About this file

This document is a draft Department of Defense (DoD) Contract Security Classification Specification (DD Form 254) for cryptographic modernization and key management engineering services. It specifies security requirements for a potential solicitation seeking these services, including a Top Secret facility clearance level with incidental access to Sensitive Compartmented Information. The prospective solicitation number is N66001-18-R-0351 and would be a follow-on to task orders N00178-14-D-4849-7N01 and 7N02 held by the incumbent, Nathan Kunes, Inc. The resulting contract would have a two-year base period and a three-year option period, with an estimated level of effort of 364,800 labor hours. The North American Industry Classification System code is 541512 and size standard is $27.5 million. The document outlines security classification guidance, access requirements, inspections, distribution, and additional security specifications for handling intelligence and other sensitive information related to the potential requirement.

View the file

Other files for this federal contract opportunity

Other files attached to Cybersecurity, Cryptographic Modernization and Key Management Engineering Services, newest first.
File Type Posted
Att 7 - Written Test Guidelines.docx DOCX document
Att 6 - Past Performance Questionnaire.pdf PDF
Att 4 - Organizational Experience Matrix.doc DOC document
Att 3 - Desired Personnel Qualifications.docx DOCX document
Att 5 - Reference Information Sheet.docx DOCX document
Att 2 - Rate Sheet.xlsx XLSX spreadsheet
N66001-18-R-0351.pdf PDF
SOW_18-R-0351_Crypto Key Management.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CLASSIFICATION (When filled in): Unclassified

18R0351

PREVIOUS EDITION IS OBSOLETE. Page 1 of 5 AEM LiveCycle Designer

DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 1 of 5 AEM LiveCycle Designer

DD FORM 254, APR 2018

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

October 31, 2020

The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED

(See Instructions)

Top Secret

b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/

MATERIAL REQUIRED AT CONTRACTOR FACILITY

None (See instructions)

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

a. PRIME CONTRACT NUMBER (See instructions.)

b. SUBCONTRACT NUMBER

c. SOLICITATION OR OTHER NUMBER

N66001-18-R-0351

DUE DATE (YYYYMMDD)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

DATE (YYYYMMDD)

20180918

b. REVISED (Supersedes all previous specifications.)

REVISION NO. DATE (YYYYMMDD)

c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)

4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:

Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.

5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:

In response to the contractor's request dated , retention of the classified material is authorized for the period of:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE

This DD 254 is for solicitation purposes only. An original DD 254 will be provided upon contract award.

b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor) Add Row Remove last Row Delete All Rows

a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

8. ACTUAL PERFORMANCE (Click button to add more locations.) Add Row Remove last Row Delete All Rows

a. LOCATION(S) (For actual performance, see instructions.)

SSC Pacific 53560 Hull Street San Diego, CA 92152-5001

b. CAGE CODE (If applicable, see Instructions.)

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

a. LOCATION(S) (For actual performance, see instructions.)

SPAWARSYSCOM, San Diego, CA and its locations NSA and its locations U.S. naval vessels

b. CAGE CODE (If applicable, see Instructions.)

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT

Cryptographic systems and solutions, key management architecture, information systems engineering and technical services. Information

18R0351

PREVIOUS EDITION IS OBSOLETE. Page 2 of 5 AEM LiveCycle Designer

DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 2 of 5 AEM LiveCycle Designer

DD FORM 254, APR 2018

assurance exploration analysis, systems, software, and test engineering services that are required to support High Assurance Internet protocol Encryptor (HAIPE), Inline Network Encryptor (INE), Link Encryption Family (LEF), cryptographic modernization, Advanced Cryptographic Capabilities (ACC), CM2, Tactical Secure Voice (TSV), Offline Network Encryption (AN/PYQ-20), Modernized Link Level COMSEC (LINK-22), Ethernet Data Encryptor (EDE), Navy Ship Site System Operational Testing (SOT) and System Operational Verification Testing

(SOVT).

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION

b. RESTRICTED DATA g. NORTH ATLANTIC TREATY ORGANIZATION

(NATO) INFORMATION

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.) h. FOREIGN GOVERMENT INFORMATION

d. FORMERLY RESTRICTED DATA i. ALTERNATIVE COMPENSATORY CONTROL MEASURES

(ACCM) INFORMATION

e. NATIONAL INTELLIGENCE INFORMATION:

(1) Sensitive Compartmented Information (SCI)

(2) Non-SCI

j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)

k. OTHER (Specify) (See instructions.)

1) NS=SCI/JWICS/NSANet/SIPRnet and 2) NATO awareness for SIPRnet access at government site.

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT

ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT

ACTIVITY

(Applicable only if there is no access or storage required at contractor facility.

See instructions.)

b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY

c. RECEIVE, STORE, AND GENERATE CLASSIFIED

INFORMATION OR MATERIAL

d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

e. PERFORM SERVICES ONLY

f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE

THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST

TERRITORIES

g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE

TECHNICAL INFORMATION CENTER (DTIC) OR OTHER

SECONDARY DISTRIBUTION CENTER

h. REQUIRE A COMSEC ACCOUNT

i. HAVE A TEMPEST REQUIREMENT

j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE

l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED

INFORMATION (CUI).

