Contract Att I_Final DD-254.pdf
PDF 513 KB Posted
- Attached to
- Cybersecurity, Cryptographic Modernization and Key Management Engineering Services Federal contract opportunity
- Solicitation number
- N66001-18-R-0351
About this file
This DD Form 254 outlines security requirements for a contract award notice. Nathan Kunes Inc. was awarded a contract to provide cybersecurity, cryptographic modernization and key management engineering services to the Department of the Navy Information Warfare Systems Command. The contract award amount is $35,236,186.35, and was awarded on May 8, 2019 under solicitation number N66001-18-R-0351. The contractor will require access to communications security information, national intelligence information including sensitive compartmented information, and controlled unclassified information. Work will be performed at government sites and U.S. naval vessels.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CLASSIFICATION (When filled in): Unclassified
19D0089
PREVIOUS EDITION IS OBSOLETE. Page 1 of 5 AEM LiveCycle Designer
DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 1 of 5 AEM LiveCycle Designer
DD FORM 254, APR 2018
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
October 31, 2020
The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED
(See Instructions)
Top Secret
b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/
MATERIAL REQUIRED AT CONTRACTOR FACILITY
None (See instructions)
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
a. PRIME CONTRACT NUMBER (See instructions.)
N66001-19-D-0089 ECD: 20240506
b. SUBCONTRACT NUMBER
c. SOLICITATION OR OTHER NUMBER
N66001-18-R-0351
DUE DATE (YYYYMMDD)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
DATE (YYYYMMDD)
20190507
b. REVISED (Supersedes all previous specifications.)
REVISION NO. DATE (YYYYMMDD)
c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)
4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:
Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.
5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:
In response to the contractor's request dated , retention of the classified material is authorized for the period of:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
a. NAME, ADDRESS, AND ZIP CODE
Nathan Kunes Inc.
5055 North Harbor Drive Suite 230 San Diego CA 92106
b. CAGE CODE
3DP47
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional) Defense Security Service (DSS) San Diego Field Office (IOFWD) 11770 Bernardo Plaza Ct.
Ste 450 San Diego, CA 92128
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor) Add Row Remove last Row Delete All Rows
a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
8. ACTUAL PERFORMANCE (Click button to add more locations.) Add Row Remove last Row Delete All Rows
a. LOCATION(S) (For actual performance, see instructions.)
NIWC Pacific 53560 Hull Street San Diego, CA 92152-5001
b. CAGE CODE (If applicable, see Instructions.)
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
a. LOCATION(S) (For actual performance, see instructions.)
SPAWARSYSCOM, San Diego, CA
NSA
U.S. Naval Vessels
b. CAGE CODE (If applicable, see Instructions.)
c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)
9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT
19D0089
PREVIOUS EDITION IS OBSOLETE. Page 2 of 5 AEM LiveCycle Designer
DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 2 of 5 AEM LiveCycle Designer
DD FORM 254, APR 2018
Cryptographic systems and solutions, key management architecture, information systems engineering and technical services. Information assurance exploration analysis, systems, software, and test engineering services that are required to support High Assurance Internet protocol Encryptor (HAIPE), Inline Network Encryptor (INE), Link Encryption Family (LEF), cryptographic modernization, Advanced Cryptographic Capabilities (ACC), CM2, Tactical Secure Voice (TSV), Offline Network Encryption (AN/PYQ-20), Modernized Link Level COMSEC (LINK-22), Ethernet Data Encryptor (EDE), Navy Ship Site System Operational Testing (SOT) and System Operational Verification Testing
(SOVT).
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION
b. RESTRICTED DATA g. NORTH ATLANTIC TREATY ORGANIZATION
(NATO) INFORMATION
c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.) h. FOREIGN GOVERMENT INFORMATION
d. FORMERLY RESTRICTED DATA i. ALTERNATIVE COMPENSATORY CONTROL MEASURES
(ACCM) INFORMATION
e. NATIONAL INTELLIGENCE INFORMATION:
(1) Sensitive Compartmented Information (SCI)
(2) Non-SCI
j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)
k. OTHER (Specify) (See instructions.)
1) NS=SCI/JWICS/NSANet/SIPRnet and 2) NATO awareness for SIPRnet access at government site.
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT
ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT
ACTIVITY
(Applicable only if there is no access or storage required at contractor facility.
See instructions.)
b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY
c. RECEIVE, STORE, AND GENERATE CLASSIFIED
INFORMATION OR MATERIAL
d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE
e. PERFORM SERVICES ONLY
f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE
THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST
TERRITORIES
g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE
TECHNICAL INFORMATION CENTER (DTIC) OR OTHER
SECONDARY DISTRIBUTION CENTER
h. REQUIRE A COMSEC ACCOUNT
i. HAVE A TEMPEST REQUIREMENT
j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS
k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE
l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED
INFORMATION (CUI).
(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)
m. OTHER (Specify) (See instructions.)
See Specific On-Site attachment for reporting, security, and training requirements.
