Attachment 9 DD254_N65236-16-R-0021.pdf
PDF 329 KB Posted
- Attached to
- Program Support Services for DARPA's Tactical Technology Office (TTO) Federal contract opportunity
- Solicitation number
- N65236-16-R-0021
View the file
Other files for this federal contract opportunity
Show all 50
Program Support Services for DARPA's Tactical Technology Office (TTO) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
1. CLEARANCE AND SAFEGUARDING
DEPARTMENT OF DEFENSE a. FACILITY CLEARANCE REQUIRED
CONTRACT SECURITY CLASSIFICATION SPECIFICATION TOP SECRET
(The requirements of the DoD Industrial Security Manual apply
b. LEVEL OF SAFEGUARD REQUIRED to all security aspects of this effort.)
TOP SECRET
2. THIS SPECIFICATION IS FOR: (X and complete as applicable) 3. THIS SPECIFICATION IS: (X and complete as applicable)
a. PRIME CONTRACT NUMBER
a. ORIGINAL (Complete date in all cases)
DATE (YYYYMMDD)
20170405
b. SUBCONTRACT NUMBER b. REVISED I REVISION NO. DATE (YYYYMMDD) (Supercedes all previous specs)
X c. SOLICITATION OR OTHER NUMBER DUE DATE (YYYYMMDD)
c. FI NAL (Complete Item 5 in all cases)
DATE (YYYYMMDD)
N65236-16-R-0021 TBD
4. IS THIS A FOLLOW-ON CONTRACT?
LJvEs ~NO If Yes, complete the fo llowing :
Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.
5. IS THIS A FINAL DD FORM 254?
LJvEs ~NO If Yes, complete the following :
In response to the contractor's request dated , retention of the classified material is authorized for the period of
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE C. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)
7. SUBCONTRACTOR
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE C. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)
8. ACTUAL PERFORMANCE
a. LOCATION b. CAGE CODE c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)
9. GENERAL IDENTIFICATION OF THIS PROCUREMENT
TTO - SET A Support
10. CONTRACTOR WILL REQUIRE ACCESS TO: YES NO 11 . IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: YES NO
a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION X X a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER CONTRACTOR'S X
FACILITY OR A GOVERNMENT ACTIVITY
b. RESTRICTED DATA X b. RECEIVE CLASSIFIED DOCUMENTS ONLY X
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION X c. RECEIVE AND GENERATE CLASSIFIED MATERIAL X
d. FORMERLY RESTRICTED DATA X d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE X
e. INTELLIGENCE INFORMATION e. PERFORM SERVICES ONLY X
(1) Sensitive Compartmented Information (SCI) X I. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S .. PUERTO RICO, U.S. POSSESSIONS X
AND TRUST TERRITORIES
(2) Non. SCI X g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER X
SECONDARY DISTRIBUTION CENTER
I. SPECIAL ACCESS INFORMATION X h. REQUIRE A COMSEC ACCOUNT X
g. NATO INFORMATION X i. HAVE TEMPEST REQUIREMENTS X
h. FOREIGN GOVERNMENT INFORMATION X j . HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS X
i. LIMITED DISSEMINATION INFORMATION X k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE X j . FOR OFFICIAL USE ONLY INFORMATION X i. OTHER (Specify)
k. OTHER (Specify)
X X
DD Form 254, DEC 1999 Designed using Adobe, DARPA/SSO
12. PUBLIC RELEASE. Any information (classified or unclassified) pertaiing to this contract shall not be released for public dissemination except as provided by the Industria l Security Manual or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for approval prior to release D Direct [8J Through (Specify)
No information, except as prov ided in applicable U .S. Statutes, which is classified or unclass ified pertaining to this contract shall be released for public dissemination without prior written approval of DA RPA.
to the Directorate for Freedom of Information and Security Review, Office of the Assistant Secretary of Defense (Public Affairs)* for review.
*In the case of non-DoD User Agencies, requests for disclosure shall be submitted to that agency.
13. SECURITY GUIDANCE. The security classification guidance needed for this classified effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the informaiton involved shall be handeled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Add additional pages as needed to provide complete guidance.)
I Oa: Class ified COMSEC information/material will be protected IA W DoD 5220.22-M. Access to classified COM SEC information requires a fina l U.S . Government clearance at the appropriate level. In accordance with DoD5220.22-M (9-407), further disclosure ofCOMSEC information by a contractor, to include subcontracting, requires prior written approval of the DARPA, Contracting Officer fo r Security Matters. (ref. DoD 5220.22-M (Ch 9, Sec 4))
All Contractors performing on thi s contract shall abide by all current and applicable successor governmental guidance. Please contact your FSO, PSO or PSR if any questions arise pertaining to the availability of these guidance documents.
All Contractors performing on thi s contract shall abide by the Open Skies Treaty or other U.S. on-site treaty compliance obligations. In doing so, the Contractor may be required to create and execute treaty compliance plans. These plans must be approved by the cognizant Program Securi ty Officer.
Reports of loss, compromise or suspected compromise shall be provided to the appropriate DARPA Program Securi ty Officer (PSO) within 24 hours of the incident, in add ition to the reporting requirements to DSS outlined in the NISPOM.
All of the above security requirements, where applicable, wi ll flow down to any subcontractors and consu ltants supporting this contract. Copies of all subcontractor DD 254 's should be emailed to the DARPA Classification Management Office, sid-clasmgmt@darpa. mil.
TIO/PM - Mr. Jeffrey Smith, (703) 696-2305; PSO - Mr. Daniel Greenbaum, (703)526-2840; PSR - Mr. Larry McKoy, (703) 248-7209
14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to ISM requirements, are established for th is contract. ~ Yes LJ No (If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirement to the cognizant security office. Use Item 13 if additional space is needed.)
Program information shall be protected in accordance with various DARPA and other agency security classification guidance, to be provided by cognizant DARPA PSO(s).
15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the cognizant security office. ~ Yes LJ No (If Yes, explain and identify specific areas or elements carved out and the activity responsible for inspections. Use Item 13 if additional space is needed.)
SAP: DARPA is responsible fo r inspection of all SAP materials under this contract.
SCI: DI A is responsible fo r inspection of all SCI materials under thi s contract.
16. CERTIFICATION AND SIGNATURE. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.
a. TYPED NAME OF CERTIFYING OFFICIAL
Timothy Wood
d. ADDRESS (Include Zip Code)
b. TITLE c. TELEPHONE (Include Area Code)
Chief, Industrial and Information Securi ty
17. REQUIRED DISTRIBUTION
Defense A dvanced Research Proj cts Agency11DA RPA) 675 North Ran1~olph S X a. CONTRACTOR
Arlington, VA 22 b. SUBCONTRACTOR
X C. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR
a t----,,.,.,,.,..,..,..=-,----+----t----t----------------"--,
e. SIGNAATE L- v--l \ d. u.s. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION
A e. ADMINISTRATIVE CONTRACTING OFFICER
X f. OTHERS AS NECESSARY
DD Form 254 (Back), DEC 1999 Designed using Adobe, DARPA/SSO
CONTINUATION SHEET FOR DD 254, CONTRACT SECURITY CLASSIFICATION SPECIFICATION
I
CONTRACT NUMBER
N65236- I 6-R-002 I
IOe( I) : SCI Access required. The Director, DIA and Director, DARPA, have excl usive security responsibility for SCI released to the contractor or developed under this contract. Before releasing or providing SCI to contractor personnel, the GCA shall ensure that they are appropriately cleared in accordance with !CD 704, and they agree to fo llow controls and procedures for the protection, handling, and accountability of SCI. All activities involving SCI (including discussions) shall be conducted in sensitive compartmented information facilities (SC!Fs). Physical security standards for SCIFs are contained in !CD 705 must be adhered to. In accordance with DoD5220.22-M (9-304), written concurrence of the DARPA, Contracting Officer for Security Matters is required prior to subcontracting. (ref. DoDM5220.22-M (Ch 9, Sec 3)) l Oe(2): Access to Intelligence information is required for performance. The Director, DARPA, has exclusive security responsibility for Non-SCI released to the contractor or developed under this contract. In accordance with DoD5220.22-M (9-304), written concurrence of the DARPA, Contracting Officer for Securi ty Matters is required prior to subcontracting. (ref. DoDM5220.22-M (Ch 9, Sec 3))
IOf: SAP activities will be accredited, governed, maintained, marked and protected in accordance with DoDM 5205.07-Volumes (I), (3) and (4);
and applicable references. and program security classification gu ides. Access to SAP information requires employees undergo additional personnel security screen ing and meet the SAP access standards delineated in the applicable DoD directives and policies. SAP inspections and security oversight while in component faci lities are under the cognizance of the DARPA SAPCO, as appropriate. The performer is required to submit an accreditation package (Fixed Faci lity Checklists (FFC) and other applicable documents) and/or System Security Plans (SSP) to the responsible DARPA PSO via "DFASTS." Otherwise, contact your PSO for submission instructions.
Effective May l , 20 l 5 Program Access Request (PAR) packages will be coordinated using the recently approved PAR and PSQ templates. The approved templates can be found at http://www.dss.mil/isp/templates.html.
All Special Access Program (SAP) accredited areas must meet the minimum physical and technical security standards outlined in the DoD 5205.07 SAP Manual Volume 3 and its references in Enclosure l , before receiving, generat ing, processing, using, or storing SAP classified information, as appropriate to the accreditation. New SAP accredited areas will be inspected by DARPA physical security prior to accreditation. In accordance with DoDM 5205.07-V I ( 11-1 ), DARPA PSO review is required prior to release to subcontractors. (ref. DoDM 5205.07-Volumes ( I), (3) and (4)) l Oj: For Official Use Only (FOUO) Information generated and/or provided under this contract shall be safeguarded and marked as specified in DoD Manual 5200.0 1 Volume 4, DoD Information Security Program.
l le: The contractor requires access to classified source data up to and including Top Secret in support of the work effort. Classified material generated in support of this contract shall be classified in accordance with the source material used or DARPA security classification guidance, wh ich will be provided by the DARPA Program Security Officer or the Program Securi ty Representative. Automated information systems must be certified and accredited by the cognizant security agency prior to processing classified information fo r a DARPA program. All personnel performing Information Assurance ( lA)/cybersecurity related duties on DARPA accredited classified information systems shall meet the requi rements set forth in DoD Directive 8140.01 , "Cyberspace Workforce Management,"." All classified information received or generated under this contract is the property of the U.S. Government. At the termination or expiration of thi s contract, DARPA will be contacted fo r proper disposition instructions. SAP information systems will require an authorization-to-operate using the Ri sk Management Framework (RMF) process outlined in the "Joint SAP Implementation Guide (JS!G) Version 4. l , dated April I, 20 16" (or successor document).
11 g: The contractor must prepare and forward DD Forms 1540 and 2345 to the COR for authorization before the services may be requested.
Technical information on file at DT!C will be made available to the contractor if the contractor requires such information. The contracting officer will certify the field of interest relating to the contract.
11 i: Any DARPA Special Access Program (SAP) Faci lity (SAPF) that wi ll electronically process classified information must be considered for TEMPEST countermeasures by the DARPA CTTA and must meet the minimum standards outlined in the DoD 5205.07 SAP Manual Volume 3 and its References listed in Enclosure I. Only those TEMPEST countermeasures recommended by CTI A and authorized by the Program Manager or contracting authority should be implemented in accordance with DoDM 5205.07-Vol. 3. (ref. DoDM 5220.22-M (Ch 11 , Sec I); DoDM 5205.07- Vol. 3)
I lj : The contractor is required to create an OPSEC Plan or incorporate into an ex isting OPSEC Plan.
Designed using Adobe, DARPA/SSO
File details come from the government source that posted it.