(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)

m. OTHER (Specify) (See instructions.)

See Specific On-Site attachment for reporting, security, and training requirements.

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.

Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

DIRECT THROUGH (Specify below)

Space and Naval Warfare Systems Center Pacific (SSC Pacific), Code 85000, 53560 Hull Street, San Diego, CA 92152-5001

Public Release Authority:

13. SECURITY GUIDANCE Add Signature Remove last Signature Delete All Signatures

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;

and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

Solicitation / Contract Numbers: N66001-17-R-0351 (old N66001-17-R-0187) /

Block 12 Continuation: Release of COMSEC, SCI, and NATO (Read-on IAW with the National Intelligence Security Policy Directive 17-008; NATO access is not required on this contract, see phrase 10.g/k(1)) material is not authorized.

Security Classification Guide (SCG): Work to be performed at government; SCGs to be provided under separate cover by the COR. All

18R0351

PREVIOUS EDITION IS OBSOLETE. Page 3 of 5 AEM LiveCycle Designer

DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 3 of 5 AEM LiveCycle Designer

DD FORM 254, APR 2018

classified guides will be reviewed at the government site. Information Assurance (IA) Vulnerabilities and Weaknesses (U) 3-02 dated 08 July 05 // (U) Classification Guide for Quantum Defense by NSA dated 25 May 2016 // (U) Cryptographic Modernization (CryptoMod) by NSA dated 1 February 2010 //(U) High Assurance Internet Protocol Encryptor Program (HAIPE) by NSA dated 26 June 2007.

The Code 58110 Branch Head, Kevin Chung, (619) 553-3363, email: kevin.chung@navy.mil.

Direct all Collateral Top Secret and SCI questions to the Contracting Officer's Representative (COR) Megan Kline, Code 58230,

(619) 553-6036, email: megan.kline@navy.mil.

Direct all Secret and Below questions to the COR Rebecca Hughes, Code 58006, (619) 553-9184, email: rebecca.hughes@navy.mil.

The Contract Specialist (CS) Suzanne McLaughlin, Code 22710, (619) 553-2556, email: suzanne.m.mclaughlin@navy.mil.

Prime contractor's are required to send copies of all subcontract DD Form 254s to obtain flowdown approvals as required to the distribution listed in block 17: SSC Pacific Codes 58110, and 58230/58006 (PM/CORs), 22710 (CS) see above and 83310 - Security -w_spsc_ssc_pac_securitycor_us@navy.mil. external address only.

Access Requirements:

10.a Further disclosure, to include subcontracting, of COMSEC information by a contractor requires prior approval of the SSC Pacific COR. Access to any COMSEC information requires special briefings at the contractor facility. Access to classified COMSEC information requires a final U.S. Government clearance at the appropriate level. Use of COMSEC information is governed by the NSA Industrial COMSEC Manual, NSA/CSS Policy Manual 3-16. Contractors that will be designated CMS users must attend an initial CMS user training class that is given by the SSC Pacific CMS office. If you have questions call (619) 553-5065. (Access is for COMSEC equipment/material)

10.e(1) The SSO Navy has exclusive security responsibility for all SCI classified material released or developed under this contract. DSS is relieved of security inspection responsibility for all such material but retains responsibility for all non-SCI classified material released to or developed under this contract. Further disclosure to include subcontracting of SCI is prohibited prior until approval is received from the SCI cleared SSC Pacific COR, SSC Pacific Code 874 and SSO Navy is required for sub-contracting. Special briefings and procedures are all required at the contractor's facility. Access to SCI information requires a final U.S. Government clearance at the appropriate level and will be performed within U.S. Government facilities only. Requesting approval for incidental SCI access, i.e., enter spaces, attend meetings, and briefings as long as the contractor is not producing a SCI product.

Contractor personnel assigned to this effort who require access to SCI data and spaces must possess a current SSBI with ICD 704 eligibility (which replaced DCID 6/4 eligibility).

Contract performance for incidental SCI is restricted to SSC Pacific, San Diego, CA.

10.g/k(1) Effective immediately all contractor personnel with SCI access must be read-on NATO secret with an entry into JPAS prior to being granted access. This contract requires SCI cleared personnel to access JWICS/NSAnet/SIPRnet. In addition, the contractor shall complete the derivative classification training; the special NATO briefing and derivative classification briefing are provided by the contracting company's facility security officer. This requirement is mandated per the national intelligence security policy directive 17-008.

This read-on meets the mandated requirement; however, contractor does require access to NATO on this contract. Contractor is not authorized to have NATO at its contractors facility. JWICS/SIPRnet under the SPAWAR Claimancy is not accredited to receive or process NATO restricted up to NATO secret data. Questions, contact the GCA NATO Control Office 619-553-3005/3191. Subcontract DD254s require approval from the GCA NCO prior to access being granted. Policies: USSAN 1-07 and DoD M-5200.01, Volume 1 followed.