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.
Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
DIRECT THROUGH (Specify below)
Naval Information Warfare Center Pacific (NIWC Pacific), Code 85000, 53560 Hull Street, San Diego, CA 92152-5001
Public Release Authority:
13. SECURITY GUIDANCE Add Signature Remove last Signature Delete All Signatures
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;
and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
Solicitation / Contract Numbers: N66001-18-R-0351 (old N66001-17-R-0187) / N66001-19-D-0089
Block 12 Continuation: Release of COMSEC, SCI, and NATO (Read-on IAW with the National Intelligence Security Policy Directive 17-008; NATO access is not required on this contract, see phrase 10.g/k(1)) material is not authorized.
Security Classification Guide (SCG): Work to be performed at government; SCGs to be provided under separate cover by the COR. All
19D0089
PREVIOUS EDITION IS OBSOLETE. Page 3 of 5 AEM LiveCycle Designer
DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 3 of 5 AEM LiveCycle Designer
DD FORM 254, APR 2018
classified guides will be reviewed at the government site. Information Assurance (IA) Vulnerabilities and Weaknesses (U) 3-02 dated 08 July 05 // (U) Classification Guide for Quantum Defense by NSA dated 25 May 2016 // (U) Cryptographic Modernization (CryptoMod) by NSA dated 1 February 2010 //(U) High Assurance Internet Protocol Encryptor Program (HAIPE) by NSA dated 26 June 2007.
The Code 58110 Branch Head, Kevin Chung, (619) 553-3363, email: kevin.chung@navy.mil.
Direct all Collateral Top Secret and SCI questions to the Contracting Officer's Representative (COR) Megan Kline, Code 58230,
(619) 553-6036, email: megan.kline@navy.mil.
Direct all Secret and Below questions to the COR Rebecca Hughes, Code 58006, (619) 553-9184, email: rebecca.hughes@navy.mil.
The Contract Specialist (CS) Suzanne McLaughlin, Code 22710, (619) 553-2556, email: suzanne.m.mclaughlin@navy.mil.
Prime contractor's are required to send copies of all subcontract DD Form 254s to obtain flow-down approvals as required to the distribution listed in block 17: NIWC Pacific Codes 58110, and 58230/58006 (PM/CORs), 22710 (CS) see above and 83310 - Security -w_spsc_ssc_pac_securitycor_us@navy.mil. external address only.
Access Requirements:
10.a Further disclosure, to include subcontracting, of COMSEC information by a contractor requires prior approval of the NIWC Pacific COR. Access to any COMSEC information requires special briefings at the contractor facility. Access to classified COMSEC information requires a final U.S. Government clearance at the appropriate level. Use of COMSEC information is governed by the NSA Industrial COMSEC Manual, NSA/CSS Policy Manual 3-16. Contractors that will be designated CMS users must attend an initial CMS user training class that is given by the NIWC Pacific CMS office. If you have questions call (619) 553-5065. (Access is for COMSEC equipment/ material)
10.e(1) The SSO Navy has exclusive security responsibility for all SCI classified material released or developed under this contract. DSS is relieved of security inspection responsibility for all such material but retains responsibility for all non-SCI classified material released to or developed under this contract. Further disclosure to include subcontracting of SCI is prohibited prior until approval is received from the SCI cleared NIWC Pacific COR, NIWC Pacific Code 874 and SSO Navy is required for sub-contracting. Special briefings and procedures are all required at the contractor's facility. Access to SCI information requires a final U.S. Government clearance at the appropriate level and will be performed within U.S. Government facilities only. Requesting approval for incidental SCI access, i.e., enter spaces, attend meetings, and briefings as long as the contractor is not producing a SCI product.
Contractor personnel assigned to this effort who require access to SCI data and spaces must possess a current SSBI with ICD 704 eligibility (which replaced DCID 6/4 eligibility).
Contract performance for incidental SCI is restricted to NIWC Pacific, San Diego, CA.
10.g/k(1) Effective immediately all contractor personnel with SCI access must be read-on NATO secret with an entry into JPAS prior to being granted access. This contract requires SCI cleared personnel to access JWICS/NSAnet/SIPRnet. In addition, the contractor shall complete the derivative classification training; the special NATO briefing and derivative classification briefing are provided by the contracting company's facility security officer. This requirement is mandated per the national intelligence security policy directive 17-008.
This read-on meets the mandated requirement; however, contractor does require access to NATO on this contract. Contractor is not authorized to have NATO at its contractors facility. JWICS/SIPRnet under the SPAWAR Claimancy is not accredited to receive or process NATO restricted up to NATO secret data. Questions, contact the GCA NATO Control Office 619-553-3005/3191. Subcontract DD254s require approval from the GCA NCO prior to access being granted. Policies: DOD M-5200.1 Volume 1, enclosure (3) and USSAN 1-07.
