DD254 attachment-New NASP Studies MAC Program_extension pages.pdf

PDF 520 KB Posted

Attached to
Navy Analytic Studies Program Federal contract opportunity
Solicitation number
N0018920RZ012
Issued by
Department of the Navy Naval Supply Systems Command

About this file

This document is a continuation page for a DD254 security classification specification related to solicitation number N0018920RZ012 from the Department of the Navy Naval Supply Systems Command for analytic studies support services. The contractor will be required to protect classified, controlled unclassified, and critical unclassified information in accordance with Department of Defense and Navy security regulations. The contractor must implement operations security countermeasures and protect critical information related to the performance of the statement of work. Subcontractors will also be required to follow all security requirements.

View the file

Other files for this federal contract opportunity

Other files attached to Navy Analytic Studies Program, newest first.
File Type Posted
N0018920RZ012-0005.docx DOCX document
N0018920RZ012-0004.docx DOCX document
N0018920RZ012-Conformed Copy of RFP after Amendment 0004.docx DOCX document
N0018920RZ012-0001.docx DOCX document
N0018920RZ012-0002.docx DOCX document
N0018920RZ012-0003.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

UNCLASSIFIED CONTINUATION – DD FORM 254 ITEM 13

Navy Analytic Studies Multiple CONTRACT # TBD ECD 20251031 Award Contract (MAC) Program Continuation Page 1 of 5

UNCLASSIFIED

BLOCK 10a. continued: Classified COMSEC material is not releasable to contractor employees who have not received a FINAL Clearance at the appropriate security level. COMSEC access shall be in accordance with (IAW) DoD 5220.22-M (NISPOM). COMSEC information and materials are subject to the controls of and restrictions specified in the National Security Agency/Central Security Service Policy Manual 3-16, Control of Communications Security (COMSEC) Material, August 2005. When access is required at government facilities, contractor personnel will adhere to COMSEC rules and regulations as mandated by command policy and procedures. 10e. continued: DSS is relieved of security inspection responsibility for all such material but retains responsibility for all non-SCI classified material released to or developed under this contract.

10g. continued: NATO information is information belonging to, and circulated by, the North Atlantic Treaty Organization (NATO). Special briefings are required for access to NATO. Access to classified NATO information requires a final U.S. Government clearance at the appropriate level. Prior approval of the contracting activity is required for subcontracting. Prior approval of by the NATO Control Officer (NCO) or alternate is required before the prime contractor or the subcontracting facility can be granted access to or store NATO material at their facility.

Personnel not assigned to a NATO staff position, but requiring access to NATO COSMIC or NATO Secret, or access to the NATO accredited SIPRNET terminals, must possess the equivalent FINAL U.S. Security Clearance based upon the appropriate personnel security investigation required. Personnel with access to NATO ATOMAL information must have a FINAL U.S. Security Clearance.

10j. continued: Controlled Unclassified Information (CUI) is UNCLASSIFIED information which is exempt from disclosure to the public under the Freedom of Information Act (FOIA). The FOIA spells out the specific requirements for designation of data as For Official Use Only (FOUO). CUI under this contract shall be safeguarded as specified in DoD Manual 5200.01, Vol. 4 “DoD Information Security Program: Controlled Unclassified Information (CUI)”. The destruction of CUI information related to this contract will be in accordance with requirements established for destruction of sensitive, unclassified information.

11c. continued: All classified information must be marked in accordance with Executive Order (EO) 13526 "Classified National Security Information", of 29 Dec 2009, SECNAV manual 5510.36 of 30 June 2006, and SECNAVINST 5510.36a of 06 Oct 2006, along with CNO LTR N09N2/8U223000 dtd 07 Jan 2008.

Accredited Information System (AIS) with unattended processing in a closed area is required. Classified IT (computer) processing shall be in accordance with the provisions of the NISPOM, Chapter 8, and must be performed on an accredited computer system approved by DSS. All technicians as well as any other contractor personnel requiring access to IT government systems must be U.S. Citizens and meet the security clearance access requirements of the site. Only persons actually performing classified tasks on this contract shall be cleared to the appropriate level in accordance with the NISPOM.

11d. continued: Approximately no more than 12 cubic feet of storage will be required on this contract.