10.j/11.l Contractors receiving, transmitting or accessing controlled unclassified technical information (CUI) on or through its contractor information system(s) must safeguard the information to avoid compromise, including but not limited to disclosure of information to unauthorized persons, unauthorized modification, destruction, or loss of an object, or the copying of information to unauthorized media, as required per DFARS Subpart 204.73 and Clauses 204.7304 and 252.204-7012. Contractors shall report to the DOD each Cyber incident that affects unclassified controlled technical information resident on or transiting contractor information systems in accordance with DFARS clause 204.7304 and 252.204-7012. Detailed reporting criteria and requirements are set forth in the clause at 252.204-7012, safeguarding of unclassified controlled technical information. For information on handling CUI see DoD M-5200.01, Volume 4.

10.k(2) Some contractor personnel that work on Top Secret and below requirements without SCI or do not require access to NATO classified data are only required to receive the NATO Awareness Brief for the sole purpose of accessing SIPRnet. The special briefing is provided by the contracting company's Facility Security Officer (FSO). Note: For this type of access, there is no requirement for the contractor to make an entry in JPAS. The contractor shall complete Derivative Classification training prior to being granted access to SIPRnet; training is provided by the company’s FSO.

11.a Contract performance is restricted to SPAWARSYSCOM, San Diego, CA, SSC Pacific, San Diego, CA, NSA, other authorized DoD locations, U.S. naval vessels, and contractors facilities. SSC Pacific-COR will provide security classification guidance for performance of

18R0351

PREVIOUS EDITION IS OBSOLETE. Page 4 of 5 AEM LiveCycle Designer

DD FORM 254, APR 2018

this contract.

11.f Access to classified U.S. government information may be required at the following overseas locations: UK, Canada, Australia, and various US Naval Ports aboard. Antiterrorism/force protection briefing within one year of departure and a country specific briefing within 90 days of departure. Anti-terrorism/force protection (AT/FP) briefings are required for all personnel (military, DoD civilian, and contractor) per OPNAVINST F3300.53C. Contractor employees must receive the AT/FP briefing annually. The briefing is available at joint knowledge online (jko): https://jkodirect.jten.mil (prefix): course number: us007; title: Level 1 Anti-terrorism awareness training, if experiencing problems accessing this website contact ssc_fortrav@navy.mil. Forward a copy of the training certificate to the previous email address or fax to (619) 553-6863. Sere 100.2 Level A code of conduct training is also required prior to OCONUS travel for all personnel. Sere 100.2 Level A training can be accessed at http://jko.jfcom.mil (recommended), https://jkodirect.jten.mil/atlas2/faces/page/ login/login.seam, recommended course: prefix: j3t: course #: a-us1329, for civilian, military, and contractors. Personnel utilizing this site must have a CAC. A Sere 100.2 Level A training disk can be borrowed at the SSC Pacific Point Loma Office or Old Town Campus Office.

Specialized training for specific locations, such as SOUTHCOM Human Rights, or U.S. Forces Korea entry training, may also be required;

SSC Pacific security personnel will inform you if there are additional training requirements. Finally, EUCOM has mandated that all personnel going on official travel to the EUCOM AOR must now register with the smart traveler enrollment program (STEP). When you sign up, you will automatically receive the most current information the State Department compiles about your destination country. You will also receive updates, including travel warnings and travel alerts. Sign up is one-time only, after you have established your step account, you can easily add official or personal travel to anywhere in the world, not just EUCOM. http://travel.state.gov/content/passports/ en/go/step.html.

11.j Contractors are required to take Operation Security training. Additional OPSEC information is attached.

11.m See Specific-On-site for reporting, security, and training requirements such as contractors performing on classified contracts are required to attend Counterintelligence (CI) training annually IAW DoDD 5240.06 (Counterintelligence Awareness and Reporting (CIAR)).

The SSC Pacific-COR will specify which positions require a clearance.

Changes: RFP was originally approved by IRCCO and SSO Navy under N66001-17-R-0187 for incidental SCI access. Solicitation is being updated to include new Solicitation N66001-18-R-0351 and is submitted to Code 874 to approve this administrative change.

No further entries on this page.

List of Attachments [2] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)

Add Attachment View Selected Attachment Remove Selected Attachment

SCI Contracting Officer's Representative (COR)

NAME & TITLE OF REVIEWING OFFICIAL

Megan Kline, COR, Code 58230

SIGNATURE

SCI Requirements Validation

NAME & TITLE OF REVIEWING OFFICIAL

Beverly Ellis, IRC & SPO, Code 874, SSC Pacific approval for administrative changes

SIGNATURE

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

No Yes If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.

(See instructions for additional guidance or use of the fillable PDF.)

Information Technology (IT) Systems Personnel Security Program Requirements are attached and must be passed to subcontractors.

Information Technology (IT) Systems Personnel Security Program Requirements for Unclassified/Position of Trust (POT) Contractors and Must be Passed Down to Subcontractors.

Specific On-Site Security Requirements are Attached. This document contains reporting, security, and training requirements. For authorized visits to other U.S. Government activities, the contractor must comply with all On-site Security requirements of the Host Command.

Intelligence Information attachment For Official Use Only (FOUO) guidance attached.

18R0351

PREVIOUS EDITION IS OBSOLETE. Page 5 of 5 AEM LiveCycle Designer

DD FORM 254, APR 2018

Operations Security (OPSEC) requirements attached and must be passed to all Subcontractors.