10.j/11.l Contractors receiving, transmitting or accessing controlled unclassified technical information (CUI) on or through its contractor information system(s) must safeguard the information to avoid compromise, including but not limited to disclosure of information to unauthorized persons, unauthorized modification, destruction, or loss of an object, or the copying of information to unauthorized media, as required per DFARS Subpart 204.73 and Clauses 204.7304 and 252.204-7012. Contractors shall report to the DOD each Cyber incident that affects unclassified controlled technical information resident on or transiting contractor information systems in accordance with DFARS clause 204.7304 and 252.204-7012. Detailed reporting criteria and requirements are set forth in the clause at 252.204-7012, safeguarding of unclassified controlled technical information. For information on handling CUI see DoD M-5200.01, Volume 4.
10.k(2) Some contractor personnel that work on Top Secret and below requirements without SCI or do not require access to NATO classified data are only required to receive the NATO Awareness Brief for the sole purpose of accessing SIPRnet. The special briefing is provided by the contracting company's Facility Security Officer (FSO). Note: For this awareness brief there is no requirement for the contractor to make an entry in JPAS. The contractor shall complete Derivative Classification training prior to being granted access to SIPRnet; training is provided by the company’s FSO. Policy: DOD M-5200.01 Volume 1, enclosure (3).
11.a Contract performance is restricted to SPAWARSYSCOM, San Diego, CA, NIWC Pacific, San Diego, CA, NSA, other authorized
19D0089
PREVIOUS EDITION IS OBSOLETE. Page 4 of 5 AEM LiveCycle Designer
DD FORM 254, APR 2018
DoD locations, and U.S. naval vessels. NIWC Pacific-COR will provide security classification guidance for performance of this contract.
11.f Access to classified U.S. government information may be required at the following overseas locations: UK, Canada, Australia, and various US Naval Ports aboard. Antiterrorism/force protection briefing within one year of departure and a country specific briefing within 90 days of departure. Anti-terrorism/force protection (AT/FP) briefings are required for all personnel (military, DoD civilian, and contractor) per OPNAVINST F3300.53C. Contractor employees must receive the AT/FP briefing annually. The briefing is available at joint knowledge online (jko): https://jkodirect.jten.mil (prefix): course number: us007; title: Level 1 Anti-terrorism awareness training, if experiencing problems accessing this website contact the JKO Help Desk (24 hours a day/7 days a week, jkohelpdesk@jten.mil, 757-203-5654). The website will allow contractors who do not have a CAC to access the training. Sere 100.2 Level A code of conduct training is also required prior to OCONUS travel for all personnel. Sere 100.2 Level A training can be accessed at http://jko.jfcom.mil (recommended), https://jkodirect.jten.mil/atlas2/faces/page/login/login.seam, recommended course: prefix: j3t: course #: a-us1329, for civilian, military, and contractors. Personnel utilizing this site must have a CAC. A Sere 100.2 Level A training disk can be borrowed at the NIWC Pacific Point Loma Office or Old Town Campus Office. Specialized training for specific locations, such as SOUTHCOM Human Rights, or U.S. Forces Korea entry training, may also be required; NIWC Pacific security personnel will inform you if there are additional training requirements. Finally, EUCOM has mandated that all personnel going on official travel to the EUCOM AOR must now register with the smart traveler enrollment program (STEP). When you sign up, you will automatically receive the most current information the State Department compiles about your destination country. You will also receive updates, including travel warnings and travel alerts. Sign up is one-time only, after you have established your step account, you can easily add official or personal travel to anywhere in the world, not just EUCOM. http://travel.state.gov/content/passports/en/go/step.html.
11.j Contractors are required to take Operation Security training. Additional OPSEC information is attached.
11.m See Specific-On-site Attachment for reporting, security, and training requirements such as contractors performing on classified contracts are required to attend Counterintelligence (CI) training annually IAW DoDD 5240.06 (Counterintelligence Awareness and Reporting (CIAR)).
The NIWC Pacific-COR will specify which positions require a clearance.
Changes: Submitting award DD254 for Prime contractor CAGE code: 3DP47 to be authorized incidental SCI access at the government site. RFP was originally approved by IRCCO and SSO Navy under N66001-17-R-0187 for incidental SCI access. Solicitation is being updated to include new Solicitation N66001-18-R-0351 and is submitted to Code 874 to approve this administrative change.
No further entries on this page.
List of Attachments [2] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)
Add Attachment View Selected Attachment Remove Selected Attachment
Branch Head, Kevin Chung, Code 58110 Megan Kline, SCI COR, Code 58230
NAME & TITLE OF REVIEWING OFFICIAL
Megan Kline, COR, Code 58230
SIGNATURE
SCI Requirements Validation
NAME & TITLE OF REVIEWING OFFICIAL
Kathy Steffel, Head, IRC and Special Project Office, Code 874, NIWC Pacific
SIGNATURE
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
No Yes If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
Information Technology (IT) Systems Personnel Security Program Requirements are attached and must be passed to subcontractors.
Information Technology (IT) Systems Personnel Security Program Requirements for Unclassified/Position of Trust (POT) Contractors and Must be Passed Down to Subcontractors.
