Attachment 3 - DD254.pdf

PDF 864 KB Posted

Attached to
Combined Synopsis Solicitation for Locksmith Services Federal contract opportunity
Solicitation number
N66001-19-Q-0083
Issued by
Department of the Navy Information Warfare Systems Command

View the file

Other files for this federal contract opportunity

Other files attached to Combined Synopsis Solicitation for Locksmith Services, newest first.
File Type Posted
Attachment 1 - Performance Work Statement Rev2.docx DOCX document
Attachment 4 - WD 2015-5636 Rev10.pdf PDF
Attachment 2 - Price Volume.xlsx XLSX spreadsheet
Attachment 5 - CDRL.doc DOC document
Attachment 6 - Reference Information Sheet.doc DOC document
CDRL_A001_Staffing_Plan_Att_2.xls XLS spreadsheet
Combined SynopsisSolicitation - N66001-19-Q-0083.docx DOCX document
Attachment 1 - Performance Work Statement.docx DOCX document
Attachment 4 - WD 2015-5636.pdf PDF
CDRL_A001_Staffing_Plan_Att_1.xls XLS spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CLASSIFICATION (When filled in):

PREVIOUS EDITION IS OBSOLETE. Page 1 of 3 AEM LiveCycle Designer

PREVIOUS EDITION IS OBSOLETE. Page 1 of 3 AEM LiveCycle Designer

DD DD FFOORMRM 252544,, APR 2018

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

October 31, 2020

The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED (See Instructions)

b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/

MATERIAL REQUIRED AT CONTRACTOR FACILITY

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

a. PRIME CONTRACT NUMBER (See instructions.)

b. SUBCONTRACT NUMBER

c. SOLICITATION OR OTHER NUMBER DUE DATE (YYYYMMDD)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

DATE (YYYYMMDD)

b. REVISED (Supersedes all previous specifications.)

REVISION NO. DATE (YYYYMMDD)

c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)

4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:

Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.

5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:

In response to the contractor's request dated , retention of the classified material is authorized for the period of:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

7. SUBCONTRACTOR(S)

(-- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor.)

a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

8. ACTUAL PERFORMANCE

a. LOCATION(S) (For actual performance, see instructions.) b. CAGE CODE (If applicable, see Instructions.)

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT

(Additional Performance Locations are located in block 13)

Unclassified

Unclassified

Top Secret None

✘ N66001-19-R-0083

2019/04/19

NIWC PACIFIC, 53560 Hull Street, San Diego, CA 92152-5001

N66001 San Diego Field Office, Defense Security Service 11770 Bernardo Plaza Court Suite 450 San Diego, CA 92128-2426

Perform services to maintain mechanical access control systems.

PREVIOUS EDITION IS OBSOLETE. Page 2 of 3 AEM LiveCycle Designer

PREVIOUS EDITION IS OBSOLETE. Page 2 of 3 AEM LiveCycle Designer

DD DD FFOORMRM 252544,, APR 2018

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION

b. RESTRICTED DATA

g. NORTH ATLANTIC TREATY ORGANIZATION

(NATO) INFORMATION

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.)

h. FOREIGN GOVERMENT INFORMATION

d. FORMERLY RESTRICTED DATA

i. ALTERNATIVE COMPENSATORY CONTROL MEASURES

(ACCM) INFORMATION

e. NATIONAL INTELLIGENCE INFORMATION:

(1) Sensitive Compartmented Information (SCI)

(2) Non-SCI

j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)

k. OTHER (Specify) (See instructions.)

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT

ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT

ACTIVITY

(Applicable only if there is no access or storage required at contractor facility.

See instructions.)

b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY

c. RECEIVE, STORE, AND GENERATE CLASSIFIED

INFORMATION OR MATERIAL

d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

e. PERFORM SERVICES ONLY

f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE

THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST

TERRITORIES

g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE

TECHNICAL INFORMATION CENTER (DTIC) OR OTHER

SECONDARY DISTRIBUTION CENTER

h. REQUIRE A COMSEC ACCOUNT

i. HAVE A TEMPEST REQUIREMENT

j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE

l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED

INFORMATION (CUI).

(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)

m. OTHER (Specify) (See instructions.)

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.

Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

DIRECT THROUGH (Specify below) Public Release Authority:

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;

and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. See instructions for additional guidance.)

List of Attachments (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)

Block 12 Continued: Release of Restricted Data, CNWDI, Formerly Restricted Data, and NATO information are not authorized.

Security Classification Guide (SCG): Work to be performed at the government site; COR to provide SCG as needed. ID # 04-018.2 "DoD Locks, Safes, Vaults, and Seals Program".

Direct all questions to the Contracting Officer's Representative (COR) Nikki Lightfoot, Code 83320, (619) 553-4619, email: nikki.lightfoot@navy.mil.