Release of Sensitive Compartmented Information (SCI) Intelligence Information to U.S. Contractors.

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

No Yes If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item

13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.

(See instructions for additional guidance or use of the fillable PDF.)

CSO and inspection authority for SCI is SSO Navy. See attached SCI Addendum.

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

a. GCA NAME

SSC Pacific

b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See Instructions)

N66001

c. ADDRESS (Include ZIP Code)

Code 22710 53560 Hull Street San Diego, CA 92152-5001

d. POC NAME

Suzanne McLaughlin

e. POC TELEPHONE (Include Area Code)

+1 (619) 553-2556

f. EMAIL ADDRESS (See Instructions) suzanne.m.mclaughlin@navy.mil

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See Instructions)

Minard, Verna F.

b. TITLE

Security's COR

c. ADDRESS (Include ZIP Code) Commanding Officer SSC Pacific Code 83310, 53560 Hull Street, CA 92152-5001

d. AAC OF THE CONTRACTING OFFICE (See Instructions)

N66001

e. CAGE CODE OF THE PRIME CONTRACTOR

(See Instructions.)

f. TELEPHONE (Include Area Code)

+1 (619) 553-3005

g. EMAIL ADDRESS (See Instructions) verna.minard@navy.mil

h. SIGNATURE

i. DATE SIGNED (See Instructions)

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

a. CONTRACTOR

b. SUBCONTRACTOR

c. COGNIZANT SECURITY OFFICE FOR PRIME AND

SUBCONTRACTOR

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY

ADMINISTRATION

e. ADMINISTRATIVE CONTRACTING OFFICER

f. OTHER AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)

S and Below COR, email: rebecca.hughes@navy.mil TS/SCI COR, email: megan.kline@navy.mil CS, email: suzanne.m.mclaughlin@navy.mil Security, w_spsc_ssc_pac_securitycor_us@navy.mil

INFORMATION TECHNOLOGY (IT) SYSTEMS

PERSONNEL SECURITY PROGRAM REQUIREMENTS

The U.S. Government conducts trustworthiness investigations of personnel who are assigned to positions that directly or indirectly affect the operation of unclassified IT resources and systems that process Department of

Defense (DoD) information, to include For Official Use Only (FOUO) and other controlled unclassified information.

The United States Office of Personnel Management (OPM), National Background Investigation Bureau (NBIB) process all requests for U.S. Government trustworthiness investigations. Requirements for these investigations are outlined in paragraph C3.6.15 and Appendix 10 of DoD 5200.2-R, available at http://www.dtic.mil/whs/directives/corres/dir.html. Personnel occupying an IT Position shall be designated as filling one of the IT Position Categories listed below. The contractor shall include all of these requirements in any subcontracts involving IT support. (Note: Terminology used in DoD 5200.2-R references “ADP” vice “IT”. For purposes of this requirement, the terms ADP and IT are synonymous.)

The Program Manager (PM), Contracting Officer’s Representative (COR) or Technical Representative (TR) shall determine the IT Position category for the contractor personnel.

DoDD Directive 8500.01, Subject: Cybersecurity, stipulates cybersecurity requirements such as "Cybersecurity workforce functions must be identified and managed, and personnel performing cybersecurity functions will be appropriately screened in accordance with this instruction and DoD 5200.2-R and qualified in accordance with

DoDD 8570.01 and supporting issuances”. DoD 5200.2-R stipulates the requirements for background investigations, special access and IT position designations and requirements. An appropriate security clearance and non-disclosure agreement are also required for access to classified information” in accordance with DoDM 5200.01

Vol. 1. DoD 5200.2-R and DoDD 5200.2 require all persons assigned to sensitive positions or assigned to sensitive duties be U.S. citizens. All persons assigned to IT-I and IT-II positions, as well as all persons with access to controlled unclassified information (without regard to degree of IT access) or performing other duties that are considered "sensitive" as defined in DoDD 5200.2 and DoD 5200.2-R must be U.S. citizens. Furthermore, access by non-citizens to unclassified export controlled data will only be granted to persons pursuant to the export control laws of the U.S. The categories of controlled unclassified information are specified in DoDM 5200.01 Vol. 4. These same restrictions apply to "Representatives of a Foreign Interest" as defined by DoD 5220.22-M (National Industrial

Security Program Operating Manual, NISPOM). DoD 8570.01-M further stipulates additional training and/or certification that is required by all persons assigned to Information Assurance functions.

I. Criteria For Designating Positions: updated per OPM Federal Investigations Notice No. 16-02, dated

October 6, 2015:

a. Tier 5/5R = IT-I Position (Privileged)

Responsibility or the development and administration of Government computer security programs, and including direction and control of risk analysis and/or threat assessment.

Significant involvement in life-critical or mission-critical systems.

Responsibility for the preparation or approval of data for input into a system, which does not necessarily involve personal access to the system, but with relatively high risk for effecting grave damage or realizing significant personal gain.

Relatively high risk assignments associated with or directly involving the accounting, disbursement, or authorization for disbursement from systems of (1) dollar amounts of $10 million per year or greater, or (2) lesser amounts if the activities of the individual are not subject to technical review by higher authority in the IT-I category to ensure the integrity of the system.