Specific On-Site Security Requirements are Attached. This document contains reporting, security, and training requirements. For authorized visits to other U.S. Government activities, the contractor must comply with all On-site Security requirements of the Host Command.
19D0089
PREVIOUS EDITION IS OBSOLETE. Page 5 of 5 AEM LiveCycle Designer
DD FORM 254, APR 2018
Intelligence Information attachment For Official Use Only (FOUO) guidance attached.
Operations Security (OPSEC) requirements attached and must be passed to all Subcontractors.
Release of Sensitive Compartmented Information (SCI) Intelligence Information to U.S. Contractors.
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
No Yes If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item
13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.
(See instructions for additional guidance or use of the fillable PDF.)
CSO and inspection authority for SCI is SSO Navy. See attached SCI Addendum.
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
a. GCA NAME
NIWC Pacific
b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See Instructions)
N66001
c. ADDRESS (Include ZIP Code)
Code 22710 53560 Hull Street San Diego, CA 92152-5001
d. POC NAME
Suzanne McLaughlin
e. POC TELEPHONE (Include Area Code)
+1 (619) 553-2556
f. EMAIL ADDRESS (See Instructions) suzanne.m.mclaughlin@navy.mil
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See Instructions)
Minard, Verna F.
b. TITLE
Security's COR
c. ADDRESS (Include ZIP Code) Commanding Officer NIWC Pacific Code 83310, 53560 Hull Street, CA 92152-5001
d. AAC OF THE CONTRACTING OFFICE (See Instructions)
N66001
e. CAGE CODE OF THE PRIME CONTRACTOR
(See Instructions.)
f. TELEPHONE (Include Area Code)
+1 (619) 553-3005
g. EMAIL ADDRESS (See Instructions) verna.minard@navy.mil
h. SIGNATURE
i. DATE SIGNED (See Instructions)
20190507
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
a. CONTRACTOR
b. SUBCONTRACTOR
c. COGNIZANT SECURITY OFFICE FOR PRIME AND
SUBCONTRACTOR
d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY
ADMINISTRATION
e. ADMINISTRATIVE CONTRACTING OFFICER
f. OTHER AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)
S and Below COR, email: rebecca.hughes@navy.mil TS/SCI COR, email: megan.kline@navy.mil CS, email: suzanne.m.mclaughlin@navy.mil Security, w_spsc_ssc_pac_securitycor_us@navy.mil
Navy DD Form 254 SCI Addendum August 18, 2017
RELEASE OF SENSITIVE COMPARTMENTED INFORMATION (SCI) INTELLIGENCE
INFORMATION TO U.S. CONTRACTORS
ATTACHMENT TO DD FORM 254 FOR CONTRACT NO.: N66001-19-D-0087/ N6600117F3504
ORDER NO.:
CONTRACT ESTIMATED COMPLETION DATE (ECD): 20240506
SCI NETWORK ACCESS REQUIRED: JWICS access at the Government site.
The Cognizant Senior Intelligence Officer (SIO) has exclusive security responsibility for all Sensitive
Compartmented Information (SCI) classified material released to or developed under the contract.
Access to SCI Intelligence material requires adherence to the requirements set forth in the following: Department of Defense (DoD) Manual (DoDM) 5105.21, Volume 1, SCI Administrative
Security Manual: Administration of Information and Information Systems Security; DoDM 5105.21, Volume 2, SCI Administrative Security Manual: Administration of Physical Security, Visitor Control, and
Technical Security; DoDM 5105.21, Volume 3, SCI Administrative Security Manual: Administration of
Personnel Security, Industrial Security, and Special Activities; ICD 403, Foreign Disclosure and Release of Classified National Intelligence; ICD 703, Protection of Classified National Intelligence Including
Sensitive Compartmented Information; ICD 703-02, Reporting Requirements for Individuals with Access to Sensitive Compartmented Information; ICD 703-03, Protection of Classified National Intelligence
Including SCI Shared with Entities Outside the Intelligence Community; ICD 703-04, Foreign
Ownership, Control, or Influence (FOCI); ICD 710, Classification Management and Control Markings
Systems; ICPG 710.1, Application of Dissemination Controls: Originator Control (ORCON); DoD
5220.22-M, Change 2, National Industrial Security Program Operating Manual (NISPOM); and DoD
5220.22-R, DoD Industrial Security Program. Contractor’s will comply with all regulations/manuals/directives stated therein which provide the necessary security and classification guidance for personnel, information, physical, automated information security (AIS), and technical security measures and is a part of the SCI security specifications for the contract. Inquiries pertaining to
SCI classification guidance or interpretations shall be directed to the Contracting Officer Representative
(COR).
