9h.__Attachment_M_-_DD254_Attachment.pdf
PDF 93 KB Posted
- Attached to
- Space Exploration Networks Services and Evolution (SENSE) Federal contract opportunity
- Solicitation number
- NNG17588638R
About this file
Attachment M - DD254 Attachment
View the file
Other files for this federal contract opportunity
Show all 50
Space Exploration Networks Services and Evolution (SENSE) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT to DD FORM 254 – March 2017
SENSE Contract No. TBD (Continued)
Item # 8 Actual Performance (Continued)
Wallops Flight Facility (WFF) Kennedy Uplink Station (KUS) Ponce De Leon Tracking site (PDL) Kokee Park Geophysical Observatory, Hawaii Blossom Point Remote Station (BPRS) McMurdo Ground Station (MGS) Monument Peak Satellite Laser Ranging Station Jet Propulsion Labaratory (JPL) Haleakalā High Altitude Observatory Site
Item #12. Public Release (Continued)
NASA/GODDARD SPACE FLIGHT CENTER
CODE 450/EXPLORATION and SPACE COMMUNICATIONS PROJECTS DIVISION
GREENBELT, MD 20771
Item # 13. Security Guidance
d. Committee on National Security Systems Instruction (CNSSI) 4000 Series on Communications Security.
e. National Security Telecommunications and Information Systems Security Instruction (NSTISSI) 4000 Series on Communications Security.
f. NSA/CSS Policy Manual 3-16, Control of COMSEC
g. CNSSI TEMPEST/ 1-13, (U) RED/BLACK Installation Guidance
h. NASA Space Network Security Classification Guide.
i. OMB Circular A-130, Appendix III, Security of Federal Automated Information
Resources
j. NASA Information Security Policy, NPD 2810.1E
k. Security of Information Technology, NPR 2810.1A
l. Federal Information Security Management Act of 2002
m. Federal Information Security Modernization Act of 2014
n. Goddard Security Manual, GPR 1600.1A
o. Internet Protocol Operational Network (IONet) Access Protection Policy and
Requirements, 290-004
p. Internet Protocol Operational Network (IONet) Access Control Compliance Checklist, CHECKLIST-July 2004, Revision 3
q. NPR 1600.1A, NASA Security Program Procedural Requirements (08/12/2013)
r. NPD 1600.2E, NASA Security Policy Revalidated w/Chg.1) (04/02/2015)
s. NPR 1600.2 NASA Classified National Security Information (CNSI) w/Change 2
(2/12/2014)
t. NPR 1600.3 Personnel Security (Change 2, April 29, 2013)
u. NPD 1600.4 National Security Programs (09/01/2012)
v. NPR 1600.4A Identity and Credential Management (08/1/2012)
w. NPR 1620.2A Facility Security Assessments (10/4/2012)
x. NPR 1620.3A, Physical Security Requirements for NASA Facilities and Property (10/4/2012)
y. NPR 1660.1C, NASA Counterintelligence (CI)/Counterterrorism (CT), (Revalidated w/Chg.1) (5/28/2015)
z. NID 1600-55 Sensitive But Classified (SBU) Controlled Information
aa. GPR 1600.1A, Goddard Security Requirements, (02/21/2014)
bb. GPR 1600.2 NASA Classified National Security Information (CNSI) (12/11/2013)
cc. GPR 1600.3 Protective Service Division Personnel Security (12/12/2013)
dd. GPR 1600.4 Identity and Credential Management (12/04/2013)
ee. Homeland Security Presidential Directive/HSPD-5, National Incident Management
System
ff. Homeland Security Presidential Directive/HSPD-7, Critical Infrastructure
Identification, Prioritization, and Protection
gg. Homeland Security Presidential Directive/HSPD-8, National Preparedness
hh. Homeland Security Presidential Directive/HSPD-12, Policy for a Common
Identification Standard for Federal Employees and Contractors
ii. Committee on National Security Systems Instruction (CNSSI) 4005 and Amendment
jj. NASA Central Office of Record Standard Operating Procedure (CSOP)
kk. Intelligence Community Directive (ICD) 703- Protection of Classified National
Intelligence, Including SCI
ll. ICD 704- Personnel Security
mm. ICD 705 (U) Sensitive Compartmented Information Facilities
nn. ICS 705-1 (U) Physical and Technical Security Standards For Sensitive
Compartmented Information Facilities (U)
oo. ICS 705-2 (U) Standards for the Accreditation and Reciprocal Use of Sensitive
Compartmented Information Facilities (U)
pp. IC Tech Spec for ICD/ICS 705 (U) Technical Specifications for Construction and
Management of Sensitive Compartmented Information Facilities (U)
qq. Committee on National Security Systems Instruction (CNSSI) 5000, (U) Guidelines for Voice Over Internet Protocol (VoIP) Computer Telephony (U)
rr. Committee on National Security Systems Instruction (CNSSI) 5006, (U) National
Instruction for Approved Telephone Equipment (U)
ss. National Telecommunications Security Working Group TSG Standard 1- (U)
Introduction to Telephone Security (U)
tt. TSG Standard 2- (U) TSG Guidelines for Computerized Telephone Systems (U)
NASA officials will provide additional security, technical, and/or classification guidance. Requests concerning clarification or interpretation regarding security requirements under this contract will be directed to the NASA/GSFC Industrial Security Specialist. The place of performance will be at the contractor cleared facilities, GSFC,WFF, WSC, GRGT, KUS, PDL, Kokee Park, MGS, Monument Peak, and other locations where the requirement is covered by the obligations specified in Section C of the basic contract document.
Item #14. Additional Security Requirements and/or Guidance
Performance of this contract will involve the receipt, generation and storage of classified material/information. Reports containing classified extracts from other classified sources will contain security markings, which correspond to those of the source documents. Those employees requiring access to classified information must have appropriate personnel security clearances. The contractor is authorized to receive/generate-classified material only at approved locations. Classified processing will be involved; however, classified information will not be entered into any computer system, word processing system, or other electrical system until the system has been issued an Authority to Operate as a National Security System
(NSS) in accordance with the Committee on National Security System Instruction (CNSSI)-1253. The contractor will be required to operate a COMSEC account issued by NASA. The NASA Central Office of Records will conduct COMSEC inspections. U.S. citizens granted a final personnel security clearance (as appropriate) and who are COMSEC-briefed are eligible for access to classified COMSEC information released or generated under this contract; any other employees must have written approval from NASA.
Any employee, who observes or becomes aware of the deliberate or suspected compromise of classified national security information, shall promptly report such information to the GSFC Counter Intelligence (CI) Office. If Sensitive But Unclassified (SBU) information appears compromised by or on behalf of foreign or domestic powers, organizations of person, employees shall report such information to the GSFC CI Office. If an employee becomes aware of information pertaining to international or domestic terrorist activities, employees shall also report to the GSFC CI Office. If the information indicates a computer compromise or other cyber intrusion, the Office of Inspector General shall be promptly notified.
Security-Related activities checked in item #11 also apply to personnel requiring access to security-controlled and/or COMSEC areas, involved in the generation and receipt of classified information, and to those in the Document Cost Center designated to process classified material. Due to the need to operate COMSEC devices at certain TDRSS sites, it will require the use of classified cryptographic keying material and documents such as NACSIs and NACSIMs.
A Defense Courier Service account is requested; designated contractor employees are authorized to courier classified material up to and including SECRET COMSEC/CRYPTO in accordance with the NISPOM.
NOTE: The following paragraph refers to the “TS//SCI” portion of this contract. This “TS//SCI” clearance level applies to the contract work set forth in the IDIQ Task Orders to be performed on-site at the Goddard Space Flight Center and at the NASA White Sands Complex, Las Cruces, NM. Also, for the Expendable Launch Vehicles (Atlas, Delta, and Titan), classified missions will be noted in their respective libraries.
This contract requires access to SCI. SCI will only be released to contractor employees requiring access in order to perform within the scope of the contract and only after official verification of the appropriate clearance level has been obtained. Any SCI material furnished to the contractor will be returned to the direct custody of the agency having cognizance unless other disposition instructions have been issued.
The names of any additional employees requiring SCI clearances solely for the purpose of this contract will be provided to the COR, or a designated contract monitor, who will verify and approve the request. After approval, the name will be provided to the GSFC Security Office Program Security Official for coordination with the Contractor Special Security Officer (CSSO). The CSSO shall submit a request for the investigation and clearance in accordance with the National Industrial Security Program Manual and any additional instructions of the User Agency having cognizance.
All visits to the White Sands Complex will be coordinated through the appropriate Security representative and verified through a National level clearance repository prior to accessing TDRSS facilities to ensure that only appropriately cleared personnel are granted access.
Document control and inventories of classified material will be conducted based on regulations published by the Cognizant Security Authority or guidance from the GSFC Program Security Official.
TEMPEST requirements are to be met in accordance with NTISSI 7000 and any cost pertaining to this requirement must be approved through the appropriate NASA security officials. Additionally, the following regulations or directives apply: (1)
CSCM-1; (2) NACSI 4005; (3) NACSI 4008; (4) NACSI 4010.
Physical Security
Certification of physical security devices such as fences, lighting, doors, access control, closed circuit TV monitoring equipment, security containers (safes), guards, etc., is the responsibility of the U.S. Government. The contractor provide remote security monitoring at PDL.” The contractor shall be responsible for the administration and maintenance of all physical security devices included in the Government Furnished Property listing (including WSC, GRGT, KUS and PDL) or acquired under this contract to ensure proper working order in accordance with DoD 5220.22M and the aforementioned references in Item #13.
WSC, GRGT, BPRS, KUS, PDL, and Wallops Ground Station (WGS) are NASA Resource Protection, Mission Essential Infrastructure, mission critical assets. The contractor shall meet the additional requirements from NPR 1600.1 and NPR
1620.3 for all mission critical assets.
Personnel Security
All personnel requiring access to classified work area or material will require security clearances to the appropriate level, based on assigned responsibilities. Access to the WSC, GRGT, BPRS, and all Cryptographic Work Areas require a SECRET security clearance.
Staff at the KUS and PDL sites and WSC Communications Services Controller, Satellite Controller, and Site Specialist positions fall under the Mission Critical Space System Personnel Reliability Program. The contractor shall meet the additional requirements from NPR 1600.1 for the Mission Critical Space System Personnel Reliability Program.
At a minimum all personnel at the facilities listed in Item #8 shall have a National Agency Check with Inquiries (NACI). The contractor shall be responsible for the administration of the personnel security program, including records for security clearances, briefings and debriefings, badges or other identification measures, and general security training for all contractor personnel.
Communications Security (COMSEC)
Procurement of cryptographic equipment and devices is a Government responsibility. Maintenance of cryptographic equipment and devices will be performed by U.S. Government Agencies and designated trained personnel. Training for contractor personnel in identification of faulty equipment and devices will be conducted by DoD. The contractor shall be responsible for ensuring that designated personnel are adequately trained on all cryptographic equipment and devices.
Security Inspections
Routine and unscheduled inspections will be conducted by U.S. Government Agencies to verify the adequacy of the security program, identify discrepancies, and recommend corrective action(s), with which the contractor shall comply (except if granted an official waiver).
Security Reporting
All security reporting shall be in accordance with DoD 5220.22M and respective NASA guidelines.
File details come from the government source that posted it. Updated .