Positions involving major responsibility for the direction, planning, design, testing, maintenance, operation, monitoring, and/or management of systems hardware and software.

Other positions as designated by Space and Naval Warfare Systems Center Pacific (SSC Pacific) that involve relatively high risk for effecting grave damage or realizing significant personal gain.

Personnel whose duties meet the criteria for IT-I Position designation require a favorably adjudicated Single Scope

Background Investigation (SSBI) or SSBI Periodic Reinvestigation (SSBI-PR) or Tier 5/5R. The SSBI or SSBI-PR http://www.dtic.mil/whs/directives/corres/dir.html or Tier 5/5R shall be updated every 5 years by using the Electronic Questionnaire for Investigation Processing

(eQIP) web based program (SF86 format).

b. Tier 3/3R = IT-II Position (Limited Privileged)

Responsibility for systems design, operation, testing, maintenance, and/or monitoring that is carried out under technical review of higher authority in the IT-I category, includes but is not limited to:

Access to and/or processing of proprietary data, information requiring protection under the Privacy

Act of 1974, and Government-developed privileged information involving the award of contracts;

Accounting, disbursement, or authorization for disbursement from systems of dollar amounts less than $10 million per year. Other positions are designated by Space and Naval Warfare Systems

Center Pacific (SSC Pacific) that involve a degree of access to a system that creates a significant potential for damage or personal gain less than that in IT-I positions. Personnel whose duties meet the criteria for an IT-II Position require a favorably adjudicated National Agency Check with

Local Agency Check and Credit Check (NACLC) or Tier 3/3R.

c. Tier 1/1R is for Unclassified – Non-Sensitive positions = IT-III Position (Non-Privileged)

All other positions involving Federal IT activities. Incumbent in this position has non-privileged access to one or more DoD information systems, application, or database to which they are authorized access. Personnel whose duties meet the criteria for an IT-III Position designation require a favorably adjudicated National Agency Check with Inquiries (NACI) or Tier 1/1R.

d. Qualified Cleared Personnel Do NOT Require Trustworthiness Investigations:

When background investigations supporting clearance eligibility have been submitted and/or adjudicated to support assignment to sensitive national security positions, a separate investigation to support IT access will normally not be required.

A determination that an individual is NOT eligible for assignment to a position of trust will result in the removal of eligibility for security clearance. Likewise, a determination that an individual is NOT eligible for a security clearance will result in the denial of eligibility for a position of trust.

II. Visit Authorization Requests (VARs) for Qualified Employees:

Contractors that have been awarded a classified contract must submit visit requests using “only” the Joint Personnel

Adjudication System (JPAS). All government activities have been directed to use JPAS when transmitting or receiving VARS. Therefore, contractors who work on classified contracts are required to have established an account through JPAS for their facility. This database contains all U.S. citizens who have received a clearance of

Confidential, Secret, and/or Top Secret. The visit request can be submitted for up to one year. When submitting a visit requests to SSC Pacific, use its Security Management Office (SMO) number (660015). This information is provided in accordance with guidance provided to contractors via the Defense Security Service (DSS) website https://www.dss.mil/ (DSS guidance dated 24 April 2007, subject: Procedures Governing the Use of JPAS by

Cleared Contractors).

III. Employment Terminations:

The contractor shall:

Immediately notify the COR or TR of the employee’s termination.

Send email to W_SPSC_SSC_PAC_clearance_US@navy.mil, Code 83310 notifying them of the termination.

Fax a termination VAL to Code 83320 at (619) 553-6169.

Return any badge and decal to Commanding Officer, Space and Naval Warfare Systems Center Pacific, Attn: Code

83320, 53560 Hull Street, San Diego, CA 92152-5001.

mailto:W_SPSC_SSC_PAC_clearance_US@navy.mil

INFORMATION TECHNOLOGY (IT) SYSTEMS PERSONNEL SECURITY PROGRAM

REQUIREMENTS FOR UNCLASSIFIED/POSITION OF TRUST (POT) CONTRACTORS

The U.S. Government conducts trustworthiness investigations of personnel who are assigned to positions that directly or indirectly affect the operation of unclassified IT resources and systems that process Department of

Defense (DoD) information, to include For Official Use Only (FOUO) and other controlled unclassified information.

The United States Office of Personnel Management (OPM), National Background Investigation Bureau (NBIB) process all requests for U.S. Government trustworthiness investigations. Requirements for these investigations are outlined in paragraph C3.6.15 and Appendix 10 of DoD 5200.2-R, available at http://www.dtic.mil/whs/directives/corres/dir.html. Personnel occupying an IT Position shall be designated as filling one of the IT Position Categories listed below. The contractor shall include all of these requirements in any subcontracts involving IT support. (Note: Terminology used in DoD 5200.2-R references “ADP” vice “IT”. For purposes of this requirement, the terms ADP and IT are synonymous.)

The Program Manager (PM), Contracting Officer’s Representative (COR) or Technical Representative (TR) shall determine the IT Position category for the contractor personnel.

DoDD Directive 8500.01, Subject: Cybersecurity, stipulates cybersecurity requirements such as "Cybersecurity workforce functions must be identified and managed, and personnel performing cybersecurity functions will be appropriately screened in accordance with this instruction and DoD 5200.2-R and qualified in accordance with

DoDD 8570.01 and supporting issuances”. DoD 5200.2-R stipulates the requirements for background investigations, special access and IT position designations and requirements. An appropriate security clearance and non-disclosure agreement are also required for access to classified information” in accordance with DoDM 5200.01

Vol. 1. DoD 5200.2-R and DoDD 5200.2 require all persons assigned to sensitive positions or assigned to sensitive duties be U.S. citizens. All persons assigned to IT-I and IT-II positions, as well as all persons with access to controlled unclassified information (without regard to degree of IT access) or performing other duties that are considered "sensitive" as defined in DoDD 5200.2 and DoD 5200.2-R must be U.S. citizens. Furthermore, access by non-citizens to unclassified export controlled data will only be granted to persons pursuant to the export control laws of the U.S. The categories of controlled unclassified information are specified in DoDM 5200.01 Vol. 4. These same restrictions apply to "Representatives of a Foreign Interest" as defined by DoD 5220.22-M (National Industrial

Security Program Operating Manual, NISPOM). DoD 8570.01-M further stipulates additional training and/or certification that is required by all persons assigned to Information Assurance functions.

IV. Criteria For Designating Positions: updated per OPM Federal Investigations Notice No. 16-02, dated

October 6, 2015:

e. Tier 5/5R = IT-I Position (Privileged)

Responsibility or the development and administration of Government computer security programs, and including direction and control of risk analysis and/or threat assessment.

Significant involvement in life-critical or mission-critical systems.

Responsibility for the preparation or approval of data for input into a system, which does not necessarily involve personal access to the system, but with relatively high risk for effecting grave damage or realizing significant personal gain.

Relatively high risk assignments associated with or directly involving the accounting, disbursement, or authorization for disbursement from systems of (1) dollar amounts of $10 million per year or greater, or (2) lesser amounts if the activities of the individual are not subject to technical review by higher authority in the IT-I category to ensure the integrity of the system.

Positions involving major responsibility for the direction, planning, design, testing, maintenance, operation, monitoring, and/or management of systems hardware and software.

Other positions as designated by Space and Naval Warfare Systems Center Pacific (SSC Pacific) that involve relatively high risk for effecting grave damage or realizing significant personal gain.

Personnel whose duties meet the criteria for IT-I Position designation require a favorably adjudicated Single Scope

Background Investigation (SSBI) or SSBI Periodic Reinvestigation (SSBI-PR) or Tier 5/5R. The SSBI or SSBI-PR or Tier 5/5R shall be updated every 5 years by using the Electronic Questionnaire for Investigation Processing

(eQIP) web based program (SF86 format).

http://www.dtic.mil/whs/directives/corres/dir.html

f. Tier 3/3R = IT-II Position (Limited Privileged)

Responsibility for systems design, operation, testing, maintenance, and/or monitoring that is carried out under technical review of higher authority in the IT-I category, includes but is not limited to:

Access to and/or processing of proprietary data, information requiring protection under the Privacy

Act of 1974, and Government-developed privileged information involving the award of contracts;

Accounting, disbursement, or authorization for disbursement from systems of dollar amounts less than $10 million per year. Other positions are designated by Space and Naval Warfare Systems

Center Pacific (SSC Pacific) that involve a degree of access to a system that creates a significant potential for damage or personal gain less than that in IT-I positions. Personnel whose duties meet the criteria for an IT-II Position require a favorably adjudicated National Agency Check with

Local Agency Check and Credit Check (NACLC) or Tier 3/3R.

g. Tier 1/1R is for Unclassified – Non-Sensitive positions = IT-III Position (Non-Privileged)

All other positions involving Federal IT activities. Incumbent in this position has non-privileged access to one or more DoD information systems, application, or database to which they are authorized access. Personnel whose duties meet the criteria for an IT-III Position designation require a favorably adjudicated National Agency Check with Inquiries (NACI) or Tier 1/1R.

V. Procedures for submitting U.S. Government Trustworthiness Investigations:

Only the e-QIP version of SF-85 and SF 86 are acceptable by OPM-NBIB.

After determining that an individual requires Public Trust Position determination, the FSO will identify the individual to the COR. The COR will notify SSC Pacific Personnel Security Office with the specific IT Level category assigned for requesting the appropriate type of investigation. The FSO will also provide the following information to the COR so that the SSC Pacific Personnel Security Office can initiate a request thru e-QIP:

Full SSN of the applicant

Full Name

Date of Birth

Place of Birth

Email Address

Phone Number

A spreadsheet will be provided by the COR for the FSO to complete that includes the above information and any additional information required by the Personnel Security Office.

The Personnel Security Office will send email notification and instructions to the applicant to complete and submit e-QIP expeditiously.

The FSO or SSC Pacific Personnel Security Office will take and submit fingerprints using SF-87, FD-258 or electronic submission. The FSO must obtain from SSC Pacific Personnel Security Office the e-QIP Request Number for inclusion in submitting the fingerprints. For immediate fingerprint result, electronic transmission of fingerprints is encouraged. OPM no longer accepts the submission of hard copy fingerprints (SF-87 or FD-258).

If fingerprints are obtained via hardcopy, the hardcopies will be sent to SSC Pacific Personnel Security via Priority, Certified, or Express mail:

COMMANDING OFFICER, SSC PAC

ATTN: Personnel Security, Code 83310

53560 Hull St

San Diego CA 92152

SSC Pacific Personnel Security Office will update Joint Personnel Adjudication System (JPAS), PSQ Sent Date, when the Public Trust Investigation request is released to the Parent Agency, OPM.

Contractor fitness determinations made by the DOD CAF are maintained in the JPAS. Favorable fitness determinations will support public trust positions only and not national security eligibility. If no issues are discovered, according to respective guidelines a “Favorable Determination” will be populated in JPAS and will be reciprocal within DoN. If issues are discovered, the DOD CAF will forward the investigation along with all supporting documentation to the SSC Pacific Security Office for local determination. The local fitness determination will be made by the Command Security Manager and your company will be notified of the decision in writing. If an individual receives a negative trustworthiness determination, they will be immediately removed from their position of trust, the FSO will be notified, and the company will replace any individual who has received a negative trustworthiness determination.

If you require additional assistance with the submission of Public Trust Investigations, you may send an email to

SSC Pacific at W_SPSC_SSC_PAC_clearance_US@navy.mil.

VI. Employment Terminations:

The contractor shall:

Immediately notify the COR or TR of the employee’s termination.

Send email to W_SPSC_SSC_PAC_clearance_US@navy.mil, Code 83310 notifying them of the termination.

Fax a termination VAL to Code 83320 at (619) 553-6169.

Return any badge and decal to Commanding Officer, Space and Naval Warfare Systems Center Pacific, Attn: Code 83320, 53560 Hull Street, San Diego, CA 92152-5001.

mailto:W_SPSC_SSC_PAC_clearance_US@navy.mil.

mailto:W_SPSC_SSC_PAC_clearance_US@navy.mil

SPECIFIC ON-SITE SECURITY REQUIREMENTS

I. GENERAL.

a. Contractor Performance. In performance of this Contract the following security services and procedures are incorporated as an attachment to the DD 254. The Contractor will conform to the requirements of DoD 5220.22-M, Department of Defense National Industrial Security Program, Operating Manual (NISPOM), as revised. The Contractor will follow all export laws and regulations in the performance of this contract. When visiting Space and Naval Warfare Systems Center Pacific (SSC Pacific) at either the Point Loma Campus (PLC) or Old Town Campus (OTC) the Contractor will comply with the security directives used regarding the protection of classified and controlled unclassified information, SECNAV M-5510.36 (series), SECNAV M-5510.30 (series), DOD M-5200.01 Volumes 1 through 4, and SSCPACINST 5720.1A (series). Both of the SECNAV Instructions and Manuals are available online at http://doni.daps.dla.mil/SECNAV.aspx and the DOD Instructions can be found at http://www.dtic.mil/whs/directives/corres/pub1.html. A copy of SSCPACINST 5720.1A will be provided upon receipt of a written request from the Contractor’s Facility Security Officer (FSO) to the SSC Pacific Security’s Contracting Officer’s Representative (COR), Code 83310. If the Contractor establishes a cleared facility or Defense Security Service (DSS) approved off-site location at SSC Pacific, the security provisions of the NISPOM will be followed within this cleared facility.

b. Security Supervision. SSC Pacific will exercise security supervision over all contractors visiting SSC Pacific and will provide security support to the Contractor as noted below. The Contractor will identify, in writing to Security’s COR, an on-site Point of Contact to interface with Security’s COR.

II. HANDLING CLASSIFIED MATERIAL OR INFORMATION.

a. Control and Safeguarding. Contractor personnel located at SSC Pacific are responsible for the control and safeguarding of all classified material in their possession. All contractor personnel will be briefed by their FSO on their individual responsibilities to safeguard classified material. In addition, all contractor personnel are invited to attend SSC Pacific conducted Security Briefings, available at this time by appointment only. In the event of possible or actual loss or compromise of classified material, the on-site Contractor will immediately report the incident to SSC Pacific Code 83310, (619) 553-3005, as well as the Contractor's FSO. A security specialist, Code 83310 representative will investigate the circumstances, determine culpability where possible, and report results of the inquiry to the FSO and the Cognizant Field Office of the DSS. On-site contractor personnel will promptly correct any deficient security conditions identified by a SSC Pacific representative.

b. Storage.

1. Classified material may be stored in containers authorized by SSC Pacific PLC Physical Security Group, Code 83320 for the storage of that level of classified material. Classified material may also be stored in Contractor owned containers brought on board SSC Pacific PLC with Code 83320's written permission. Areas located within cleared contractor facilities on board SSC Pacific will be approved by DSS.

2. The use of Open Storage areas must be pre-approved in writing by Code 83320 for the open storage, or processing, of classified material prior to use of that area for open storage. Specific supplemental security controls for open storage areas, when required, will be provided by SSC Pacific, Code 83320.

c. Transmission of Classified Material.