1. Requirements for access to SCI:
a. All SCI will be handled in accordance with special security requirements, which will be furnished by the Command Special Security Officer (SSO).
b. SCI will not be released to contractor employees without specific release approval of the originator of the material as outlined in governing directives; based on prior approval and certification of "need-to-know" by the designated COR.
c. The contractor must restrict access to only those individuals who possess the necessary security clearance and who are actually providing services under the contract with a valid need to know. Further dissemination to other contractors, subcontractors, other government agencies, private individuals or organizations is prohibited unless authorized in writing by the originating agency through the COR.
d. Names of contractor personnel requiring access to SCI will be submitted to the COR for approval. Upon receipt of written approval from the COR, the company security officer will submit request(s) for special background investigations, in accordance with the
NISPOM, to the Defense Security Service (DSS).
Navy DD Form 254 SCI Addendum August 18, 2017
e. SCI material must not be released to foreign nationals or immigrant aliens whether they are consultants, U.S. contractors, or employees of the contractor and regardless of the level of their security clearance, except with advance written permission from the originator. Requests for release to foreign nationals shall be initially forwarded to the
COR and shall include:
i. A copy of the proposed disclosure.
ii. Full justification reflecting the benefits to U.S. interests.
iii. Name, nationality, particulars of clearance, and current access authorization of each proposed foreign national recipient.
f. Contractor personnel must maintain accountability for all intelligence materials released to their custody.
g. SCI material will not be reproduced without prior approval of the originator of the material. All SCI material shall bear a prohibition against reproduction while in the contractor’s custody.
h. Inquiries pertaining to classification guidance on SCI will be directed through the Command
SSO to the responsible COR as indicated on the DD Form 254.
i. SCI released to cleared-DoD Contractors, all reproductions thereof, and all other information generated based on, or incorporating data from, in support of this contract, remains the property of the U.S. Government. Upon completion or cancellation of the contract, all SCI material furnished will be returned to the direct custody of the supporting SSO, or destroyed IAW instructions outlined by the COR.
j. SCI will be stored and maintained only in properly accredited facilities meeting the physical security requirements in ICD 705, SCI Facilities and ICS 705, Technical Specifications for
Construction and Management of SCI Facilities
k. The Space and Naval Warfare Systems Center, Pacific (SSC PAC) SSO will recognize the above noted estimated completion date (ECD) as the completion date for the contract. The SSO will initiate action to debrief contractor personnel with access to this contract unless extensions or modifications to the contract are received by the SSO office no later than 30 days after the established completion date.
l. The contractor is governed by ICD 704, ‘Personnel Security Standards and Procedures Governing
Eligibility for Access to Sensitive Compartmented Information (SCI) And Other Controlled
Access Program Information’ and may be supplemented by additional SSO Navy guidance.
Contractor personnel that are eligible for access to SCI or currently possess an SCI personnel security clearance with another non-DoD agency must have their SCI eligibility accepted and entered into JPAS by the DoD Consolidated Adjudications Facility (CAF) prior to having access to SCI information retained by SSC PAC, unescorted access to SSC PAC spaces, and receipt of an
Navy DD Form 254 SCI Addendum August 18, 2017
SSC PAC issued contractor badge. The Facility Security Officer (FSO) will identify, in writing, contractor personnel assigned to this contract by NAME, SSN, Date and Place of Birth, and provide this documentation to the COR identified. The COR will identify the SCI caveats for the contract and forward a copy of this documentation to the SSO for processing. This documentation will be marked and protected under the Privacy Act of 1974.
m. Electronic processing of SCI must be accomplished on equipment accredited in accordance with
DoDM 5105.21 Volumes 1- 3, ICD 503, Information Technology System Security Risk
Management, Certification and Accreditation, and the DoDIIS Joint Security Implementation
Guide (DJSIG), Appendix D.
n. SCI security management issues shall be directed to the SSC PAC SSO, Ms. Vanessa Rayner,
(619) 553-5138.
o. In accordance with Director of National Intelligence Memorandum 5 May 2017, Access to North
Atlantic Treaty Organization (NATO) Information by Intelligence Community (IC) Personnel and
Naval Intelligence Security Policy Directive 17-008 Revision, Mandate for North Atlantic Treaty
Organization (NATO) Information by Intelligence Community (IC) Personnel, all DoN
Contractors SCI cleared and those cleared SCI with access to JWICS or SIPRNet must be briefed into NATO Secret Information. Specific requirements shall be identified in the DD254. Direct questions to the NATO Control Officer, SSC Pacific, Ms. Verna Minard, (619) 553-3005.
**NOTE**: ADDITIONAL SECURITY GUIDANCE SPECIFIC TO THE SCI CONTRACT WILL BE
PROVIDED BY THE COR AND COMMAND SSO TO IDENTIFY SECURITY CLASSIFICATION
GUIDES AND PROGRAM SPECIFIC SECURITY GUIDANCE THAT DEFINE TECHNICAL AND
SAFEGUARDING REQUIREMENTS IDENTIFIED IN THE SOW/PWS/SOO.
DRAFT
SAMPLE
PREVIOUS EDITION IS OBSOLETE.
Page of AEM LiveCycle Designer
DD FORM 254, APR 2018
NEEDS DD67
DEPARTMENT OF DEFENSE
CONTRACT SECURITY CLASSIFICATION SPECIFICATION
(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)
OMB No. 0704-0567 OMB approval expires:
October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.
RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.
1. CLEARANCE AND SAFEGUARDING
2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)
3. THIS SPECIFICATION IS: (X and complete as applicable.)
a. ORIGINAL (Complete date in all cases.)
b. REVISED (Supersedes all previous specifications.)
4. IS THIS A FOLLOW-ON CONTRACT?
If yes, complete the following:
Classified material received or generated under
5. IS THIS A FINAL DD FORM 254?
If yes, complete the following:
6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)
7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)
8. ACTUAL PERFORMANCE (Click button to add more locations.)
10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)
e. NATIONAL INTELLIGENCE INFORMATION:
11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)
12. PUBLIC RELEASE
Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)
13. SECURITY GUIDANCE
The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.
(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)
14. ADDITIONAL SECURITY REQUIREMENTS
Requirements, in addition to NISPOM requirements for classified information, are established for this contract.
If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
15. INSPECTIONS
Elements of this contract are outside the inspection responsibility of the CSO.
If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. (See instructions for additional guidance or use of the fillable PDF.)
16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)
17. CERTIFICATION AND SIGNATURES
Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.
18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL
9.0.0.2.20120627.2.874785 DD 254, DoD Contract Security Classification Specification List of Attachments [2] (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form) IT_IT_FOR_UNCLASSIFIED_POT_CONTRACTORS_ONSITE_INTEL_FOUO_OPSEC_20190225.pdf 19D0089 T.O. 16F3504 18R0351 17R0187 DD254 SCI Addendum 18 August dtd 20190503.pdf
| CurrentPage: |
| PageCount: |
| Classification: Unclassified |
| SerialNum: 19D0089 |
| a. Facility clearance level. Select one.: 1 |
| b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 4 |
| Choose Yes or No: 1 |
| Choose Yes or No: 1 |
| Prime: N66001-19-D-0089 ECD: 20240506 |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Sub: |
| Choose Yes or No: 0 |
| Choose Yes or No: 0 |
| Soli: N66001-18-R-0351 |
| DueDate: |
| dateA: 2019-05-07 |
| RevisionNum: |
| dateB: |
| Final: |
| dateC: |
| No: 1 |
| No: 1 |
| No: 0 |
| No: 0 |
| Yes: 0 |
| Yes: 0 |
| Yes: 1 |
| Yes: 1 |
| Enter your name here.: |
| ReqDated: |
| Enter your name here.: |
| Name: |
Nathan Kunes Inc.
5055 North Harbor Drive Suite 230 San Diego CA 92106
| Name: Minard, Verna F. |
| Cage: 3DP47 |
| CSO: Defense Security Service (DSS) |
San Diego Field Office (IOFWD) 11770 Bernardo Plaza Ct.
Ste 450 San Diego, CA 92128
| addrow: |
| Removerow: |
| Click to delete a row: |
| Location: NIWC Pacific |
53560 Hull Street San Diego, CA 92152-5001
Location: SPAWARSYSCOM, San Diego, CA
NSA
U.S. Naval Vessels Block9:
Cryptographic systems and solutions, key management architecture, information systems engineering and technical services. Information assurance exploration analysis, systems, software, and test engineering services that are required to support High Assurance Internet protocol Encryptor (HAIPE), Inline Network Encryptor (INE), Link Encryption Family (LEF), cryptographic modernization, Advanced Cryptographic Capabilities (ACC), CM2, Tactical Secure Voice (TSV), Offline Network Encryption (AN/PYQ-20), Modernized Link Level COMSEC (LINK-22), Ethernet Data Encryptor (EDE), Navy Ship Site System Operational Testing (SOT) and System Operational Verification Testing (SOVT).
| a: 1 |
| a: 1 |
| a: 1 |
| f: 0 |
| f: 1 |
| f: 1 |
| b: 0 |
| b: 0 |
| b: 0 |
| g: 1 |
| g: 0 |
| c: 0 |
| c: 0 |
| c: 1 |
| h: 0 |
| h: 0 |
| d: 0 |
| d: 0 |
| d: 0 |
| i: 0 |
| i: 0 |
| SCI: 1 |
| NonSCI: 0 |
| j: 1 |
| j: 1 |
| k: 1 |
| k: 0 |
| Enter your name here.: 1) NS=SCI/JWICS/NSANet/SIPRnet and 2) NATO awareness for SIPRnet access at government site. |
| Enter your name here.: See Specific On-Site attachment for reporting, security, and training requirements. |
| Enter your name here.: S and Below COR, email: rebecca.hughes@navy.mil |
TS/SCI COR, email: megan.kline@navy.mil CS, email: suzanne.m.mclaughlin@navy.mil Security, w_spsc_ssc_pac_securitycor_us@navy.mil
| e: 0 |
| e: 1 |
| l: 1 |
| m: 1 |
| direct: 0 |
| thru: 1 |
| Enter your name here.: Naval Information Warfare Center Pacific (NIWC Pacific), Code 85000, 53560 Hull Street, San Diego, CA 92152-5001 |
| PublicAuthority: |
| AddSig: |
| RemoveSig: |
| text: Solicitation / Contract Numbers: N66001-18-R-0351 (old N66001-17-R-0187) / N66001-19-D-0089 |
Block 12 Continuation: Release of COMSEC, SCI, and NATO (Read-on IAW with the National Intelligence Security Policy Directive 17-008; NATO access is not required on this contract, see phrase 10.g/k(1)) material is not authorized.
Security Classification Guide (SCG): Work to be performed at government; SCGs to be provided under separate cover by the COR. All classified guides will be reviewed at the government site. Information Assurance (IA) Vulnerabilities and Weaknesses (U) 3-02 dated 08 July 05 // (U) Classification Guide for Quantum Defense by NSA dated 25 May 2016 // (U) Cryptographic Modernization (CryptoMod) by NSA dated 1 February 2010 //(U) High Assurance Internet Protocol Encryptor Program (HAIPE) by NSA dated 26 June 2007.
The Code 58110 Branch Head, Kevin Chung, (619) 553-3363, email: kevin.chung@navy.mil.
Direct all Collateral Top Secret and SCI questions to the Contracting Officer's Representative (COR) Megan Kline, Code 58230,
(619) 553-6036, email: megan.kline@navy.mil.
Direct all Secret and Below questions to the COR Rebecca Hughes, Code 58006, (619) 553-9184, email: rebecca.hughes@navy.mil.
The Contract Specialist (CS) Suzanne McLaughlin, Code 22710, (619) 553-2556, email: suzanne.m.mclaughlin@navy.mil.
Prime contractor's are required to send copies of all subcontract DD Form 254s to obtain flow-down approvals as required to the distribution listed in block 17: NIWC Pacific Codes 58110, and 58230/58006 (PM/CORs), 22710 (CS) see above and 83310 - Security - w_spsc_ssc_pac_securitycor_us@navy.mil. external address only.
Access Requirements:
10.a Further disclosure, to include subcontracting, of COMSEC information by a contractor requires prior approval of the NIWC Pacific COR. Access to any COMSEC information requires special briefings at the contractor facility. Access to classified COMSEC information requires a final U.S. Government clearance at the appropriate level. Use of COMSEC information is governed by the NSA Industrial COMSEC Manual, NSA/CSS Policy Manual 3-16. Contractors that will be designated CMS users must attend an initial CMS user training class that is given by the NIWC Pacific CMS office. If you have questions call (619) 553-5065. (Access is for COMSEC equipment/material)
10.e(1) The SSO Navy has exclusive security responsibility for all SCI classified material released or developed under this contract. DSS is relieved of security inspection responsibility for all such material but retains responsibility for all non-SCI classified material released to or developed under this contract. Further disclosure to include subcontracting of SCI is prohibited prior until approval is received from the SCI cleared NIWC Pacific COR, NIWC Pacific Code 874 and SSO Navy is required for sub-contracting. Special briefings and procedures are all required at the contractor's facility. Access to SCI information requires a final U.S. Government clearance at the appropriate level and will be performed within U.S. Government facilities only. Requesting approval for incidental SCI access, i.e., enter spaces, attend meetings, and briefings as long as the contractor is not producing a SCI product.
Contractor personnel assigned to this effort who require access to SCI data and spaces must possess a current SSBI with ICD 704 eligibility (which replaced DCID 6/4 eligibility).
Contract performance for incidental SCI is restricted to NIWC Pacific, San Diego, CA.
10.g/k(1) Effective immediately all contractor personnel with SCI access must be read-on NATO secret with an entry into JPAS prior to being granted access. This contract requires SCI cleared personnel to access JWICS/NSAnet/SIPRnet. In addition, the contractor shall complete the derivative classification training; the special NATO briefing and derivative classification briefing are provided by the contracting company's facility security officer. This requirement is mandated per the national intelligence security policy directive 17-008. This read-on meets the mandated requirement; however, contractor does require access to NATO on this contract. Contractor is not authorized to have NATO at its contractors facility. JWICS/SIPRnet under the SPAWAR Claimancy is not accredited to receive or process NATO restricted up to NATO secret data. Questions, contact the GCA NATO Control Office 619-553-3005/3191. Subcontract DD254s require approval from the GCA NCO prior to access being granted. Policies: DOD M-5200.1 Volume 1, enclosure (3) and USSAN 1-07.
10.j/11.l Contractors receiving, transmitting or accessing controlled unclassified technical information (CUI) on or through its contractor information system(s) must safeguard the information to avoid compromise, including but not limited to disclosure of information to unauthorized persons, unauthorized modification, destruction, or loss of an object, or the copying of information to unauthorized media, as required per DFARS Subpart 204.73 and Clauses 204.7304 and 252.204-7012. Contractors shall report to the DOD each Cyber incident that affects unclassified controlled technical information resident on or transiting contractor information systems in accordance with DFARS clause 204.7304 and 252.204-7012. Detailed reporting criteria and requirements are set forth in the clause at 252.204-7012, safeguarding of unclassified controlled technical information. For information on handling CUI see DoD M-5200.01, Volume 4.