Accredited Information System (AIS) with unattended processing in a closed area is required. Classified IT (computer) processing shall be in accordance with the provisions of the NISPOM, Chapter 8, and must be performed on an accredited computer system approved by DSS. All technicians as well as any other contractor personnel requiring access to IT government systems must be U.S. Citizens and meet the security clearance access requirements of the site. Only persons actually performing classified tasks on this contract shall be cleared to the appropriate level in accordance with the NISPOM.

Award Contract (MAC) Program Continuation Page 2 of 5

11g. continued: The contractor is authorized the use of DTIC regarding specific contract related information and will prepare and process DD Form 1540 in accordance with the NISPOM, Chapter 11, Section 2. The COR will certify need-to-know with DTIC.

11j. continued: The contractor will accomplish the following minimum requirements in support of the NAVSUP Operations Security (OPSEC) program: The contractor shall document items of critical information applicable to contractor operations involving information on or related to the PWS/SOW. Contractor is responsible to adequately protect government designated critical information, and to determine and protect critical information generated by the contractor using guidance and meeting requirements outlined in the OPSEC attachment. All OPSEC requirements must be passed to all subcontractors. See Continuation Pages 4-5, below.

11k. continued: The contractor shall make arrangements to use the services of the Defense Courier Service (DCS) for transportation of qualified material. Contractor use shall be in accordance with the DoD 5220.22-M (Reference (g)) and DoD Instruction 5200.33, Defense Courier Operations (DCO). DoD Directive 5200.33 is located at http://www.dtic.mil/whs/directives/corres/pdf/520033p.pdf.

11l. continued: CUI under this contract shall be safeguarded as specified in DoD Manual 5200.01, Vol. 4 “DoD Information Security Program: Controlled Unclassified Information (CUI)”. The destruction of CUI information related to this contract will be in accordance with requirements established for destruction of sensitive, unclassified information.

11m. continued: Classified IT (computer) processing shall be IAW the provisions of the NISPOM, Chapter 8, and must be performed on an accredited computer system approved by DSS. All technicians as well as any other contractor personnel requiring access to IT government systems must be U.S. Citizens and meet the security clearance access requirements of the site. Only persons actually performing classified tasks on this contract shall be cleared to the appropriate level IAW the NISPOM. Accredited Information System (AIS) with unattended processing in a closed area is required and authorized.

The use of personal electronic devices and media (computer laptops, flash (thumb) drives, FITBITs or other tracking devices, or other removable drives) are prohibited in OPNAV spaces except where explicitly permitted.

All removable electronic medial must be labeled (UNCLASSIFIED, etc) to the highest classification of data stored, and/or for the classification of the system in which it is used. If classified, any removable electronic media must be tracked and stored appropriate to that level of classification. A request for use of "Medical Devices" (hearing aids, heart and blood pressure monitors) must be approved before they can be worn in a SCIF.

Block 12. continued: SUBMIT FOR PUBLIC RELEASE REQUESTS VIA APPROPRIATE PROGRAM SPONSOR, Navy, USMC, or DoD, for approval.

Block 13. continued: Transportation of classified material shall be IAW the requirements of DoDM 5200.01-V3, February 24, 2012, DoD Information Security Program: Protection of Classified Information, and the NISPOM. All DON Security Classification Guides and the DON Declassification Guide are required for performance of this contract and will be provided to the contractor by the GCA.

Contractors that have been awarded a classified contract must submit visit requests using “only” the Joint Personnel Adjudication System (JPAS). All government activities have been directed to use JPAS when transmitting or receiving Visit Authorization Letters (VAL). Contractors who work on classified contracts are

Award Contract (MAC) Program Continuation Page 3 of 5 required to have established an account through JPAS for their facility. This database contains all U.S. Citizens who have received a clearance of CONFIDENTIAL, SECRET, and/or TOP SECRET. The visit request can be submitted for one year. This information is provided in accordance with guidance provided to contractors via the Defense Security Service (DSS) website http://www.dss.mil/index.html.

NO FURTHER ENTRIES ON THIS PAGE

Award Contract (MAC) Program Continuation Page 4 of 5

Block 11.j. continued: OPERATIONS SECURITY REQUIREMENTS

All work is to be performed in accordance with DoD and Navy Operations Security (OPSEC) requirements, per the following applicable documents:

- National Security Decision Directive (NSDD) 298: National Operations Security Program

- DoD 5205.02E: DoD Operations Security (OPSEC) Program

- OPNAVINST 3432.1A: DoN Operations Security

The contractor will accomplish the following minimum requirements in support of DoN Operations Security Program:

- The contractor will practice OPSEC and implement OPSEC countermeasures to protect DoD Critical Information. Items of Critical Information are those facts, which individually, or in the aggregate, reveal sensitive details about OPNAV or the Contractor’s security or operations related to the support or performance of this PWS/SOW, and thus require a level of protection from adversarial collection or exploitation not normally afforded to unclassified information.