1. All classified material transmitted by mail for use by long term visitors will be addressed as follows:

(a) TOP SECRET, Non-Sensitive Compartmented Information (SCI) material using the Defense Courier Service: SPAWARSYSCEN-PACIFIC: 271582-SN00, SPAWARSYSCEN PACIFIC.

(b) CONFIDENTIAL and SECRET material transmitted by FedEx will be addressed to COMMANDING

OFFICER, SPACE AND NAVAL WARFARE SYSTEMS CENTER PACIFIC, ATTN RECEIVING

OFFICER CODE 43150, 4297 PACIFIC HIGHWAY, SAN DIEGO, CA 92110.

(c) CONFIDENTIAL and SECRET material transmitted by USPS Registered and Express mail will be http://doni.daps.dla.mil/SECNAV.aspx http://www.dtic.mil/whs/directives/corres/pub1.html addressed to COMMANDING OFFICER, SPACE AND NAVAL WARFARE SYSTEMS CENTER PACIFIC, 53560 HULL STREET, SAN DIEGO CA 92152-5001. The inner envelope will be addressed to the attention of the Contracting Officer's Representative (COR) or applicable Technical Representative (TR) for this contract, to include their code number.

2. All SECRET material hand carried to SSC Pacific by contractor personnel must be delivered to the Classified Material Control Center (CMCC), Code 83430, Building 58, Room 102, for processing.

3. All CONFIDENTIAL material hand carried to SSC Pacific by contractor personnel must be delivered to the Mail

Distribution Center, Code 83430, for processing. This applies for either the OTC or PLC sites.

4. All SSC Pacific classified material transmitted by contractor personnel from the SSC Pacific will be sent via SSC Pacific COR or TR for this contract.

5. The sole exception to the above is items categorized as a Data Deliverable. All contract Data Deliverables will be addressed to COMMANDING OFFICER, ATTN DOCUMENT CONTROL CODE 83430, SPACE AND NAVAL WARFARE SYSTEMS CENTER PACIFIC, 53560 HULL STREET, SAN DIEGO, CA 92152-5001.

III. INFORMATION SYSTEMS (IS) Security.

a. Contractors using ISs, networks, or computer resources to process classified, sensitive unclassified and/or unclassified information will comply with the provisions of SECNAVINST 5239.3 (series) and local policies and procedures. Contractor personnel must ensure that systems they use at SSC Pacific have been granted a formal letter of approval to operate by contacting their Information System Security Officer (ISSO). Any suspected cybersecurity incident, such as spillage of classified information to an unclassified system, regardless of the location of the computer system, must be reported immediately to the COR/TR/PM, Security's COR, ISSO, the Contractor's Facility Security Officer (FSO), and the Contracting Officer. Contractors who willfully misuse Government computer resources will be held liable to reimburse the Government for all associated costs.

b. Contractors receiving, transmitting or accessing unclassified controlled technical information on or through its contractor information (s) must safeguard the information to avoid compromise, including but not limited to disclosure of information of information to unauthorized persons, unauthorized modification, destruction, or loss of an object, or the copying of information to unauthorized media, as required per DFARS subpart 2014.73 and clauses 204.7304 and 252.204-7012. Contractors shall report to the DOD each cybersecurity incident that affects unclassified controlled technical information resident on or transiting contractor information systems in accordance with DFARS clause

204.7304 and 252.204-7012. Detailed reporting criteria and requirements are set forth in the clause at 252.204-7012 safeguarding of unclassified controlled technical information.

IV. VISITOR CONTROL PROCEDURES.

Title 18 USC 701 provides for criminal sanctions including fine or imprisonment for anyone in possession of a badge who is not entitled to have possession. Sec.701. Official badges, identification cards, other insignia. Whoever manufactures, sells, or possesses any badge, identification card, or other insignia, of the design prescribed by the head of any department or agency of the United States for use by any officer or employee thereof, or any colorable imitation thereof, or photographs, prints, or in any other manner makes or executes any engraving, photograph, print, or impression in the likeness of any such badge, identification card, or other insignia, or any colorable imitation thereof, except as authorized under regulations made pursuant to law, shall be fined under this title or imprisoned not more than six months, or both.

a. Contractor personnel assigned to SSC Pacific will be considered long-term visitors for the purpose of this contract.

b. Contractors that have been awarded a classified contract must submit visit requests using “only” the Joint Personnel

Adjudication System (JPAS). All government activities have been directed to use JPAS when transmitting or receiving Visit Authorization Letters (VALs). Therefore, contractors who work on classified contracts are required to have established an account through JPAS for their facility. This database contains all U.S. citizens who have received a clearance of Confidential, Secret, and/or Top Secret. The visit request can be submitted for one year.

When submitting visit requests to SSC Pacific use its Security Management Office (SMO) number (660015). This information is provided in accordance with guidance provided to contractors via the Defense Security Service (DSS) website https://www.dss.mil (DSS guidance dated 24 April 2007, subject: Procedures Governing the Use of JPAS by Cleared Contractors).

c. For visitors to receive a SSC Pacific badge their Government point of contact must approve their visit request and the visitor must present government issued photo identification.

d. Visit requests for long-term visitors must be received at least one week prior to the expected arrival of the visitor to ensure necessary processing of the request.

e. Code 83320 will issue temporary…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .