/3R is for Secret – Non Critical Sensitive positions = IT-II Position (Limited Privileged)

Responsibility for systems design, operation, testing, maintenance, and/or monitoring that is carried out under technical review of higher authority in the IT-I category, includes but is not limited to:

Access to and/or processing of proprietary data, information requiring protection under the Privacy Act of 1974, and Government-developed privileged information involving the award of contracts;

Accounting, disbursement, or authorization for disbursement from systems of dollar amounts less than

$10 million per year. Other positions are designated by Space and Naval Warfare Systems Center

Pacific (SSC Pacific) that involve a degree of access to a system that creates a significant potential for damage or personal gain less than that in IT-I positions. Personnel whose duties meet the criteria for an

IT-II Position require a favorably adjudicated National Agency Check with Local Agency Check and

Credit Check (NACLC) or Tier 3/3R.

Tier 1/1R is for Unclassified – Non-Sensitive positions = IT-III Position (Non-Privileged)

All other positions involving Federal IT activities. Incumbent in this position has non-privileged access to one or more DoD information systems, application, or database to which they are authorized access.

Personnel whose duties meet the criteria for an IT-III Position designation require a favorably adjudicated National Agency Check with Inquiries (NACI) or Tier 1/1R.

Qualified Cleared Personnel Do NOT Require Trustworthiness Investigations:

When background investigations supporting clearance eligibility have been submitted and/or adjudicated to support assignment to sensitive national security positions, a separate investigation to support IT access will normally not be required. A determination that an individual is NOT eligible for assignment to a position of trust will also result in the removal of eligibility for security clearance. Likewise, a determination that an individual is

NOT eligible for a security clearance will result in the denial of eligibility for a position of trust.

Procedures for submitting U.S. Government Trustworthiness Investigations:

Only the e-QIP version of SF-85 and SF 86 are acceptable by OPM-FIPC.

The Facility Security Officer (FSO) must verify employee's security clearance eligibility in the Joint Personnel

Adjudication System (JPAS) before contacting SSC Pacific Personnel Security Office to initiate request for trustworthiness investigations.

After determining that an individual requires Public Trust Position determination, the FSO will identify the individual to the SSC Pacific Personnel Security Office and the specific IT Level category assigned for requesting the appropriate type of investigation. The FSO will also provide the following information to the SSC

Pacific Personnel Security Office to initiate a request thru e-QIP:

Full SSN of the applicant

Full Name

Date of Birth

Place of Birth

Email Address

Phone Number

The Personnel Security Office will send email notification and instruction to the applicant to complete and submit e-QIP expeditiously.

The FSO or SSC Pacific Personnel Security Office will take and submit fingerprints using SF-87, FD-258 or electronic submission. The FSO must obtain from SSC Pacific Personnel Security Office the e-QIP Request

Number for inclusion in submitting the fingerprints. For immediate fingerprint result, electronic transmission of fingerprints is encouraged. Submission of hard copy SF-87 or FD-258 is acceptable until 2013 to:

E-QIP RAPID RESPONSE TEAM

OPM-FIPC

1137 BRANCHTON ROAD

BOYERS, PA 16020

SSC Pacific Personnel Security Office will notify the FSO when the Public Trust Investigation request is released to the Parent Agency, the Office of Personnel Management (OPM).

Contractor fitness determinations made by the DOD CAF are maintained in the Joint Personnel Adjudication

System (JPAS). Favorable fitness determinations will support public trust positions only and not national security eligibility. If no issues are discovered, according to respective guidelines a “Favorable Determination” will be populated in JPAS and will be reciprocal within DoN. If issues are discovered, the DOD CAF will forward the investigation along with all supporting documentation to the SSC Pacific Security Office for local determination. The local fitness determination will be made by the Command Security Manager and your company will be notified of the decision in writing. If an individual received a negative trustworthiness determination, they will be immediately removed from their position of trust, the contractor will follow the same employee termination processing above, and they will replace any individual who has received a negative trustworthiness determination.

If you require additional assistance with the submission of Public Trust Investigations, you may send an email to

SSC Pacific at W_SPSC_SSC_PAC_clearance US@navy.mil.