10.k(2) Some contractor personnel that work on Top Secret and below requirements without SCI or do not require access to NATO classified data are only required to receive the NATO Awareness Brief for the sole purpose of accessing SIPRnet. The special briefing is provided by the contracting company's Facility Security Officer (FSO). Note: For this awareness brief there is no requirement for the contractor to make an entry in JPAS. The contractor shall complete Derivative Classification training prior to being granted access to SIPRnet; training is provided by the company’s FSO. Policy: DOD M-5200.01 Volume 1, enclosure (3).
11.a Contract performance is restricted to SPAWARSYSCOM, San Diego, CA, NIWC Pacific, San Diego, CA, NSA, other authorized DoD locations, and U.S. naval vessels. NIWC Pacific-COR will provide security classification guidance for performance of this contract.
11.f Access to classified U.S. government information may be required at the following overseas locations: UK, Canada, Australia, and various US Naval Ports aboard. Antiterrorism/force protection briefing within one year of departure and a country specific briefing within 90 days of departure. Anti-terrorism/force protection (AT/FP) briefings are required for all personnel (military, DoD civilian, and contractor) per OPNAVINST F3300.53C. Contractor employees must receive the AT/FP briefing annually. The briefing is available at joint knowledge online (jko): https://jkodirect.jten.mil (prefix): course number: us007; title: Level 1 Anti-terrorism awareness training, if experiencing problems accessing this website contact the JKO Help Desk (24 hours a day/7 days a week, jkohelpdesk@jten.mil, 757-203-5654). The website will allow contractors who do not have a CAC to access the training. Sere 100.2 Level A code of conduct training is also required prior to OCONUS travel for all personnel. Sere 100.2 Level A training can be accessed at http://jko.jfcom.mil (recommended), https://jkodirect.jten.mil/atlas2/faces/page/login/login.seam, recommended course: prefix: j3t: course #: a-us1329, for civilian, military, and contractors. Personnel utilizing this site must have a CAC. A Sere 100.2 Level A training disk can be borrowed at the NIWC Pacific Point Loma Office or Old Town Campus Office. Specialized training for specific locations, such as SOUTHCOM Human Rights, or U.S. Forces Korea entry training, may also be required; NIWC Pacific security personnel will inform you if there are additional training requirements. Finally, EUCOM has mandated that all personnel going on official travel to the EUCOM AOR must now register with the smart traveler enrollment program (STEP). When you sign up, you will automatically receive the most current information the State Department compiles about your destination country. You will also receive updates, including travel warnings and travel alerts. Sign up is one-time only, after you have established your step account, you can easily add official or personal travel to anywhere in the world, not just EUCOM. http://travel.state.gov/content/passports/en/go/step.html.
11.j Contractors are required to take Operation Security training. Additional OPSEC information is attached.
11.m See Specific-On-site Attachment for reporting, security, and training requirements such as contractors performing on classified contracts are required to attend Counterintelligence (CI) training annually IAW DoDD 5240.06 (Counterintelligence Awareness and Reporting (CIAR)).
The NIWC Pacific-COR will specify which positions require a clearance.
Changes: Submitting award DD254 for Prime contractor CAGE code: 3DP47 to be authorized incidental SCI access at the government site. RFP was originally approved by IRCCO and SSO Navy under N66001-17-R-0187 for incidental SCI access. Solicitation is being updated to include new Solicitation N66001-18-R-0351 and is submitted to Code 874 to approve this administrative change.
No further entries on this page.
text:
Branch Head, Kevin Chung, Code 58110 Megan Kline, SCI COR, Code 58230 text:
SCI Requirements Validation
| attachmentsList: |
| AddAttachment: |
| ViewAttachment: |
| RemoveAttachment: |
| rep: Megan Kline, COR, Code 58230 |
| rep: Kathy Steffel, Head, IRC and Special Project Office, Code 874, NIWC Pacific |
| Sig: |
| Enter your name here.: |
Information Technology (IT) Systems Personnel Security Program Requirements are attached and must be passed to subcontractors.
Information Technology (IT) Systems Personnel Security Program Requirements for Unclassified/Position of Trust (POT) Contractors and Must be Passed Down to Subcontractors.
Specific On-Site Security Requirements are Attached. This document contains reporting, security, and training requirements. For authorized visits to other U.S. Government activities, the contractor must comply with all On-site Security requirements of the Host Command.
Intelligence Information attachment For Official Use Only (FOUO) guidance attached.
Operations Security (OPSEC) requirements attached and must be passed to all Subcontractors.
Release of Sensitive Compartmented Information (SCI) Intelligence Information to U.S. Contractors.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .