BIDDING_012-19_OPSEC_Reviewed.pdf
PDF 2 MB Posted
- Attached to
- iLab Support Federal contract opportunity
- Solicitation number
- N0017819R2628
About this file
DD Form 254-Bidding
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| N0017819R2628_-_iLab_Support_-_DID.pdf | ||
| N0017819R2628_FBO.pdf | ||
| N0017819R2628__iLab_Support_-_CDRL_A001.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CLASSIFICATION (When filled in): Unclassified
PREVIOUS EDITION IS OBSOLETE. Page 1 of 4
AEM LiveCycle Designer DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 1 of 4
AEM LiveCycle Designer
DD FORM 254, APR 2018
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
October 31, 2020
The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED
(See Instructions)
Secret
b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/
MATERIAL REQUIRED AT CONTRACTOR FACILITY
None (See instructions)
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
a. PRIME CONTRACT NUMBER (See instructions.)
b. SUBCONTRACT NUMBER
c. SOLICITATION OR OTHER NUMBER
BIDDING 012-19
DUE DATE (YYYYMMDD)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
DATE (YYYYMMDD)
20190301
b. REVISED (Supersedes all previous specifications.)
REVISION NO. DATE (YYYYMMDD)
c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)
4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:
Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.
5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:
In response to the contractor's request dated , retention of the classified material is authorized for the period of:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor) Add Row Remove last Row Delete All Rows
a. NAME, ADDRESS, AND ZIP CODE
THIS DD254 IS FOR BIDDING PURPOSES ONLY
b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
THIS DD254 IS A GUIDE FOR BIDDING PURPOSES
ONLY. AN ORIGINAL DD254 WILL BE ISSUED
UPON AWARD OF CONTRACT.
8. ACTUAL PERFORMANCE (Click button to add more locations.) Add Row Remove last Row Delete All Rows
a. LOCATION(S) (For actual performance, see instructions.)
Naval Surface Warfare Center, Dahlgren Division Dahlgren, VA 22448
b. CAGE CODE (If applicable, see Instructions.)
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT
The Naval Surface Warfare Center, Dahlgren Division (NSWCDD), Innovation Lab (iLab) has acquired a variety of technology and collaboration tools that require specialized support to keep the technology systems integrated and operational and users trained on their use.
The iLab is built around a modern Audio/Visual (A/V) system, the Bluescape collaboration controller and associated touch monitor/cloud environment, as well as several disparate visualization and prototype tools such as the Microsoft hololens, the multi-user Colossus table and 3D plastic/metal printers as well as new 3D scanning capabilities. NSWCDD has invested a substantial amount of time and money into a collaboration tool called Bluescape which we are now implementing into a Cloud environment to allow collaboration across NSWCDD and the NR&DE. This SOW is to secure on-site Bluescape Cloud Integration Management support.
PREVIOUS EDITION IS OBSOLETE. Page 2 of 4
AEM LiveCycle Designer DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 2 of 4
AEM LiveCycle Designer
DD FORM 254, APR 2018
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION
b. RESTRICTED DATA g. NORTH ATLANTIC TREATY ORGANIZATION
(NATO) INFORMATION
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.) h. FOREIGN GOVERMENT INFORMATION
d. FORMERLY RESTRICTED DATA i. ALTERNATIVE COMPENSATORY CONTROL MEASURES
(ACCM) INFORMATION
e. NATIONAL INTELLIGENCE INFORMATION:
(1) Sensitive Compartmented Information (SCI)
(2) Non-SCI
j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)
k. OTHER (Specify) (See instructions.)
SIPRNET
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT
ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT
ACTIVITY
(Applicable only if there is no access or storage required at contractor facility.
See instructions.)
b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY
c. RECEIVE, STORE, AND GENERATE CLASSIFIED
INFORMATION OR MATERIAL
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE
e. PERFORM SERVICES ONLY
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE
THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST
TERRITORIES
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE
TECHNICAL INFORMATION CENTER (DTIC) OR OTHER
SECONDARY DISTRIBUTION CENTER
h. REQUIRE A COMSEC ACCOUNT
i. HAVE A TEMPEST REQUIREMENT
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE
l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED
INFORMATION (CUI).
(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)
m. OTHER (Specify) (See instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.
Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
DIRECT THROUGH (Specify below)
None Authorized
Public Release Authority:
13. SECURITY GUIDANCE Add Signature Remove last Signature Delete All Signatures
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;
and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
1. National Industrial Security Program Operating Manual (NISPOM), Feb 2006, Incorporating Changes, May 18, 2016 applies to this contract.
2. The contractor is not authorized to release any data to foreign nationals or foreign representatives without an approved export license.