Visit Authorization Letters (VALs) for Qualified Employees:

Contractors that have been awarded a classified contract must submit visit requests using “only” the Joint

Personnel Adjudication System (JPAS). All government activities have been directed to use JPAS when transmitting or receiving VALS. Therefore, contractors who work on classified contracts are required to have established an account through JPAS for their facility. This database contains all U.S. citizens who have received a clearance of Confidential, Secret, and/or Top Secret. The visit request can be submitted for one year.

When submitting a visit requests to SSC Pacific, use its Security Management Office (SMO) number (660015).

mailto:W_SPSC_SSC_PAC_clearance%20US@navy.mil

This information is provided in accordance with guidance provided to contractors via the Defense Security

Service (DSS) website https://www.dss.mil/ (DSS guidance dated 24 April 2007, subject: Procedures Governing the Use of JPAS by Cleared Contractors).

Employment Terminations:

The contractor shall:

Immediately notify the COR or TR of the employee’s termination.

Send email to W_SPSC_SSC_PAC_clearance_US@navy.mil, Code 83310 notifying them of the termination.

Fax a termination VAL to Code 83320 at (619) 553-6169.

Return any badge and decal to Commanding Officer, Space and Naval Warfare Systems Center Pacific, Attn: Code 83320, 53560 Hull Street, San Diego, CA 92152-5001.

https://www.dss.mil/ mailto:W_SPSC_SSC_PAC_clearance_US@navy.mil

SPECIFIC ON-SITE SECURITY REQUIREMENTS

I. GENERAL.

a. CONTRACTOR WILL ABIDE BY ALL SECURITY REGULATIONS AS IDENTIFIED BY EACH

HOST COMMAND FOR ALL LOCATIONS OF PERFORMANCE. The below guidance is for performance onboard SPAWAR / PEO C4I OTC locations. Other locations of performance may have differing or additional requirements that must be followed by contractor personnel.

b. Contractor Performance. In performance of this Contract the following security services and procedures are incorporated as an attachment to the DD 254. The Contractor will conform to the requirements of DoD 5220.22-M, Department of Defense National Industrial Security Program, Operating Manual (NISPOM). When visiting the Program Executive Office Command, Control, Communications, Computers, and Intelligence (PEO C4I) at Old Town Campus (OTC) the Contractor will comply with the security directives used regarding the protection of classified and controlled unclassified information, SECNAVINST 5510.36 (series), SECNAVINST 5510.30 (series), and

SPAWARINST 5510.1. Both of the SECNAV Instructions are available online at http://neds.nebt.daps.mil/directives/table52.html the SPAWAR instruction is available via request. If the Contractor establishes a cleared facility or Defense Security Service (DSS) approved off-site location from COMSPAWAR SYSCOM, the security provisions of the NISPOM will be followed within this cleared facility.

c. Security Supervision. Space and Naval Warfare Systems Command (SPAWAR) will exercise security supervision over all contractors visiting PEO C4I and will provide security support to the Contractor as noted below. The Contractor will identify, in writing to Security’s Representative, an on-site Point of

Contact to interface with Security’s Representative.

II. HANDLING CLASSIFIED MATERIAL OR INFORMATION.

a. Control and Safeguarding. Contractor personnel located at PEO C4I are responsible for the control and safeguarding of all classified material in their possession. All contractor personnel will be briefed by their FSO on their individual responsibilities to safeguard classified material. In the event of possible or actual loss or compromise of classified material, the on-site Contractor will immediately report the incident to SPAWAR’s Code 8.3.3 Security COR, as well as the Contractor's FSO. A Code 8.3.3 representative will investigate the circumstances, determine culpability where possible, and report results of the inquiry to the FSO and the Cognizant DSS Field Office. On-site contractor personnel will promptly correct any deficient security conditions identified by a SPAWAR Security representative.

b. Storage.

1. Classified material may be stored in containers authorized by SPAWARSYSCOM Command

Security Manager (CSM) for the storage of that level of classified material. Classified material may also be stored in Contractor owned containers brought on board SPAWAR with written permission. Areas located within cleared contractor facilities on board SPAWAR will be approved by DSS.

2. The use of Open Storage areas must be pre-approved in writing by SPAWARYSCOM CSM for the open storage, or processing, of classified material. Specific supplemental security controls for open storage areas, when required, will be provided by SPAWARSYSCOM CSM.

c. Transmission of Classified Material.

http://neds.nebt.daps.mil/directives/table52.html

1. All classified material transmitted by mail for use by long term visitors will be addressed as follows:

(a) TOP SECRET, Non-Sensitive Compartmented Information (non-SCI) material using the

Defense Courier Service: SSC Pacific: 271582-SN00, SSC Pacific.

(b) CONFIDENTIAL and SECRET material transmitted by FedEx will be addressed to

COMMANDING OFFICER, SPACE AND NAVAL WARFARE SYSTEMS CENTER

PACIFIC, ATTN RECEIVING OFFICER CODE 43150, 4297 PACIFIC HIGHWAY, SAN

DIEGO, CA 92110.

(c) CONFIDENTIAL and SECRET material transmitted by USPS Registered and Express mail will be addressed to COMMANDING OFFICER, SPACE AND NAVAL WARFARE SYSTEMS

CENTER PACIFIC, 53560 HULL STREET, SAN DIEGO CA 92152-5001. The inner envelope will be addressed to the attention of the Contracting Officer's Representative (COR) or applicable

Technical Representative (TR) for this contract, to include their code number.

2. All CONFIDENTIAL material hand carried to PEO C4I by contractor personnel that is intended to remain at PEO C4I shall be provided to the designated recipient or proper cleared PEO C4I employee.

3. All PEO C4I classified material transmitted by contractor personnel from PEO C4I will be sent via the PEO C4I TR for this contract.

4. The sole exception to the above is items categorized as a Data Deliverable. All contract Data

Deliverables will be sent directly to the TR and a notification of deliverables without attachments will be sent to the appropriate personnel, unless otherwise stated in the contract.

III. INFORMATION SYSTEMS (IS) Security. Contractors using ISs, networks, or computer resources to process classified, sensitive unclassified and/or unclassified information will comply with the provisions of

SECNAVINST 5239.3 (series) and local policies and procedures. Contractor personnel must ensure that systems they use at COMSPAWARSYSCOM/PEO C4I have been granted a formal letter of approval to operate by contacting their Information Assurance Office.

IV. VISITOR CONTROL PROCEDURES.

As a tenant command of Naval Base Point Loma (NBPL), SPAWAR / PEO C4I contractors must abide by NBPL visitor procedures. These procedures can be accessed via the following link:

https://www.cnic.navy.mil/regions/cnrsw/installations/navbase_point_loma/about/visitor_information.html

V. INSPECTIONS. SPAWAR Code 8.3.3 personnel may conduct periodic inspections of the security practices of the on-site Contractor. All contractor personnel will cooperate with Code 8.3.3 representatives during these inspections. A report of the inspection will be forwarded to the Contractor's employing facility, Security’s

Representative and TR. The Contractor must be responsive to the Code 8.3.3 representative's findings.

VI. REPORTS. As required by the NISPOM, Chapter 1, Section 3, contractors are required to report certain events that have an impact on the status of the facility clearance (FCL), the status of an employee's personnel clearance (PCL), the proper safeguarding of classified information, or indication classified information has been lost or compromised.

a. The Contractor will ensure that certain information pertaining to assigned contractor personnel or operations is reported to Security’s Representative, Code 8.3.3. If further investigation is warranted it will be conducted by Code 8.3.3. This reporting will include the following:

1. The denial, suspension, or revocation of security clearance of any assigned personnel;

2 Any adverse information on an assigned employee's continued suitability for continued access to classified access;

3. Any instance of loss or compromise, or suspected loss or compromise, of classified information;

4. Actual, probable or possible espionage, sabotage, or subversive information; or

5. Any other circumstances of a security nature that would affect the contractor's operation on board

PEO C4I.

b. In addition to the NISPOM reporting requirements, any conviction and/or violation of the Foreign

Corrupt Practices Act, or any other violation of the International Traffic in Arms Regulations (ITAR) shall immediately be reported to the Designated Disclosure Authority (DDA), TR and PM.

VII. PHYSICAL SECURITY.

a. Naval Base Point Loma (NBPL) will provide appropriate response to emergencies occurring onboard this command. The Contractor will comply with all emergency rules and procedures established for

NBPL.

b. A roving Contract Security Guard patrol will be provided by SPAWARSYCOM. Such coverage will consist of, but not be limited to, physical checks of the window or door access points, classified containers, and improperly secured documents or spaces.

c. All personnel aboard PEO C4I property are subject to random inspections of their vehicles and personal items. Consent to these inspections is given when personnel accept either a badge or a vehicle pass/decal permitting entrance to this command.

Contractors must comply with installation access control procedures. Any Contractor who repeatedly violates access control requirements will be issued an Apparent Security Violation (ASV). After the ASV has been investigated, a letter will be forwarded to the contracting facility’s Security Officer via the Center’s Contracting

Officer for resolution.

VIII. TECHNICAL REPRESENTATIVE RESPONSIBILITIES.

a. Review requests by cleared contractors for retention of classified information beyond a two-year period and advise the contractor of disposition instructions and/or submit a Final DD 254 to Security’s

Representative.

b. In conjunction with the appropriate transportation element, coordinates a suitable method of shipment for classified material when required.

c. Certify and approve Registration For Scientific and Technical Information Services requests (DD 1540)

(DTIC).

d. Ensure timely notice of contract award is given to host commands when contractor performance is required at other locations.

e. Certify need-to-know on visit requests and conference registration forms.

IX. SPECIAL CONSIDERATIONS FOR ON-SITE CLEARED FACILITIES.

Any cleared contractor facility on board PEO C4I will be used strictly for official business associated with this contract. No other work may be performed aboard this facility. Additional PEO C4I contracts may be performed in this cleared facility, but only on a case-by-case basis. The TR and Security’s Representative must all be in agreement that this particular arrangement best suits the needs of the Government. At the end of this contract the on-site facility must be vacated, with proper written notification being submitted to the

DSS and Security’s Representative.

X. ITEMS PROHIBITED ABOARD TEAM SPAWAR.

The following items are prohibited within any Team SPAWAR controlled areas, with the exception of personnel authorized to possess weapons in the performance of required duties. Also, note exceptions for alcohol possession and consumption on board Team SPAWAR property.

WEAPONS

1. Ammunition

2. Fireworks

3. Molotov Cocktail

4. Pipe Bomb

5. Black Jack

6. Slingshots

7. Billy/Sand Club

8. Nunchakus

9. Sand Bag: Partially filled with sand and swung like a mace

10. Metal (Brass) Knuckle

11. Dirk or Dagger

12. Switch Blade or Butterfly Knife

13. Knife with a blade (cutting edge) longer than 4 inches

14. Razor with Unguarded blade.

15. Pipe, Bar or Mallet to be used as a club.

16. Compressed Air or Spring Fired Pellet/BB gun

17. Tear Gas/Pepper Spray Weapon

18. Pistol, Revolver, Rifle, Shotgun or any other Firearm

19. Bows, Crossbows or Arrows

20. Bowie Style Hunting Knife

21. Any weapon prohibited by State law

22. Any object similar to the aforementioned items

23. Any offensive or defensive weapons not described above, but likely to cause injury (i.e., Stun Gun, Blow Gun).

24. Any abrasive, caustic, acid, chemical agent or similar substance, with which to inflict property damage or personal injury

25. Combination Tools with Knife Blades Longer Than 4 inches (i.e., Gerber, Leatherman, etc.)

Military personnel aboard Team SPAWAR controlled areas not authorized to possess a firearm, as part of prescribed military duties will be apprehended if found in possession. Civilians in unauthorized possession of a firearm will be detained while civilian authorities are notified.

CONTROLLED SUBSTANCES

The unauthorized possession or use of controlled substances defined as marijuana, narcotics, hallucinogens, psychedelics, or other controlled substances included in Schedule I, II, III, IV, or V established by Section 202 of the Comprehensive Drug Abuse Prevention and Control Act of 1970

(84 Stat. 1236) is prohibited.

CONTRABAND

Contraband defined as all equipment, products, and materials of any kind which are used, intended for use, or designed for use in injecting, ingesting, inhaling, or otherwise introducing into the human body, marijuana or other controlled substances, in violation of law. This includes hypodermic syringes, needles, and other objects to inject controlled substances in the body or objects to ingest, inhale or otherwise introduce marijuana, cocaine or hashish oil into the body is prohibited.

ALCOHOL

All COMSPAWARSYSCOM, co-located command and other government employees, as well as support contractors and authorized visitors may bring unopened containers of alcohol on board the Center if it remains in their private vehicles except where expressly authorized for an approved event. Alcoholic beverages will be consumed only at designated facilities for which written permission by the head of the command is granted.

Personnel desiring to hold a social function and serve alcohol, should send a memo (hard copy) to the head of the command, via the appropriate division head, Director of Security, and Public Affairs Officer (PAO).

The PEO will approve or disapprove the facility use request based on availability and general use policy. If facility use is approved, the PAO will forward the memo to the head of the command for approval/disapproval.

COUNTERFEIT CURRENCY

Counterfeit currency defined as any copy, photo, or other likeness of any U.S. currency, either past or present, not authorized by the U.S. Treasury Department is prohibited.

XI. ESCORTING POLICY.

a. ALL PEO C4I FOREIGN NATIONAL VISITORS MUST BE PROCESSED THROUGH THE

SPAWARSYSCOM FOREIGN VISITS OFFICE, 8.3.3.5. Contact phone number: (858) 537-8884.

XIII. CELLULAR PHONE USAGE.

a. Cellular phone use is prohibited in all secure spaces, i.e. Open Storage areas, classified laboratories.

b. Vehicle operators on DoD installations and operators of Government vehicles shall not use cellular phones, unless the vehicle is safely parked or unless they are using a hands-free device, and are also prohibited from wearing of any other portable headphones, earphones, or other listening devices while operating a motor vehicle.

c. The use of cellular phones, portable headphones, earphones, or other listening devices while jogging, walking, bicycling, or skating on roads and streets on Navy installations is prohibited except for use on designated bicycle and running paths and sidewalks.

XIV. PERSONAL ELECTRONIC MEDIA

The use of personal electronic media (computer laptops, flash (thumb), or other removable drives) is prohibited in team SPAWAR spaces except where explicitly permitted by the COMSPAWARSYSCOM

Director of Security, (858) 537-8898. All removable electronic media must be labeled (unclassified, etc.) To the highest classification of data stored, and/or for the classification of the system in which it is used. If classified, any removable electronic media must be tracked and stored appropriate to that level of classification.

FOR OFFICIAL USE ONLY (FOUO) INFORMATION

1. The For Official Use Only (FOUO) marking is assigned to Information at the time of its creation. It isn't authorized as a substitute for a security classification marking but is used on official government information that may be withheld from the public under exemptions 2 through 9of the Freedom of Information Act (FOIA).

2. Use of FOUO markings doesn't mean that the information can't be released to the public, only that it must be reviewed by SPAWAR prior to its release to determine whether a significant and legitimate government purpose is served by withholding the information or portions of it.

3. An UNCLASSIFIED document containing FOUO information will be marked "FOR OFFICIAL USE ONLY" on the bottom face and interior pages.

4. Classified documents containing FOUO do not require any markings on the face of the document; however, the interior pages containing only FOUO information shall be marked top and bottom center with "FOR

OFFICIAL USE ONLY" Mark only unclassified portions containing FOUO with "(FOUO)" immediately before the portion.

5. Any FOUO information released to you by SPAWAR is required to be marked with the following statement prior to transfer:

THIS DOCUMENT CONTAINS INFORMATION EXEMPT FROM MANDATORY DISCLOSURE

UNDER THE FOIA EXEMPTION(S) ___________ APPLY.

6. Removal of the FOUO marking can only be accomplished by the originator or other competent authority. DO

NOT RCMOVE ANY FOUO MARKING WITHOUT WRITTEN AUTHORIZATION FROM SPAWAR OR

THE AUTHOR. When the FOUO status is terminated you will be notified.

7. You may disseminate FOUO information to your employees and subcontractors who have a need for the

Information in connection with this contract.

8 During working hours, reasonable steps should be taken to minimize risk of access by unauthorized personnel.

FOUO Information shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During nonworking hours, the information shall be stored in locked desks, file cabinets, bookcases, locked rooms, or similar items.

9. FOUO information may be transmitted via first-class mail, parcel post, fourth-class mail for bulk shipments only.

10. When no longer needed, FOUO information may be disposed by tearing each copy Into pieces to preclude reconstructing and placing it in a regular trash, or recycle, container or in the uncontrolled burn.

11. Unauthorized disclosure of FOUO information doesn't constitute a security violation but the releasing agency should be informed of any unauthorized disclosure. The unauthorized disclosure of FOUO Information protected by the Privacy Act may result in criminal sanctions.

12. Electronic transmission of FOUO Information (voice, data, or facsimile) should be by approved secure communications systems whenever practical.

13. To obtain for official use only (FOUO) guidance refer to the DoD Information Security Program Regulation, DoD 5200.1-r, appendix 3, located at http://www.dtic.mil/whs/directives/corres/pdf/520001r.pdf.

http://www.dtic.mil/whs/directives/corres/pdf/520001r.pdf

CONTRACTOR REQUIREMENTS FOR ACCESS TO INTELLIGENCE INFORMATION

1. Intelligence material and information, either furnished by the user agency or generated under the contract performance, will not be:

a. Reproduced without prior approval of the originator of the material. All Intelligence material shall bear a prohibition against reproduction while in your custody; or

b. Released to foreign nationals or immigrant aliens who you may employ, regardless of their security clearance or access authorization, except with the specific permission of the Office of Naval

Intelligence (ONI-5), via Security’s Contracting Officer’s Representative (COR); or

c. Released to any activity or person of the contractor’s organization not directly engaged in providing services under the contract or to another contractor (including subcontractors), government agency, private individual, or organization without prior approval of the originator of the material, and prior approval and certification of need-to-know by the designated project manager/contract sponsor.

2. Intelligence material does not become the property of the contractor and may be withdrawn at any time.

Upon expiration of the contract, all intelligence released and any material using data from the Intelligence must be returned to the COR or authorized representative for final disposition. The contractor shall maintain such records as will permit them to furnish, on demand, the names of individuals who have access to Intelligence material in their custody.

3. Access to Intelligence data will only be through cognizant government program managers/project engineers.

Independent access is not inferred or intended.

4. Classified Intelligence, even though it bears no control markings, will not be released in any form to foreign nationals or immigrant aliens (including u.s. government employed, utilized or integrated foreign nationals and immigrant aliens) without permission of the originator.

5. You will maintain records that will permit you to furnish, on demand, the names of individuals who have access to Intelligence material in your custody.

6. Access to SCI Intelligence data requires the adherence to the requirements set forth in the following documents:

- DoDM 5105.21, Volumes 1-3, SCI Administrative Security Manual

- DoD 5220.22M, Change 2 (NISPOM) and Supplements

- DoDM 5200.01, Volumes 1-4, DoD Information Security Program

- SECNAV 5510.36, Information Security Program

- ICD 403-Foreign Disclosure and Release of Classified Nation Intelligence

- ICD 704, Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive

Compartmented Information and Other Controlled Access Program Information

- ICD 701, Security Policy Directive for Unauthorized Disclosures of Classified Information

- ICD 703, Protection of National Intelligence, Including Sensitive Compartmented information

- ICS 703-02, Reporting Requirements for Individuals with Access to Sensitive Compartmented

Information

- ICS 703-03, Protection of Classified National Intelligence Including Sensitive Compartmented

Information Shared with Entities Outside the Intelligence Community

- ICD 710, Classified Management and Control Markings System

TEMPEST REQUIREMENTS QUESTIONNAIRE (TRQ)

FOR CONTRACTOR FACILITIES

1. This TRQ must be completed and sent to the contracting authority and the Certified TEMPEST Technical

Authority (CTTA) within 30 days after contract award for all contracts where classified National Security

Information (NSI) will be processed and the requirements of item 13 of the DD 254 have been met.

2. The prime contractor cannot pass TEMPEST requirements to subcontractors. Subcontractors must submit a

Contractor TRQ prior to processing.

3. The TRQ is for information collection only. It is not a directive or an implied requirement, nor is it an encouragement to procure TEMPEST equipment or any type of shielding for use on this contract. DO NOT initiate any changes to equipment of facilities for TEMPEST unless it has been recommended by the CTTA and specifically directed by the contracting authority.

4. The contracting authority will not issue any directives concerning TEMPEST until after the contractor submitted TRQ has been evaluated by the CTTA and resulting recommendations received. To fully evaluate the

TRQ, the CTTA may request additional information concerning the facility, its physical control, the equipment which will be used to process NSI, etc.

5. The contractor shall ensure compliance with any TEMPEST countermeasure(s) specifically directed in writing by the contracting authority.

6. Please provide the information requested in paragraphs 7 through 20 and return to the CTTA at:

Commanding Officer

SPAWARSYSCEN Atlantic

Code 723

PO Box 190022

North Charleston, SC 29419-9022

7. Provide the name, address, position title and phone number (at the facility where classified processing will occur) of a point of contact who is knowledgeable of the processing requirements, the types of equipment to be used, and the physical layout of the facility.

8. Provide the specific geographical location, address, and zip code, where classified processing will be performed.

9. What are the classification level(s) of material to be processed/handled by electronic or electromechanical information system(s) and what percentage is processed at each level?

10. What special categories of classified information are processed?

11. Is there a direct connection (wireline or fiber) to a Radio Frequency (RF) transmitter(s) located either locally or at a remote site?

12. Are there any RF transmitters located within 6 meters of the system processing NSI or the system’s RED signal lines?

13. Describe how access is controlled to your facility including the building, compound, plant, property, and/or parking lots. Where are visitor’s first challenged/identified? Include controls such as alarms, guards, patrols, fences, and warning signs. Provide a simple block diagram of the equipment, the facility, and the surrounding areas. The diagram(s) should extend out

TEMPEST REQUIREMENTS QUESTIONNAIRE (TRQ)

FOR CONTRACTOR FACILITIES

to the nearest uncontrolled area on each side of the facility, such as a military base perimeter, plant property line, commercial building or residential area.

14. Are there other tenants in the building who are not U.S. department/agents?

15. Are there any known foreign business or government offices in adjacent buildings?

16. Provide the make and model number of all equipment used to process, transfer, or store classified information. Include computers, peripherals, network hardware, multiplexors, modems, encryption devices

(COMSEC), etc.

17. Have on-site TEMPEST tests been conducted on any of these equipment(s)? If so, which ones? When was the test(s) conducted? Who conducted the test(s)? Have all deficiencies (if any) been resolved?

18. Has a TEMPEST Facility Zoning test been conducted? If so, who conducted the testing and when?

19. Is this company foreign-owned or controlled? If so, what is the country?

20. Provide the contract number, identify the sponsoring command, point of contact or Contracting Officer’s

Representative, and their telephone number.

OPERATIONS SECURITY (OPSEC) REQUIREMENTS

All work is to be performed in accordance with DoD and Navy Operations Security (OPSEC) requirements, per the following applicable documents:

National Security Decision Directive 298, National Operations Security Program (NSDD) 298

DOD 5205.02, DOD Operations Security (OPSEC) Program Manual

OPNAVINST 3432.1, Operations Security

SPAWARINST 3432.1,Operations Security (OPSEC) Policy

The contractor will accomplish the following minimum requirements in support of the Program Executive Office

Command, Control, Communications, Computers and Intelligence (PEO C4I) OPSEC Program:

The contractor will practice OPSEC and implement OPSEC countermeasures to protect DoD Critical

Information. Items of Critical Information are those facts, which individually, or in the aggregate, reveal sensitive details about PEO C4I or the contractor’s security or operations related to the support or performance of this SOW, and thus require a level of protection from adversarial collection or exploitation not normally afforded to unclassified information.

Contractor must protect Critical Information and other sensitive unclassified information and activities, especially those activities or information which could compromise classified information or operations, or degrade the planning and execution of military operations performed or supported by the contractor in support of the mission. Protection of Critical Information will include the adherence to and execution of countermeasures which the contractor is notified by or provided by PEO C4I, for Critical

Information on or related to the SOW.

Sensitive unclassified information is that information marked FOR OFFICIAL USE ONLY (or FOUO), Privacy Act of 1974, Company Proprietary, and information identified by PEO C4I or the

SPAWARSYSCOM Security Representative.

PEO C4I has identified the following items as Critical Information that may be related to this SOW:

o Known or probable vulnerabilities to any U.S. system and their direct support systems.

o Details of capabilities or limitations of any U.S. system that reveal or could reveal known or probable vulnerabilities of any U.S. system and their direct support systems.

o Details of information about military operations, missions, and exercises.

o Details of U.S. systems supporting combat operations (numbers of systems deployed, deployment timelines, locations, effectiveness, unique capabilities, etc.).

o Operational characteristics for new or modified weapon systems (Probability of Kill, Countermeasures, Survivability, etc.).

o Required performance characteristics of U.S. systems using leading edge or greater technology

(new, modified, or existing).

o Telemetered or data-linked data or information from which operational characteristics can be inferred or derived.

o Test or evaluation information pertaining to schedules of events during which Critical Information might be captured. (advance greater than 3 days).

o Details of Team SPAWAR unique Test or Evaluation capabilities (disclosure of unique capabilities).

o Existence and/or details of intrusions into or attacks against DoD Networks or Information Systems, including, but not limited to, tactics, techniques and procedures used, network vulnerabilities exploited, and data targeted for exploitation.

o Network User ID’s and Passwords.

o Counter-IED capabilities and characteristics, including success or failure rates, damage assessments, advancements to existing or new capabilities.

o Vulnerabilities in Command processes, disclosure of which could allow someone to circumvent security, financial, personnel safety, or operations procedures.

o Force Protection specific capabilities or response protocols (timelines/equipment/numbers of personnel/training received/etc.).

o Command leadership and VIP agendas, reservations, plans/routes etc.

o Detailed facility maps or installation overhead photography (photo with annotation of Command areas or greater resolution than commercially available).

o Details of COOP, PEO C4I emergency evacuation procedures, or emergency recall procedures.

o Government personnel information that would reveal force structure and readiness (such as recall rosters or deployment lists).

o Compilations of information that directly disclose Command Critical Information.

The above Critical Information and any that the contractor develops, regardless if in electronic or hardcopy form, must be protected by a minimum of the following countermeasures:

All emails containing Critical Information must be DoD Public Key Infrastructure (PKI) signed and PKI encrypted when sent.

Critical Information may not be sent via unclassified fax.

Critical Information may not be discussed via non-secure phones.

Critical Information may not be provided to individuals that do not have a need to know it in order to complete their assigned duties.

Critical Information may not be disposed of in recycle bins or trash containers.

Critical Information may not be left unattended in uncontrolled areas.

Critical Information in general should be treated with the same care as FOUO or proprietary information.

Critical Information must be destroyed in the same manner as FOUO.

Critical Information must be destroyed at contract termination or returned to the government at the government’s discretion.

The contractor shall document items of Critical Information that are applicable to contractor operations involving information on or related to the SOW. Such determinations of Critical Information will be completed using the DoD OPSEC 5 step process as described in National Security Decision Directive (NSDD) 298, “National

Operations Security Program”.

OPSEC training must be Included as part of the contractors ongoing security awareness program conducted in accordance with Chapter 3, Section 1, of the NISPOM. NSDD 298, DoD 5205.02, “DOD Operations Security

(OPSEC) Program”, and OPNAVINST 3432.1, “Operations Security” should be used to assist in creation or management of training curriculum.

If the contractor cannot resolve an issue concerning OPSEC they will contact the SPAWARSYSCOM Security

Representative (who will consult with the SPAWARSYSCOM OPSEC Manager).

All above requirements MUST be passed to all Sub-contractors.

Questions pertaining to the SPAWAR OPSEC Program should be directed to Grant Merkel, 619-553-2800, email grant.merkel@navy.mil .

mailto:grant.merkel@navy.mil

File details come from the government source that posted it. Updated .