- Contractor must protect Critical Information and other sensitive unclassified information and activities, especially those activities or information which could compromise classified information or operations, or degrade the planning and execution of military operations performed or supported by the contractor in support of the mission. Protection of Critical Information will include the adherence to and execution of countermeasures which the contractor is notified by or provided by OPNAV, for Critical Information on or related to this PWS/SOW.

- Sensitive unclassified information is that information marked FOR OFFICIAL USE ONLY (or FOUO), Privacy Act of 1974, COMPANY PROPRIETARY, and also information as identified by OPNAV.

- OPNAV has identified the following items as Critical Information that may be related this PWS/SOW:

Known or probable vulnerabilities to any U.S. system and their direct support systems.

Details of capabilities or limitations of any U.S. system that reveal or could reveal known or probable vulnerabilities of any U.S. system and their direct support systems.

Details of information about military operations, missions and exercises.

Details of U.S. systems supporting combat operations (numbers of systems deployed, deployment timelines, locations, effectiveness, unique capabilities, etc.).

Operational characteristics for new or modified weapon systems (Probability of Kill, Countermeasures, Survivability, etc.).

Required performance characteristics of U.S. systems using leading edge or greater technology

(new, modified or existing).

Telemetered or data-linked data or information from which operational characteristics can be inferred or derived.

Test or evaluation information pertaining to schedules of events during which Critical

Information might be captured.

Existence and/or details of intrusions into or attacks against DoD Networks or Information

Systems, including but not limited to, tactics, techniques and procedures used, network vulnerabilities exploited, and data targeted for exploitation.

Network User ID’s and Passwords.

Vulnerabilities in Command processes, disclosure of which could allow someone to circumvent security, financial, personnel safety, or operations procedures.

Force Protection specific capabilities or response protocols (timelines, equipment, numbers of personnel, training received, etc.).

Award Contract (MAC) Program Continuation Page 5 of 5

Command leadership and VIP agendas, reservations, plans, routes, etc.

Detailed facility maps or installation overhead photography (photo with annotation of

Command areas or greater resolution than commercially available).

Details of COOP, OPNAV emergency evacuation procedures, or emergency recall procedures.

Government personnel information that would reveal force structure and readiness (such as recall rosters or deployment lists).

Compilations of information that directly disclose Command Critical Information.

- The above Critical Information and any that the contractor develops, regardless if in electronic or hardcopy form, must be protected by a minimum of the following:

All email containing Critical Information must be DoD Public Key Infrastructure (PKI) signed and

PKI encrypted when sent.

Critical Information may not be sent via unclassified fax.

Critical Information may not be discussed via non-secure phones.

Critical Information many not be provided to individuals that do not have a need to know in order to complete their assigned duties.

Critical Information may not be disposed of in recycle bins or trash containers.

Critical Information may not be left unattended in uncontrolled areas.

Critical Information in general should be treated with the same care as FOUO or proprietary information.

Critical Information must be destroyed in the same manner as FOUO.

Critical Information must be destroyed at contract termination or returned to the government at the government’s discretion.

- The contractor shall document items of Critical Information that are applicable to contractor operations involving information on or related to the PWS/SOW. Such determinations of Critical Information will be completed using the DoD OPSEC 5 step process as described in National Security Decision Directive (NSDD) 298, “National Operations Security Program”.

- OPSEC training must be included as part of the contractor’s ongoing security awareness program conducted in accordance with Chapter 3, Section 1, of the NISPOM. NSDD 298, DoD 5205.02E, “DoD Operations Security (OPSEC) Program”, and OPNAVINST 3432.1A, “DoN Operations Security” should be used to assist in creation or management of training curriculum.

- If the contractor cannot resolve an issue concerning OPSEC they will contact the COR (who will consult with the OPNAV OPSEC manager).

- All requirements above MUST be passed to all Sub-contractors.

NO FURTHER ENTRIES ON THIS PAGE

File details come from the government source that posted it. Updated .