3. Block 10a: Access to classified COMSEC information requires a final U.S. Government clearance at the appropriate level. Further disclosure of COMSEC information by a contractor, to include subcontracting, requires prior approval by GCA.
4. Block 10g and 10k: The actual knowledge of, generation, or production of NATO information is not required for performance on this contract. Contractors requiring access to SIPRNET are to receive a NATO awareness briefing prior to being provided access.
5. Block 10j: CUI encompasses what was previously stated as FOUO and PII. DoD components refer to DoDM 5200.01, VOL 4, "DoD Information Security Program: Controlled Unclassified Information (CUI)," available at http://www.esd.whs.mil/DD/DoD-Issuances/ when considering protection for CUI.
6. Block 11a: Contract Performance is restricted to Naval Surface Warfare Center, Dahlgren Division, Dahlgren VA
7. Block 11l: CUI encompasses what was previously stated as FOUO and PII. DoD components refer to DoDM 5200.01, VOL 4, "DoD Information Security Program: Controlled Unclassified Information (CUI)," available at http://www.esd.whs.mil/DD/DoD-Issuances/
PREVIOUS EDITION IS OBSOLETE. Page 3 of 4
AEM LiveCycle Designer DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 3 of 4
AEM LiveCycle Designer
DD FORM 254, APR 2018
when considering protection for CUI.
8. See attachments for additional security guidance.
List of Attachments (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)
Add Attachment View Selected Attachment Remove Selected Attachment
OPSEC review conducted NAME & TITLE OF REVIEWING OFFICIAL
Todd Goings, Code 1053 Alt OPSEC Program Manager
SIGNATURE
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
No Yes If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
No Yes If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item
13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
a. GCA NAME
Naval Surface Warfare Center Dahlgren Div
b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See Instructions)
N00178
c. ADDRESS (Include ZIP Code) 6097 Tisdale Road Ste. 307 Dahlgren, VA 22448-5156
d. POC NAME
Frank Lagano
e. POC TELEPHONE (Include Area Code)
+1 (540) 653-6290
f. EMAIL ADDRESS (See Instructions) frank.lagano@navy.mil
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See Instructions)
Malaguti, Sherrie
b. TITLE
Security Contracting Officer
c. ADDRESS (Include ZIP Code) Naval Surface Warfare Center, Dahlgren Division 6146 Tisdale Road, Suite 237 Dahlgren, VA 22448-5158
d. AAC OF THE CONTRACTING OFFICE (See Instructions)
N00178
e. CAGE CODE OF THE PRIME CONTRACTOR
(See Instructions.)
N/A
f. TELEPHONE (Include Area Code)
+1 (540) 653-2487
g. EMAIL ADDRESS (See Instructions) sherrie.malaguti@navy.mil
h. SIGNATURE
i. DATE SIGNED (See Instructions)
20190306
PREVIOUS EDITION IS OBSOLETE. Page 4 of 4
AEM LiveCycle Designer
DD FORM 254, APR 2018
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
a. CONTRACTOR
b. SUBCONTRACTOR
c. COGNIZANT SECURITY OFFICE FOR PRIME AND
SUBCONTRACTOR
d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY
ADMINISTRATION
e. ADMINISTRATIVE CONTRACTING OFFICER
f. OTHER AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)
UNCLASSIFIED
BIDDING 012-19
CONTINUATION – DD FORM 254 ITEM 13
ADDITIONAL SECURITY GUIDELINES FOR COMSEC
Contractor Generated COMSEC Material: Any material generated by the contractor (including but not limited to: correspondence, drawings, models, mockups, photograph, schematics, status programs and special inspection reports, engineering notes, computation and training aids) will be classified according to its own content. Classification guidance will be taken from other elements of this Contract Security Classification Specification, DD Form 254, Government furnished equipment or data, or special instructions issued by the Contracting Officer, or his/her duly appointed representative.
REQUIREMENTS
1. Contractor employees or cleared commercial carriers shall not carry classified COMSEC material on commercial passenger aircraft anywhere in the world without the approval of the procuring contracting officer.
2. No contractor generated or government furnished material may be provided to the Defense Technical Information Center (DTIC).
Contractor generated technical reports will bear the statement “Not Releasable to the Defense Technical Information Center per DOD Directive 5100-38.”
3. Classified paper COMSEC material may be destroyed by burning, pulping or pulverizing. When a method other than burning is used, all residues must be reduced to pieces 5 mm or smaller in any dimension. When classified COMSEC material other than paper is to be destroyed, specific guidance must be obtained from the User Agency.
4. The following Downgrading and Declassification notation applies to all classified COMSEC information provided to and generated by the contractor:
DERIVED FROM: NSA/CSS Classification Guide, dated 30 Sep 2013, revised 23 May 2014 DECLASSIFY ON: (calculate declassification date that is 25 years from the date of the source) DATE OF SOURCE: (Date of document from which information is derived)
5. All contractor personnel to be granted access to classified COMSEC information must be U.S. citizens granted FINAL clearance by the government prior to being given access. Immigrant aliens, interim cleared personnel, or personnel holding a contractor granted CONFIDENTIAL clearance are not eligible for access to classified COMSEC information released or generated under this contract without the express permission of the Director, NSA.
6. Unclassified COMSEC information released or generated under this contract shall be restricted in its dissemination to personnel involved in the contract. Release in open literature or exhibition of such information without the express written permission of the Director, NSA, is strictly prohibited.
7. Recipients of COMSEC information under this contract may not release information to subcontractors without permission of the User Agency.
8. The requirements of NSA/CSS Policy Manual 3-16, dated 23 January 2015 are applicable to this effort.
9. Additional notices to be affixed to the cover and title or first page of contractor generated COMSEC documents:
a. “COMSEC MATERIAL – ACCESS BY CONTRACTOR PERSONNEL RESTRICTED TO U.S. CITIZENS HOLDING A FINAL
GOVERNMENT CLEARANCE.”
b. “THIS PUBLICATION OR INFORMATION IT CONTAINS MAY NOT BE RELEASED TO FOREIGN NATIONALS WITHOUT PRIOR SPECIFIC APPROVAL FROM THE DIRECTOR, NSA. ALL APPROVALS WILL IDENTIFY THE SPECIFIC INFORMATION AND COPIES OF THIS PUBLICATION AUTHORIZED FOR RELEASE TO SPECIFIC FOREIGN HOLDERS. ALL REQUESTS FOR ADDITIONAL
ISSUANCES MUST RECEIVE PRIOR SPECIFIC APPROVAL FROM THE DIRECTOR, NSA.”
CONTINUATION – DD FORM 254 BLOCK 13
BLOCK 13 CONTINUATION STATEMENTS:
1. CLASSIFIED OR UNCLASSIFIED TECHNICAL PAPERS TO BE PRESENTED AT A
CLASSIFIED SYMPOSIUM MUST BE APPROVED BY THE NSWCDD CONTRACTING
OFFICER'S REPRESENTATIVE PRIOR TO THE PRESENTATION.
2. SECURITY CLASSIFICATION GUIDES (SCG’s) AND UNCLASSIFIED LIMITED DOCUMENTS
(E.G., FOUO, DISTRIBUTION STATEMENT CONTROLLED) ARE NOT AUTHORIZED
FOR PUBLIC RELEASE; THEREFORE, THEY CAN NOT BE POSTED ON A PUBLICLY
ACCESSIBLE WEB SERVER OR TRANSMITTED OVER THE INTERNET UNLESS
APPROPRIATELY ENCRYPTED. REQUEST FOR PUBLIC RELEASE CANNOT BE
TRANSMITTED VIA THE INTERNET UNTIL THE CONTRACTOR RECEIVES FINAL
APPROVAL FROM THE COR.
3. ALL CONTRACTOR REQUESTS FOR SHARING OF CLASSIFIED AND OTHER
SENSITIVE INFORMATION BETWEEN PRIME CONTRACTS MUST BE FORWARDED IN
WRITING TO THE NSWCDD SECURITY OFFICE POC IDENTIFIED IN BLOCK 16 OF THIS
FORM FOR APPROVAL.
4. PERSONNEL DESIGNATED AS DERIVATIVE CLASSIFIERS SHALL RECEIVE DERIVATIVE
CLASSIFICATION TRAINING PRIOR TO ACCESS FROM THE CONTRACTOR'S FACILITY
SECURITY OFFICER (FSO). THE FSO SHALL ENSURE PERSONNEL RECEIVE INITIAL AND
BIENNIAL TRAINING DURING THE LIFE OF THIS CONTRACT. EVIDENCE OF COMPLETION,
TRAINING CERTIFICATES OR EQUIVALENT, SHALL BE PROVIDED TO THE INFORMATION
ASSURANCE MANAGER NO LATER THAN THE INDIVIDUAL'S DUE DATE.
5. ALL CLASSIFIED DOCUMENTS MUST BE DESTROYED USING A NATIONAL SECURITY
AGENCY (NSA) APPROVED HIGH SECURITY CROSSCUT SHREDDER LISTED ON THE
NSA/CSS EVALUATED PRODUCTS LIST(EPL) FOR HIGH SECURITY CROSSCUT PAPER
SHREDDERS, OR OTHER APPROVED METHOD FOR DESTROYING CLASSIFIED
INFORMATION.
6. ALL CLASSIFIED INFORMATION INVOLVED IN SECURITY INCIDENTS SHALL BE RETAINED
AND PROVIDED TO THE CERTIFYING OFFICIAL IN ITEM 16 OF THIS DD 254 FOR
CLASSIFICATION REVIEW.
7. ALL SECURITY RELATED ISSUES, INCIDENTS, OR REQUESTS PERTAINING TO THIS
CONTRACT SHALL BE PRESENTED IN WRITING BY THE CONTRACTOR'S FACILITY
SECURITY OFFICER (FSO) TO THE INDIVIDUAL IDENTIFIED IN BLOCK 16(A) OF THIS
DD254. THE CONTRACTOR SHALL ABIDE BY OTHER REPORTING REQUIREMENTS
OUTLINED IN THE NISPOM.
8. FORWARD A COPY OF SUBCONTRACTOR DD 254S ISSUED UNDER THIS CONTRACT TO
THE OFFICIAL SHOWN IN ITEM 16 OF THIS DD254.
DODM 5200.01, VOL IV
24 FEB 2012
CONTROLLED UNCLASSIFIED INFORMATION (CUI)
1. DEFINITION. Controlled Unclassified Information is defined as unclassified information meeting standards for safeguarding and dissemination controls pursuant to law, regulations, and government-wide policies under Executive Order 13556, which establishes a uniform program for designation of information meeting the standards for CUI, uses standardized marking, and ensures information is only controlled when needed.
2. CATERGORIES OF CUI. CUI consists of the following;
For Official Use Only (FOUO) information;
Privacy Act Information (See PII attachment);
Department of State Sensitive But Unclassified (SBU) information;
Department of Defense (DoD) and Department of Energy (DoE) Unclassified Controlled Nuclear Information (UCNI);
Drug Enforcement Administration (DEA) Sensitive Information;
Foreign Government Information (FGI);
Unclassified Navy Nuclear Propulsion Information (U-NNPI); and
National Geospatial Intelligence Agency Limited Distribution Information
3. GENERAL GUIDANCE: Controlled Unclassified Information (CUI) such as FOUO, Security Classification Guides (SCG), and other information with Distribution Statements B thru F, are not authorized for public release and cannot be placed on a publicly accessible web site or web server.
a. Distribution statements for classified documents will be determined by the Security Classification Guide used to mark the document.
b. All technical data provided to the contractor by the government will be protected from public disclosure in accordance with the markings contained therein.
c. Any material produced under the terms of this contract will be classified directly from the source document(s) from which it was obtained. It will be marked with the most restrictive downgrading/declassification statement contained in such documents.
4. TRANSMITTAL. All emails containing such information or attachments must be appropriately marked, and digitally signed and encrypted if being transmitted within Navy networks, or outside a Navy network to an approved contractor email address. All transmissions to personal email accounts (AOL, Yahoo, Hotmail, Comcast, etc.) are prohibited.
5. OFFSITE HANDLING. The contractor shall provide adequate physical protection to such information as to preclude access by any person or entity not authorized such access by the government.
6. DISCLOSURE POLICY: All other information relating to the items to be delivered or services to be performed under this contract may not be disclosed by any means without prior approval of the authorized representative of the contracting officer. Dissemination or public disclosure includes, but is not limited to, permitting access to such information by foreign nationals or by any other person or entity; publication of technical or scientific papers; advertising; or any other proposed public release. Due to the sensitivity of this program, no classified material received or generated under this contract will be transferred to any other contractor or agency without the approval of the Contracting Officer or Contracting Officer’s Representative (COR).
7. FACILITY VISITS: All visit requests for contractor personnel visiting NSWCDL shall meet the following requirements;
a. Requests must be sent through the Joint Personnel Adjudication System (JPAS), under SMO code 001785 for GENSER and 001783 for SCI.
b. Visit requests for Contractor Personnel not submitted via JPAS shall be faxed to the COR, TPOC or the respective department administrative office no later than five (5) working days prior to the intended visit for NEED-TO-KNOW certification. All requests shall contain the information required by Chapter 6, NISPOM, and shall not exceed 12 months.
c. Visit requests for subcontractors to other activities will have a NEED-TO-KNOW certified by the prime contractor.
d. Information on this contract is not releasable to personnel possessing limited (reciprocal) clearances without the written approval of NSWCDD.
Additional guidance can be found at DODM 5200.01, VOL IV.
INNOVATION LAB SUPPORT
STATEMENT OF WORK (SOW)
1.0 BACKGROUND
The Naval Surface Warfare Center, Dahlgren Division (NSWCDD), Innovation Lab (iLab) has acquired a variety of technology and collaboration tools that require specialized support to keep the technology systems operational and users trained on their use.
The iLab is built around a modern Audio/Visual (A/V) system, the
Bluescape collaboration controller and associated touch monitor/cloud environment, as well as several disparate visualization and prototype tools such as the Microsoft hololens, the multi-user Colossus table and 3D plastic/metal printers as well as new 3D scanning capabilities. NSWCDD has invested a substantial amount of time and money into a collaboration tool called Bluescape which we are now implementing into a Cloud environment to allow collaboration across NSWCDD and the NR&DE. This SOW is to secure on-site
Bluescape Cloud Integration Management support.
2.0 APPLICABLE DOCUMENTS
2.1 SECNAV M-5239.2, Department of the Navy Cyberspace
Information Technology and Cybersecurity Workforce Management and Qualification Manual dated June 2016;
2.2 Original Equipment Manufacturer (OEM) Specifications;
2.3 Department of Defense (DoD) 5400.7-R, DoD Freedom of
Information Act Program, Chapters 3 and 4;
2.4 NAVADMIN 216/15, Cyber Hygiene Authorization to use
Personal Wearable Fitness Devices (e.g., FitBit, Jawbone UP, etc.) in Navy Spaces, dated 14 September 2015.
2.5 SECNAVINST 1543.2, Cyberspace/Information Technology
Workforce Continuous Learning, dated 30 November 2012.
3.0 REQUIREMENTS
3.1 The contractor shall administer Bluescape Software as
follows:
3.1.1 Act as the Navy Bluescape Organization owner;
3.1.2 Manage user account approvals, creations, and deletions;
and
3.1.3 Provide Bluescape Workspace Creation and Maintenance.
3.2 The contractor shall support the cloud instance of
Bluescape through the deployment, integration, use, and updates required for full and uninterrupted software use/access.
3.3 The contractor shall support the iLab Bluescape
Collaboration Cloud Environment as follows:
3.3.1 Maintain and manage the operation and use of the
Bluescape environment daily and during iLab activities;
3.3.2 Maintain and adjust for unique configurations and
applications to support the variety of uses in the iLab.
3.3.3 Administer routine upgrades and minor modifications; and
3.3.4 Provide basic troubleshooting.
3.3.5 Provide basic deployment support to other NSWCDD
organizations obtaining/joining the Bluescape Environment.
3.4 The contractor shall provide the following Bluescape
training throughout the period of performance to be coordinated with the technical point of contact identified below:
3.4.1 “Bluescape Portal and Access” Training;
3.4.2 “Workspace Creation” Training;
3.4.3 “Features and Capabilities” Training;
3.4.4 “Inviting and Sharing with Others” Training;
3.4.5 Visual Methodology and Template Training (Bluescape Live
Training, Program Management, Engineering Management, Visual
Intelligence);
3.5 The contractor shall comply with the Department of
Navy(DON) Cyberspace Information Technology (IT) / Cybersecurity
Workforce (CSWF) Program requirements of SECNAV M-5239.2, which includes:
3.5.1 Earn and maintain appropriate credentials from the Cyber
IT/CSWF Qualification Matrix, described in SECNAV M-5239.2, associated with the specialty area and level commensurate with the scope of major assigned duties for the position to which you are assigned, and
3.5.2 Participate in a continuous learning program as described in SECNAVINST 1543.2 to include a minimum of 40 hours of Cyber
IT/CSWF related continuous learning annually.
4.0 DELIVERABLES
The contractor shall provide reports in accordance with CDRL
A001.
5.0 TRAVEL
The contractor will be required to travel in performance of this contract. The number of trips and types of personnel traveling shall be limited to the minimum required to accomplish work requirements and shall be coordinated with the technical point of contact. All travel shall be conducted in accordance with the
Federal Travel Regulations (FTR). The following travel is anticipated: Two (2) personnel to NSWCDD located in Dahlgren, Virginia throughout the period of performance as well as the following anticipated travel:
Personnel Warfare Center Division/Location Number of Days
2 Carderock - West Bethesda, MD 2
2 Corona - Norco, CA 2
2 Indian Head – Indian Head, MD 2
2 Dam Neck – Norfolk, VA 3
2 Crane – Crane, IN 3
2 Panama City – Panama City, FL 3
2 Philadelphia – Philadelphia, PA 3
2 Port Hueneme – Port Hueneme, CA 3
2 Keyport – Mechanicsburg, PA 3
2 Newport – Newport, RI 3
6.0 SECURITY
6.1 Daily Onsite Contractor personnel shall possess, at a
minimum, at the time of contract award, a SECRET (S) clearance based on a T3 investigation completed within the last 10 years.
Interim clearances are acceptable. All Key personnel (Those performing short term duties to include Bluescape deployment) performing under this order shall possess, at a minimum, a DoD
Security Clearance of SECRET within ninety-days (90) after
Contract award.
6.1.2 Contractor personnel with privileged user access to
Bluescape require DOD Directive 8570.01M or its successor certification(s)/qualifications to be maintained throughout the performance of this contract.
6.1.3 The Contractor shall have access to information and
compartments up to SECRET classification to complete tasking previously described in this SOW. The contractor will also require access to SIPRNET in support of this contract.
6.1.4 All deliverables associated with this contract are
unclassified unless otherwise specified. Access to classified spaces and material and generation of classified material shall be in accordance with the attached DD Form 254.
Contractors will require access to Communications Security (COMSEC) Information and North Atlantic Treaty Organization
(NATO) Information.
Contractors will require access to classified information only at another contractor’s facility or a government activity. There is no requirement for safeguarding classified material at the contractor's facility.
6.4 CONTROLLED UNCLASSIFIED INFORMATION (CUI): For Official
Use Only (FOUO) and Personally Identifiable Information (PII) generated and/or provided under this contract shall be safeguarded and marked as specified in DoD 5400.7-R Chapters 3 and 4.
6.5 FACILITY CLEARANCE (FCL)
The Contractor shall possess and maintain a SECRET facility clearance as verified within the Industrial Security Facility
Database.
6.6 ELECTRONIC SPILLAGES (ES): Electronic Spillages are
unacceptable and pose a risk to national security. An electronic spillage is defined as classified data placed on an information system (IS), media or hardcopy document possessing insufficient security controls to protect the data at the required classification level, thus posing a risk to national security
(e.g., sensitive compartmented information (SCI) onto collateral, Secret onto Unclassified, etc.). The Contractor's performance as it relates to ES will be evaluated by the
Government. ES reflects on the overall security posture of
NSWCDD and a lack of attention to detail with regard to the handling of classified information of IS security discipline and will be reflected in the Contractor's CPARS performance rating.
In the event that a Contractor is determined to be responsible for an ES, all direct and indirect costs incurred by the
Government for ES remediation will be paid by the Contractor.
6.6.1 NSWCDD Security will continue to be responsible for the corrective action plan in accordance with the security guidance reflected on the DOD Contract Security Classification
Specification - DD Form 254. NSWCDD Security will identify the
Contractor facility and contract number associated with all electronic spillages during the investigation that involve
Contractor support. NSWCDD Security will notify the Contracts
Division with the Contractor facility name and contract number, incident specifics and associated costs for clean-up. The
Contracting Officer will be responsible to work with the
Contractor Facility to capture the costs incurred during the spillage clean up. The Contractor is also responsible for taking
Information Security Awareness training within 30 days of contract award and annually thereafter, via their Facility
Security Officer (FSO), as part of the mandatory training requirements. If a spillage occurs additional training will be required to prevent recurrence.
6.7 CYBER SECURITY WORKFORCE: IAW DOD/DON CSWF requirements, contractors assigned to an IT Level-I designated position with
SECRET access will be required to have a favorably adjudicated
T5 investigation completed every 5 years. This investigation will be at the government's expense and will be initiated by the
Government. Until such time the T5 is favorably adjudicated, the
Contractor must remain at IT Level-II status in JPAS/DISS and will not be assigned Level-I duties.
6.8 PORTABLE ELECTRONIC DEVICES (PEDS):
6.8.1 Non-Government and/or personally owned portable
electronic devices (PEDs) are prohibited in all NSWCDD buildings with the exception of personally owned cell phones which are authorized for use in spaces up to, and including, Controlled
Access Areas. The Contractor shall ensure the onsite personnel remain compliant with this PED policy. NSWCDD instruction defines PEDs as the following: any electronic device designed to be easily transported, with the capability to store, record, receive or transmit text, images, video, or audio data in any format via any transmission medium. PEDs include, but are not limited to, pagers, laptops, radios, compact discs and cassette players/recorders. In addition, this includes removable storage media such as flash memory, memory sticks, multimedia cards and secure digital cards, micro-drive modules, ZIP drives, ZIP disks, recordable CDs, DVDs, MP3 players, iPADs, digital picture frames, electronic book readers, kindle, nook, cameras, external hard dish drives, and floppy diskettes.
6.8.2 PED’s belonging to an external organization shall not be connected to NSWCDD networks or infrastructure without prior approval from the NSWCDD Information Assurance and Compliance
Branch. This approval will be granted using the TARIS form and action tracker process.
6.8.3 Personally owned hardware or software shall not be
connected or introduced to any NSWCDD hardware network or information system infrastructure.
6.8.4 Personal Wearable Fitness Devices (PWFDs) marketed
primarily as fitness or sleep devices are allowed in all Navy spaces where collateral non-Sensitive Compartmented Information
(SCI), classified information is processed, stored, or discussed up to and including secret. User must ensure PWFD is compliant with all requirements in NAVADMIN 216/15, Cyber Hygiene
Authorization to use Personal Wearable Fitness Devices (e.g., FitBit, Jawbone UP, etc.) in Navy Spaces, dated 14 September
2015 and register PWFD in the NSWCDD Fitness Device Tracker.
6.9 OPERATIONS SECURITY (OPSEC): All Contractors (including
Subcontractors) shall supplement their current security practices by requiring any personnel involved in executing this contract to complete Government-sponsored and administered
Operations Security (OPSEC) training. In addition, all
Contractors should be aware of the Critical Information List
(CIL) for the department they are supporting as well as the
OPSEC plan for NSWCDD. Upon contract award, all identified
Contractors, including Subcontractors, shall sign a Contractor's conformance statement and submit it to the NSWCDD COR named in block 13 of the attached DD-254 thereby acknowledging that they will meet the requirements of this contract. The COR shall contact their Department Training Coordinator to schedule key employees to attend the Government-sponsored OPSEC training.
The Contractor must immediately notify the Government upon the discovery of any nonconformance with the OPSEC Plan.
6.10 INFORMATION SECURITY AND COMPUTER SYSTEM USAGE: In
accordance with U.S. Navy policy, any personnel, including the
Contractor, who utilizes DoD-owned systems, shall assume responsibility for adherence to restrictions regarding internet and e-mail usage. Navy policy prohibits racist, sexist, threatening, pornographic, personal business, subversive or politically partisan communications. All personnel, including the Contractor, are accountable and must act accordingly. DoD computer systems are monitored to ensure that the use is authorized, to facilitate protection against unauthorized access, and to verify security procedures, survivability and operational security. During monitoring, information may be examined, recorded, copied, and used for authorized purposes.
All information, including personal information, placed on or sent over a DoD system may be monitored. Use of a DoD system constitutes consent to monitoring. Unauthorized use may result in criminal prosecution. Evidence of unauthorized use collected during monitoring may be used as a basis for recommended administrative, criminal or adverse action.
6.11 USE OF INFORMATION SYSTEM (IS) RESOURCES: Contractor
Provision of IS Resources Except in special circumstances explicitly detailed elsewhere in this document, the Contractor shall provide all IS resources needed in the performance of this contract. This includes, but is not limited to computers, software, networks, certificates, and network addresses.
Contractor Use of NSWCDD IS Resources in the event that the
Contractor is required to have access to NSWCDD IS resources, the login name used for access shall conform to the NMCI login naming convention. If the Contractor requires access to applications/systems that utilize client certificates for authentication, the Contractor is responsible for obtaining requisite certificates from a DoD or External Certificate
Authority. If this contract requires that the Contractor be granted access and use of NSWCDD IS resources (at any site), the
IS shall be accredited for Contractor use in accordance with procedures specified by the Information Assurance Office.
Connections between NSWCDD and Contractor Facilities. If there is a requirement (specifically delineated elsewhere in this contract) for interconnection (e.g., link level or Virtual
Private Network (VPN)) between any facilities and/or ISs owned or operated by the Contractor and ISs owned or operated by
NSWCDD, such interconnection shall take place only after approval from the NSWCDD Information Assurance Office. All such connections as well as the ISs connected thereto will be accredited in accordance with DoD policy (DoDI 5200.40) by the cognizant Designated Approving authority (DAA) and comply with the requirements of CJCSI 6211.02B regarding Memorandums of
Agreement. All such connections will be made outside the appropriate NSWCDD firewall.
6.12 VISITS BY FOREIGN NATIONALS AND FOREIGN REPRESENTATIVES:
6.12.1 Contract performance may require that the Contractor
host, at an off-base location, foreign nationals and/or foreign representatives. A foreign national is a person who is a citizen of a foreign nation, and who is not a citizen of the United
States. A foreign representative is a person who represents a foreign interest in dealings with the U.S. Government, either directly or through dealings with a U.S. Government Contractor.
A foreign representative may be a United States citizen. A
Contractor-hosted visit of a foreign national or foreign representative may be either an “official” visit or an
“unofficial” visit. An official visit is a visit where the foreign national or foreign representative is representing a foreign government in an official capacity. An unofficial visit is a visit where the foreign national or foreign representative is not representing a foreign government.
6.12.2 A visit by a foreign national or a foreign
representative may be either “DoD Sponsored” or “Non-DoD
Sponsored”. A DoD Sponsored visit is a visit that is coordinated by a DoD entity. A Non-DoD Sponsored visit is a visit that does not involve DoD coordination (A visit by either a foreign national or a foreign representative pursuant to performance by the Contractor under this contract is not considered to be, by itself, a sponsored visit). The Contractor hosting a visit by either a foreign national or a foreign representative is responsible for adherence to Department of Defense and
Department of the Navy directives, instructions, regulations, and manuals that govern foreign disclosure. “Foreign Disclosure” is defined as the disclosure of Classified Military Information
(CMI) and Controlled Unclassified Information (CUI) to foreign nationals and/or foreign representatives. Disclosure of such information may be accomplished orally, visually, in writing, or by any other medium.
6.12.3 Classified Military Information (CMI). This is
information that is originated by or for the Department of
Defense, or a Military Department, or an entity under its jurisdiction and control, and which requires protection in the interest of national security. Such information is designated as
TOP SECRET, SECRET, or CONFIDENTIAL. Controlled Unclassified
Information (CUI). This is information that although unclassified is subject to access or distribution limitations in accordance with statute or regulation. Included is information exempt from mandatory release to the public under the Freedom of
Information Act, or information that is subject to export control. Naval Surface Warfare Center Dahlgren Division (NSWCDD)
Foreign National Visitor and Foreign Disclosure Application process. The NSWCDD has established a foreign national visitor approval and foreign disclosure process. Whenever, pursuant to the terms of this contract, a visit to a Contractor facility or
Contractor workspace by a foreign national or foreign representative is anticipated, and one or more NSWCDD employees will be in attendance at this visit/meeting for the purpose of potential discussions, above the public release level, resulting in disclosure of either CMI or CUI, a completed “NSWCDD Foreign
National Visitor and Foreign Disclosure Application” e-form must be supplied to the Contractor’s Facility Security Officer (FSO).
The accountable NSWCDD personnel attending the meeting must ensure that the NSWCDD disclosure process has been complied with and an approved copy of the “NSWCDD Foreign National Visitor and
Foreign Disclosure Application” generated e-form has been provided to the COR and the Contractor’s FSO. The Contractor’s
FSO should ensure that approved copies of the e-form are maintained at their facility as a record of compliance with requirements set forth in the National Industrial Security
Program Operating Manual (NISPOM) as well as the requirements set forth above.
6.13 IDENTIFICATION BADGES: The Contractor shall be required to obtain identification badges from the Government for all
Contractor personnel to be located on Government property. The identification badge shall be visible at all times while employees are on Government property. The Contractor shall furnish all requested information required to facilitate issuance of identification badges and shall conform to applicable regulations concerning the use and possession of the badges. The Contractor shall be responsible for ensuring that all identification badges issued to Contractor employees are returned to the appropriate Security Office within 48 hours following completion of the Task Order, relocation, reassignment, or termination of an employee, and upon request by the Procuring Contracting Officer.
6.14 NON-DISCLOSURE AGREEMENTS (NDAs): NDAs may be utilized to allow for access to company sensitive/proprietary data. For tasks requiring NDAs the Contractor shall obtain appropriate agreements for all of their employees that are associated with the task requiring such an agreement. The labor categories listed in Section H may be required to sign non-disclosure statements as applicable to specific tasking. The COR will notify the Contractor that will need to sign the NDAs. The signed NDAs shall be executed prior to accessing data or providing support for information that is considered business or program sensitive and returned to the COR for endorsement and retention. Copies of all executed NDAs shall be provided to the
COR and the Contract Specialist.
6.15 CONTROL OF CONTRACTOR PERSONNEL: The Contractor shall
comply with the requirements of NAVSEA and NSWCDD instructions regarding performance in Government facilities. All persons engaged in work while on Government property shall be subject to search of their persons (no bodily search) and vehicles at any time by the Government, and shall report any known or suspected security violations to the appropriate Security Department.
Assignment, transfer, and reassignment of Contractor personnel shall be at the discretion of the Contractor. However, when the
Government directs, the Contractor shall remove from contract performance any person who endangers life, property, or national security through improper conduct. All Contractor personnel engaged in work while on Government property shall be subject to the Standards of Conduct contained in SECNAVINST 5370.2J.
7.0 TECHNICAL POINT OF CONTACT (TPOC)
Frank Lagano, 00T frank.lagano@navy.mil
540.653.6290 mailto:frank.lagano@navy.mil
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of AEM LiveCycle Designer
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.