SEE SECTION 13 CONTINUATION SECTION AT THE BOTTOM OF THIS FORM

Unclassified

Unclassified

SEE SECTION 13 CONTINUATION SECTION AT THE BOTTOM OF

THIS FORM

[IT_IT_FOR_UNCLASSIFIED_Position_Of_Trust_CONTRACTORS_ONSITE_FOUO_OPSEC_20190225.pdf - LINE_14]

SEE SECTION 13 CONTINUATION SECTION AT THE BOTTOM OF THIS

FORM

PREVIOUS EDITION IS OBSOLETE. Page 3 of 3 AEM LiveCycle Designer

PREVIOUS EDITION IS OBSOLETE. Page 3 of 3 AEM LiveCycle Designer

DD DD FFOORMRM 252544,, APR 2018

NAME & TITLE OF REVIEWING OFFICIAL SIGNATURE

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

No Yes If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. (See instructions for additional guidance.)

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

No Yes If Yes, explain and identify specific areas and government activity responsible for inspections. (See instructions for additional guidance.)

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

a. GCA NAME

b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See Instructions)

c. ADDRESS (Include ZIP Code) d. POC NAME

e. POC TELEPHONE (Include Area Code)

f. EMAIL ADDRESS (See Instructions)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.

a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See Instructions)

b. TITLE

c. ADDRESS (Include ZIP Code)

d. AAC OF THE CONTRACTING OFFICE (See Instructions)

e. CAGE CODE OF THE PRIME CONTRACTOR (See Instructions.)

f. TELEPHONE (Include Area Code)

g. EMAIL ADDRESS (See Instructions)

h. SIGNATURE

i. DATE SIGNED (See Instructions)

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

a. CONTRACTOR

b. SUBCONTRACTOR

c. COGNIZANT SECURITY OFFICE FOR PRIME AND

SUBCONTRACTOR

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY

ADMINISTRATION

e. ADMINISTRATIVE CONTRACTING OFFICER

f. OTHER AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)

Unclassified

Unclassified

Information Technology (IT) Systems Personnel Security Program Requirements are attached and must be passed to subcontractors.

Information Technology (IT) Systems Personnel Security Program Requirements for Unclassified/Position of Trust (POT) Contractors and Must be Passed Down to Subcontractors.

Specific On-Site Security Requirements are Attached. This document contains reporting and training requirements. For authorized visits to other U.S. Government activities, the contractor must comply with all On-site Security requirements of the Host Command.

For Official Use Only (FOUO) guidance attached.

Operations Security (OPSEC) requirements attached and must be passed to all Subcontractors.

Verna Minard Security Administration Verna Minard

Naval Information Warfare Center Pacific Attn: Code 22710, 53560 Hull Street, San Diego, CA, 92152-5001

Micah Sandusky

(619) 553-4489

N66001 micah.sandusky@navy.mil

Verna Minard N66001

Security Administration

Verna Minard

NIWC PACIFIC, 4297 PACIFIC HIGHWAY BLDG 7 SAN DIEGO CA 92110-

5000, SAN DIEGO, CA, 92110-5000

619-553-3005 2019/04/19 verna.minard@navy.mil nikki.lightfoot@navy.mil, micah.sandusky@navy.mil, w_spsc_ssc_pac_securitycor_us@navy.mil

13. SECURITY GUIDANCE. The security classification guidance needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes: to challenge the guidance or classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any document/guides/extracts referenced herein.

Add additional pages as needed to provide complete guidance.

CONTINUATION OF ITEM 13

[Block: 13 Continuation]

The Contracting Specialist (CS) Micah Sandusky, Code 22710, (619) 553-4489, email: micah.sandusky@navy.mil.

-Prime contractor's are required to send copies of all subcontract DD Form 254s to obtain flow-down approvals as required to the distribution listed in block 17: NIWC Pacific Codes 83320 (COR), 22710 (CS) see above and 83310 - Security - w_spsc_ssc_pac_securitycor_us@navy.mil external address only.

Direct all questions to the Contracting Officer's Representative (COR) Nikki Lightfoot, Code 83320, (619) 553-4619, email: nikki.lightfoot@navy.mil.

The Contracting Specialist (CS) Micah Sandusky, Code 22710, (619) 553-4489, email: micah.sandusky@navy.mil.

-Prime contractor's are required to send copies of all subcontract DD Form 254s to obtain flow-down approvals as required to the distribution listed in block 17: NIWC Pacific Codes 83320 (COR), 22710 (CS) see above and 83310 - Security - w_spsc_ssc_pac_securitycor_us@navy.mil external address only.

Ref 10b: Restricted Data Information is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level.

Written concurrence of the GCA is required prior to subcontracting. : Access to Restricted Data requires a final U.S. government clearance at the appropriate level. The possibility exists that the locksmith contractor may come into accidental contact with the above information while servicing classified containers, vaults and strongrooms.

Ref 10c: CNWDI Information is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. Written concurrence of the GCA is required prior to subcontracting. : Permission of the NIWC Pacific technical code/COR is required prior to subcontracting CNWDI.

Special briefings and procedures are also required. Access to CNWDI requires a Final U.S. Government granted clearance at the appropriate level. The possibility exists that the locksmith contractor may come into accidental contact with the above information while servicing classified containers, vaults and strongrooms.

Ref 10d: The contractor is permitted access to Formerly Restricted Data (FRD) in the performance of this contract. Access to FRD requires a final U.S.

Government clearance at the appropriate level. Written concurrence of the GCA is required prior to subcontracting. : Further disclosure, to include subcontracting, of Formerly Restricted Data by a contractor requires prior approval from NIWC Pacific technical code/COR. Special briefings and procedures are also required at the contractor’s facility. Access to formerly restricted date requires a final U.S. government clearance at the appropriate level. The possibility exists that the locksmith contractor may come into accidental contact with the above information while servicing classified containers, vaults and strongrooms.

Ref 10g: Personnel not assigned to a NATO staff position, but requiring access to NATO classified information, NATO COSMIC, NATO Secret or access to the NATO accredited SIPRNET terminals, must possess the equivalent FINAL or Interim U.S. Security Clearance based upon the appropriate personnel security investigation required. Personnel with access to NATO ATOMAL information must have the appropriate level FINAL U.S. Security Clearance. The government program/project manager is the designated representative that will ensure the contractor security manager and concerned employees are NATO briefed prior to access being granted. The contractor will maintain strict compliance in regards to NATO information IAW NISPOM Ch 10, Section 7. Prior approval from the GCA is required for subcontracting. : NATO information: This means information/documents belonging to, and circulated by, the North Atlantic Treaty Organization (NATO). Access to NATO information requires a final U.S. government clearance at the appropriate level and a special briefing.

The special briefing is provided by the contracting company's facility security officer. Prior approval from the contracting activity's NATO Control Officer (NCO)/Alternate (code 83310, (619) 553-3005/3191) is required before the prime contractor or a subcontractor facility can be granted access (read-on) to NATO material no exceptions for this contract. Contractor shall follow requirements noted in DoD M-5200.01, Volume 1, enclosure (3) and USSAN 1-07.

Contractor is not authorized to have hold NATO data at its contractor's facility on this contract.

The NIWC Pacific NATO Control Officer/alternate have reviewed the requirement supporting this contractual obligation in which the locksmiths must be NATO read-on because of the possible viewing of NATO documents while changing combinations.

Ref 10h: Foreign Government Information (FGI) is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. Written concurrence of the GCA is required prior to subcontracting. : Prior approval of NIWC Pacific technical/COR is required for subcontracting. Access to any foreign government information requires special briefings at the contractor facility. Due to the nature of this contract, the possibility exists that the contractor may have visual contact of foreign government information.

Ref 10j: For Official Use Only (FOUO) Information generated and/or provided under this contract shall be safeguarded and marked as specified in DoD Manual 5200.1 Volumes 1-4 . : Contractors receiving, transmitting or accessing controlled unclassified technical information (CUI) on or through its contractor information system(s) must safeguard the information to avoid compromise, including but not limited to disclosure of information to unauthorized persons, unauthorized modification, destruction, or loss of an object, or the copying of information to unauthorized media, as required per DFARS Subpart

204.73 and Clauses 204.7304 and 252.204-7012. Contractors shall report to the DOD each Cyber incident that affects unclassified controlled technical information resident on or transiting contractor information systems in accordance with DFARS clause 204.7304 and 252.204-7012. Detailed reporting criteria and requirements are set forth in the clause at 252.204-7012, safeguarding of unclassified controlled technical information. For information on handling CUI see DOD M-5200.01, Volume 4.

Ref 11a: Contractor performance is restricted to locations identified in Block 13. Government agency or activity will provide security classification guidance for performance of this contract. : Contract performance is restricted to NIWC Pacific, San Diego, CA, COMSPAWARSYSCOM. NIWC Pacific-COR will provide security classification guidance for performance of this contract.

Ref 11e: Contractor is not allowed to Fabricate, Modify, or Store Classified Hardware. Perform services only. : Contract is for mechanical access control systems support services. Cleared personnel are required to perform this service because escorting personnel or sanitization of the work space cannot preclude access to classified information.

13. SECURITY GUIDANCE. The security classification guidance needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes: to challenge the guidance or classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any document/guides/extracts referenced herein.

Add additional pages as needed to provide complete guidance.

CONTINUATION OF ITEM 13

Ref 11j : Contractors are required to take Operation Security training. Additional OPSEC information is attached.

[Block: 8] [Location] SPACE AND NAVAL WARFARE SYSTEMS COMMAND, 4297 PACIFIC HIGHWAY, SAN DIEGO CA 92110-5000 [Location Code] N00039 [Cognizant Security Office] San Diego Field Office, Defense Security Service 11770 Bernardo Plaza Court Suite 450 San Diego, CA 92128-2426

[Block: 11M] See Specific-On-site for reporting, security, and training requirements such as contractors performing on classified contracts are required to attend Counterintelligence (CI) training annually IAW DoDD 5240.06 (Counterintelligence Awareness and Reporting (CIAR)).

[Block: 12] DoDAAC[N66001] Ouid[N66001] Release Information[Naval Information Warfare Center Pacific (NIWC Pacific), Code 85000, 53500 Hull Street, San Diego, CA 92152-5001]

Location Code/Agency Name/Address[N66001, NIWC PACIFIC NIWC PACIFIC, 4297 PACIFIC HIGHWAY BLDG 7 SAN DIEGO CA 92110-5000, SAN DIEGO, CA, 92110-5000]

CONTINUATION - DD FORM 254 ITEM 13: N66001-19-R-0083

INFORMATION TECHNOLOGY (IT) SYSTEMS

PERSONNEL SECURITY PROGRAM REQUIREMENTS

The U.S. Government conducts trustworthiness investigations of personnel who are assigned to positions that directly or indirectly affect the operation of unclassified IT resources and systems that process Department of

Defense (DoD) information, to include For Official Use Only (FOUO) and other controlled unclassified information.

The United States Office of Personnel Management (OPM), National Background Investigation Bureau (NBIB) process all requests for U.S. Government trustworthiness investigations. Requirements for these investigations are outlined in paragraph C3.6.15 and Appendix 10 of DoD 5200.2-R, available at http://www.dtic.mil/whs/directives/corres/dir.html. Personnel occupying an IT Position shall be designated as filling one of the IT Position Categories listed below. The contractor shall include all of these requirements in any subcontracts involving IT support. (Note: Terminology used in DoD 5200.2-R references “ADP” vice “IT”. For purposes of this requirement, the terms ADP and IT are synonymous.)

The Program Manager (PM), Contracting Officer’s Representative (COR) or Technical Representative (TR) shall determine the IT Position category for the contractor personnel.

DoDD Directive 8500.01, Subject: Cybersecurity, stipulates cybersecurity requirements such as "Cybersecurity workforce functions must be identified and managed, and personnel performing cybersecurity functions will be appropriately screened in accordance with this instruction and DoD 5200.2-R and qualified in accordance with

DoDD 8570.01 and supporting issuances”. DoD 5200.2-R stipulates the requirements for background investigations, special access and IT position designations and requirements. An appropriate security clearance and non-disclosure agreement are also required for access to classified information” in accordance with DoDM 5200.01

Vol. 1. DoD 5200.2-R and DoDD 5200.2 require all persons assigned to sensitive positions or assigned to sensitive duties be U.S. citizens. All persons assigned to IT-I and IT-II positions, as well as all persons with access to controlled unclassified information (without regard to degree of IT access) or performing other duties that are considered "sensitive" as defined in DoDD 5200.2 and DoD 5200.2-R must be U.S. citizens. Furthermore, access by non-citizens to unclassified export controlled data will only be granted to persons pursuant to the export control laws of the U.S. The categories of controlled unclassified information are specified in DoDM 5200.01 Vol. 4. These same restrictions apply to "Representatives of a Foreign Interest" as defined by DoD 5220.22-M (National Industrial

Security Program Operating Manual, NISPOM). DoD 8570.01-M further stipulates additional training and/or certification that is required by all persons assigned to Information Assurance functions.

I. Criteria For Designating Positions: updated per OPM Federal Investigations Notice No. 16-02, dated

October 6, 2015:

a. Tier 5/5R = IT-I Position (Privileged)

Responsibility or the development and administration of Government computer security programs, and including direction and control of risk analysis and/or threat assessment.

Significant involvement in life-critical or mission-critical systems.

Responsibility for the preparation or approval of data for input into a system, which does not necessarily involve personal access to the system, but with relatively high risk for effecting grave damage or realizing significant personal gain.

Relatively high risk assignments associated with or directly involving the accounting, disbursement, or authorization for disbursement from systems of (1) dollar amounts of $10 million per year or greater, or (2) lesser amounts if the activities of the individual are not subject to technical review by higher authority in the IT-I category to ensure the integrity of the system.

Positions involving major responsibility for the direction, planning, design, testing, maintenance, operation, monitoring, and/or management of systems hardware and software.

Other positions as designated by Naval Information Warfare Center Pacific (NIWC Pacific) that involve relatively high risk for effecting grave damage or realizing significant personal gain.

Personnel whose duties meet the criteria for IT-I Position designation require a favorably adjudicated Single Scope

Background Investigation (SSBI) or SSBI Periodic Reinvestigation (SSBI-PR) or Tier 5/5R. The SSBI or SSBI-PR or Tier 5/5R shall be updated every 5 years by using the Electronic Questionnaire for Investigation Processing

(eQIP) web based program (SF86 format).

b. Tier 3/3R = IT-II Position (Limited Privileged)

Responsibility for systems design, operation, testing, maintenance, and/or monitoring that is carried out under technical review of higher authority in the IT-I category, includes but is not limited to:

Access to and/or processing of proprietary data, information requiring protection under the Privacy

Act of 1974, and Government-developed privileged information involving the award of contracts;

Accounting, disbursement, or authorization for disbursement from systems of dollar amounts less than $10 million per year. Other positions are designated by Naval Information Warfare Center

Pacific (NIWC Pacific) that involve a degree of access to a system that creates a significant potential for damage or personal gain less than that in IT-I positions. Personnel whose duties meet the criteria for an IT-II Position require a favorably adjudicated National Agency Check with

Local Agency Check and Credit Check (NACLC) or Tier 3/3R.

c. Tier 1/1R is for Unclassified – Non-Sensitive positions = IT-III Position (Non-Privileged)

All other positions involving Federal IT activities. Incumbent in this position has non-privileged access to one or more DoD information systems, application, or database to which they are authorized access. Personnel whose duties meet the criteria for an IT-III Position designation require a favorably adjudicated National Agency Check with Inquiries (NACI) or Tier 1/1R.

d. Qualified Cleared Personnel Do NOT Require Trustworthiness Investigations:

When background investigations supporting clearance eligibility have been submitted and/or adjudicated to support assignment to sensitive national security positions, a separate investigation to support IT access will normally not be required.

A determination that an individual is NOT eligible for assignment to a position of trust will result in the removal of eligibility for security clearance. Likewise, a determination that an individual is NOT eligible for a security clearance will result in the denial of eligibility for a position of trust.

II. Visit Authorization Requests (VARs) for Qualified Employees:

Contractors that have been awarded a classified contract must submit visit requests using “only” the Joint Personnel

Adjudication System (JPAS). All government activities have been directed to use JPAS when transmitting or receiving VARS. Therefore, contractors who work on classified contracts are required to have established an account through JPAS for their facility. This database contains all U.S. citizens who have received a clearance of

Confidential, Secret, and/or Top Secret. The visit request can be submitted for up to one year. When submitting a visit requests to NIWC Pacific, use its Security Management Office (SMO) number (660015). This information is provided in accordance with guidance provided to contractors via the Defense Security Service (DSS) website https://www.dss.mil/ (DSS guidance dated 24 April 2007, subject: Procedures Governing the Use of JPAS by

Cleared Contractors).

III. Employment Terminations:

The contractor shall:

Immediately notify the COR or TR of the employee’s termination.

Send email to W_SPSC_SSC_PAC_clearance_US@navy.mil, Code 83310 notifying them of the termination.

Fax a termination VAL to Code 83320 at (619) 553-6169.

Return any badge and decal to Commanding Officer, Naval Information Warfare Center Pacific, Attn:

Code 83320, 53560 Hull Street, San Diego, CA 92152-5001.

INFORMATION TECHNOLOGY (IT) SYSTEMS PERSONNEL SECURITY PROGRAM

REQUIREMENTS FOR UNCLASSIFIED/POSITION OF TRUST (POT) CONTRACTORS

The U.S. Government conducts trustworthiness investigations of personnel who are assigned to positions that directly or indirectly affect the operation of unclassified IT resources and systems that process Department of

Defense (DoD) information, to include For Official Use Only (FOUO) and other controlled unclassified information.

The United States Office of Personnel Management (OPM), National Background Investigation Bureau (NBIB) process all requests for U.S. Government trustworthiness investigations. Requirements for these investigations are outlined in paragraph C3.6.15 and Appendix 10 of DoD 5200.2-R, available at http://www.dtic.mil/whs/directives/corres/dir.html. Personnel occupying an IT Position shall be designated as filling one of the IT Position Categories listed below. The contractor shall include all of these requirements in any subcontracts involving IT support. (Note: Terminology used in DoD 5200.2-R references “ADP” vice “IT”. For purposes of this requirement, the terms ADP and IT are synonymous.)

The Program Manager (PM), Contracting Officer’s Representative (COR) or Technical Representative (TR) shall determine the IT Position category for the contractor personnel.

DoDD Directive 8500.01, Subject: Cybersecurity, stipulates cybersecurity requirements such as "Cybersecurity workforce functions must be identified and managed, and personnel performing cybersecurity functions will be appropriately screened in accordance with this instruction and DoD 5200.2-R and qualified in accordance with

DoDD 8570.01 and supporting issuances”. DoD 5200.2-R stipulates the requirements for background investigations, special access and IT position designations and requirements. An appropriate security clearance and non-disclosure agreement are also required for access to classified information” in accordance with DoDM 5200.01

Vol. 1. DoD 5200.2-R and DoDD 5200.2 require all persons assigned to sensitive positions or assigned to sensitive duties be U.S. citizens. All persons assigned to IT-I and IT-II positions, as well as all persons with access to controlled unclassified information (without regard to degree of IT access) or performing other duties that are considered "sensitive" as defined in DoDD 5200.2 and DoD 5200.2-R must be U.S. citizens. Furthermore, access by non-citizens to unclassified export controlled data will only be granted to persons pursuant to the export control laws of the U.S. The categories of controlled unclassified information are specified in DoDM 5200.01 Vol. 4. These same restrictions apply to "Representatives of a Foreign Interest" as defined by DoD 5220.22-M (National Industrial

Security Program Operating Manual, NISPOM). DoD 8570.01-M further stipulates additional training and/or certification that is required by all persons assigned to Information Assurance functions.

IV. Criteria For Designating Positions: updated per OPM Federal Investigations Notice No. 16-02, dated

October 6, 2015:

e. Tier 5/5R = IT-I Position (Privileged)

Responsibility or the development and administration of Government computer security programs, and including direction and control of risk analysis and/or threat assessment.

Significant involvement in life-critical or mission-critical systems.

Responsibility for the preparation or approval of data for input into a system, which does not necessarily involve personal access to the system, but with relatively high risk for effecting grave damage or realizing significant personal gain.

Relatively high risk assignments associated with or directly involving the accounting, disbursement, or authorization for disbursement from systems of (1) dollar amounts of $10 million per year or greater, or (2) lesser amounts if the activities of the individual are not subject to technical review by higher authority in the IT-I category to ensure the integrity of the system.

Positions involving major responsibility for the direction, planning, design, testing, maintenance, operation, monitoring, and/or management of systems hardware and software.

Other positions as designated by Naval Information Warfare Center Pacific (NIWC Pacific) that involve relatively high risk for effecting grave damage or realizing significant personal gain.

Personnel whose duties meet the criteria for IT-I Position designation require a favorably adjudicated Single Scope

Background Investigation (SSBI) or SSBI Periodic Reinvestigation (SSBI-PR) or Tier 5/5R. The SSBI or SSBI-PR or Tier 5/5R shall be updated every 5 years by using the Electronic Questionnaire for Investigation Processing

(eQIP) web based program (SF86 format).

f. Tier 3/3R = IT-II Position (Limited Privileged)

Responsibility for systems design, operation, testing, maintenance, and/or monitoring that is carried out under technical review of higher authority in the IT-I category, includes but is not limited to:

Access to and/or processing of proprietary data, information requiring protection under the Privacy

Act of 1974, and Government-developed privileged information involving the award of contracts;

Accounting, disbursement, or authorization for disbursement from systems of dollar amounts less than $10 million per year. Other positions are designated by Naval Information Warfare Center

Pacific (NIWC Pacific) that involve a degree of access to a system that creates a significant potential for damage or personal gain less than that in IT-I positions. Personnel whose duties meet the criteria for an IT-II Position require a favorably adjudicated National Agency Check with

Local Agency Check and Credit Check (NACLC) or Tier 3/3R.

g. Tier 1/1R is for Unclassified – Non-Sensitive positions = IT-III Position (Non-Privileged)

All other positions involving Federal IT activities. Incumbent in this position has non-privileged access to one or more DoD information systems, application, or database to which they are authorized access. Personnel whose duties meet the criteria for an IT-III Position designation require a favorably adjudicated National Agency Check with Inquiries (NACI) or Tier 1/1R.

V. Procedures for submitting U.S. Government Trustworthiness Investigations:

Only the e-QIP version of SF-85 and SF 86 are acceptable by OPM-NBIB.

After determining that an individual requires Public Trust Position determination, the FSO will identify the individual to the COR. The COR will notify NIWC Pacific Personnel Security Office with the specific IT Level category assigned for requesting the appropriate type of investigation. The FSO will also provide the following information to the COR so that the NIWC Pacific Personnel Security Office can initiate a request thru e-QIP:

Full SSN of the applicant

Full Name

Date of Birth

Place of Birth

Email Address

Phone Number

A spreadsheet will be provided by the COR for the FSO to complete that includes the above information and any additional information required by the Personnel Security Office.

The Personnel Security Office will send email notification and instructions to the applicant to complete and submit e-QIP expeditiously.

The FSO or NIWC Pacific Personnel Security Office will take and submit fingerprints using SF-87, FD-258 or electronic submission. The FSO must obtain from NIWC Pacific Personnel Security Office the e-QIP Request

Number for inclusion in submitting the fingerprints. For immediate fingerprint result, electronic transmission of fingerprints is encouraged. OPM no longer accepts the submission of hard copy fingerprints (SF-87 or FD-258).

If fingerprints are obtained via hardcopy, the hardcopies will be sent to NIWC Pacific Personnel Security via

Priority, Certified, or Express mail:

COMMANDING OFFICER, NIWC

ATTN: Personnel Security, Code 83310

53560 Hull St

San Diego CA 92152

NIWC Pacific Personnel Security Office will update Joint Personnel Adjudication System (JPAS), PSQ Sent Date, when the Public Trust Investigation request is released to the Parent Agency, OPM.

Contractor fitness determinations made by the DOD CAF are maintained in the JPAS. Favorable fitness determinations will support public trust positions only and not national security eligibility. If no issues are discovered, according to respective guidelines a “Favorable Determination” will be populated in JPAS and will be reciprocal within DoN. If issues are discovered, the DOD CAF will forward the investigation along with all supporting documentation to the NIWC Pacific Security Office for local determination. The local fitness determination will be made by the Command Security Manager and your company will be notified of the decision in writing. If an individual receives a negative trustworthiness determination, they will be immediately removed from their position of trust, the FSO will be notified, and the company will replace any individual who has received a negative trustworthiness determination.

If you require additional assistance with the submission of Public Trust Investigations, you may send an email to

NIWC Pacific at W_SPSC_SSC_PAC_clearance_US@navy.mil.

VI. Employment Terminations:

The contractor shall:

Immediately notify the COR or TR of the employee’s termination.

Send email to W_SPSC_SSC_PAC_clearance_US@navy.mil, Code 83310 notifying them of the termination.

Fax a termination VAL to Code 83320 at (619) 553-6169.

Return any badge and decal to Commanding Officer, Naval Information Warfare Center Pacific, Attn: Code

83320, 53560 Hull Street, San Diego, CA 92152-5001.

SPECIFIC ON-SITE SECURITY REQUIREMENTS

I. GENERAL.

a. Contractor Performance. In performance of this Contract the following security services and procedures are incorporated as an attachment to the DD 254. The Contractor will conform to the requirements of

DoD 5220.22-M, Department of Defense National Industrial Security Program, Operating Manual

(NISPOM), as revised. The Contractor will follow all export laws and regulations in the performance of this contract. When visiting Naval Information Warfare Center Pacific (NIWC Pacific) at either the Point

Loma Campus (PLC) or Old Town Campus (OTC) the Contractor will comply with the security directives used regarding the protection of classified and controlled unclassified information, SECNAV

M-5510.36 (series), SECNAV M-5510.30 (series), DOD M-5200.01 Volumes 1 through 4, and

SSCPACINST 5720.1A (series). Both of the SECNAV Instructions and Manuals are available online at http://doni.daps.dla.mil/SECNAV.aspx and the DOD Instructions can be found at http://www.dtic.mil/whs/directives/corres/pub1.html. A copy of SSCPACINST 5720.1A will be provided upon receipt of a written request from the Contractor’s Facility Security Officer (FSO) to the NIWC

Pacific Security’s Contracting Officer’s Representative (COR), Code 83310. If the Contractor establishes a cleared facility or Defense Security Service (DSS) approved off-site location at NIWC Pacific, the security provisions of the NISPOM will be followed within this cleared facility.

b. Security Supervision. NIWC Pacific will exercise security supervision over all contractors visiting

NIWC Pacific and will provide security support to the Contractor as noted below. The Contractor will identify, in writing to Security’s COR, an on-site Point of Contact to interface with Security’s COR.

II. HANDLING CLASSIFIED MATERIAL OR INFORMATION.

a. Control and Safeguarding. Contractor personnel located at NIWC Pacific are responsible for the control and safeguarding of all classified material in their possession. All contractor personnel will be briefed by their FSO on their individual responsibilities to safeguard classified material. In addition, all contractor personnel are invited to attend NIWC Pacific conducted Security Briefings, available at this time by appointment only. In the event of possible or actual loss or compromise of classified material, the on-site

Contractor will immediately report the incident to NIWC Pacific Code 83310, (619) 553-3005, as well as the Contractor's FSO. A security specialist, Code 83310 representative will investigate the circumstances, determine culpability where possible, and report results of the inquiry to the FSO and the

Cognizant Field Office of the DSS. On-site contractor personnel will promptly correct any deficient security conditions identified by a NIWC Pacific representative.

b. Storage.

1. Classified material may be stored in containers authorized by NIWC Pacific PLC Physical Security

Group, Code 83320 for the storage of that level of classified material. Classified material may also be stored in Contractor owned containers brought on board NIWC Pacific PLC with Code 83320's written permission. Areas located within cleared contractor facilities on board NIWC Pacific will be approved by DSS.

2. The use of Open Storage areas must be pre-approved in writing by Code 83320 for the open storage, or processing, of classified material prior to use of that area for open storage. Specific supplemental security controls for open storage areas, when required, will be provided by NIWC Pacific, Code

83320.

c. Transmission of Classified Material.

1. All classified material transmitted by mail for use by long term visitors will be addressed as follows:

(a) TOP SECRET, Non-Sensitive Compartmented Information (SCI) material using the Defense

Courier Service: NIWC-PACIFIC: 271582-SN00, NIWC PACIFIC; Call Security COR to verify address 619-553-3005.

(b) CONFIDENTIAL and SECRET material transmitted by FedEx will be addressed to

COMMANDING OFFICER, NAVAL INFORMATION WARFARE CENTER PACIFIC,

ATTN RECEIVING OFFICER CODE 43150, 4297 PACIFIC HIGHWAY, SAN DIEGO, CA

92110.

(c) CONFIDENTIAL and SECRET material transmitted by USPS Registered and Express mail will be addressed to COMMANDING OFFICER, NAVAL INFORMATION WARFARE CENTER

PACIFIC, 53560 HULL STREET, SAN DIEGO CA 92152-5001. The inner envelope will be addressed to the attention of the Contracting Officer's Representative (COR) or applicable

Technical Representative (TR) for this contract, to include their code number.

2. All SECRET material hand carried to NIWC Pacific by contractor personnel must be delivered to the Classified Material Control Center (CMCC), Code 83430, Building 58, Room 102, for processing.

3. All CONFIDENTIAL material hand carried to NIWC Pacific by contractor personnel must be delivered to the Mail Distribution Center, Code 83430, for processing. This applies for either the

OTC or PLC sites.

4. All NIWC Pacific classified material transmitted by contractor personnel from the NIWC Pacific will be sent via NIWC Pacific COR or TR for this contract.

5. The sole exception to the above is items categorized as a Data Deliverable. All contract Data

Deliverables will be addressed to COMMANDING OFFICER, ATTN DOCUMENT CONTROL

CODE 83430, NAVAL INFORMATION WARFARE CENTER PACIFIC, 53560 HULL STREET,

SAN DIEGO, CA 92152-5001.

III. INFORMATION SYSTEMS (IS) Security.

a. Contractors using ISs, networks, or computer resources to process classified, sensitive unclassified and/or unclassified information will comply with the provisions of SECNAVINST 5239.3 (series) and local policies and procedures. Contractor personnel must ensure that systems they use at NIWC Pacific have been granted a formal letter of approval to operate by contacting their Information System Security Officer

(ISSO). Any suspected cybersecurity incident, such as spillage of classified information to an unclassified system, regardless of the location of the computer system, must be reported immediately to the

COR/TR/PM, Security's COR, ISSO, the Contractor's Facility Security Officer (FSO), and the Contracting

Officer. Contractors who willfully misuse Government computer resources will be held liable to reimburse the Government for all associated costs.

b. Contractors receiving, transmitting or accessing unclassified controlled technical information on or through its contractor information (s) must safeguard the information to avoid compromise, including but not limited to disclosure of information of information to unauthorized persons, unauthorized modification, destruction, or loss of an object, or the copying of information to unauthorized media, as required per DFARS subpart 2014.73 and clauses 204.7304 and 252.204-7012. Contractors shall report to the DOD each cybersecurity incident that affects unclassified controlled technical information resident on or transiting contractor information systems in accordance with DFARS clause 204.7304 and 252.204-

7012. Detailed reporting criteria and requirements are set forth in the clause at 252.204-7012 safeguarding of unclassified controlled technical information.

IV. VISITOR CONTROL PROCEDURES.

Title 18 USC 701 provides for criminal sanctions including fine or imprisonment for anyone in possession of a badge who is not entitled to have possession. Sec.701. Official badges, identification cards, other insignia.

Whoever manufactures, sells, or possesses any badge, identification card, or other insignia, of the design prescribed by the head of any department or agency of the United States for use by any officer or employee thereof, or any colorable imitation thereof, or photographs, prints, or in any other manner makes or executes any engraving, photograph, print, or impression in the likeness of any such badge, identification card, or other insignia, or any colorable imitation thereof, except as authorized under regulations made pursuant to law, shall be fined under this title or imprisoned not more than six months, or both.

a. Contractor personnel assigned to NIWC Pacific will be considered long-term visitors for the purpose of this contract.

b. Contractors that have been awarded a classified contract must submit visit requests using “only” the Joint

Personnel Adjudication System (JPAS). All government activities have been directed to use JPAS when transmitting or receiving Visit Authorization Letters (VALs). Therefore, contractors who work on classified contracts are required to have established an account through JPAS for their facility. This database contains all U.S. citizens who have received a clearance of Confidential, Secret, and/or Top

Secret. The visit request can be submitted for one year. When submitting visit requests to NIWC Pacific use its Security Management Office (SMO) number (660015). This information is provided in accordance with guidance provided to contractors via the Defense Security Service (DSS) website https://www.dss.mil

(DSS guidance dated 24 April 2007, subject: Procedures Governing the Use of JPAS by Cleared

Contractors).

c. For visitors to receive a NIWC Pacific badge their Government point of contact must approve their visit request and the visitor must present government issued photo identification.

d. Visit requests for long-term visitors must be received at least one week prior to the expected arrival of the visitor to ensure necessary processing of the request.

e. Code 83320 will issue temporary identification badges to Contractor personnel following receipt of a valid VAL from the Contractor's FSO. The responsible NIWC Pacific COR will request issuance of picture badges to contractor personnel. Identification badges are the property of the U.S. Government, will be worn in plain sight, and used for official business only. Unauthorized use of an NIWC Pacific badge will be reported to the DSS. For additional information see paragraph g below.

f. Prior to the termination of a Contractor employee with a NIWC Pacific badge or active VAL on file the

FSO must:

1. Notify in writing Code 83320, the Contracting Officer, the COR, Security’s COR, and the laboratory managers of any laboratories into which the employee had been granted unescorted access of the termination, resignation or reassignment and the effective date that the contractor employee no longer requires admittance to the Federally-controlled facility or access to Federally-controlled information systems. In emergencies, a facsimile may be sent or a telephone notification may be used. The telephone notification, however, must be followed up in writing within five working days.

2. Immediately confiscate any NIWC Pacific issued identification badge, common access card (CAC), and return them to Code 83320 no later than five working days after the effective date of the termination. In addition, the contractor will relay departure information to the cognizant Personnel

Security Office (W_SPSC_SSC_PAC_clearance_US@navy.mil) and Trusted Agent (TA)

(ssc_pac_trustedagent@navy.mil) that entered the individual into the Trusted Associated

Sponsorship System (TASS).

3. The Contractor will ensure each departed contractor employee has completed the NIWC Pacific Out-

Processing Checklist, when applicable.

g. Common Access…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.