PWS (DRAFT) Security Support Services Recompete.pdf

PDF 799 KB Posted

Attached to
Sources Sought - Security Support Services Federal contract opportunity
Solicitation number
HDTRA1-21-R-0038
Issued by
Defense Threat Reduction Agency

About this file

This performance work statement outlines security support services required by the Defense Threat Reduction Agency. The agency requires personnel to perform non-personal security support services across multiple locations, including the National Capital Region, Albuquerque, Travis Air Force Base, Eglin Air Force Base, and Kaiserslautern, Germany. Duties include operations support, special security office support, special access program security, foreign disclosure, personnel security, antiterrorism/force protection, information security, industrial security, operations security, locksmith services, escort services, and access support. The performance work statement provides detailed requirements for each duty.

View the file

Other files for this federal contract opportunity

Other files attached to Sources Sought - Security Support Services, newest first.
File Type Posted
Questions_Clarifications (HDTRA121R0038 Sources Sought).docx DOCX document
Attachment 3 - LCAT Security Services.pdf PDF
Attachment 2 - Labor Breakout (090721).pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

DEFENSE THREAT REDUCTION AGENCY

SECURITY SUPPORT SERVICES

April 7, 2020

1 Introduction

1.1 Mission

The Defense Threat Reduction Agency (DTRA) safeguards the United States and its allies from global Weapons of Mass Destruction (WMD) threats by integrating, synchronizing and providing expertise, technologies and capabilities. The DTRA Engineering and Logistics Department (J4L) provides logistical support operations for all aspects of the Agency’s worldwide logistics requirements. On 1 October 2016, the Joint Improvised-Threat Defeat Agency (JIDA), to include its mission to counter improvised threats with tactical responsiveness and through anticipatory, rapid acquisition in support of Combatant Commands’ efforts transitioned to DTRA. OI-MSC is responsible for Security management for DTRA. DTRA Security programs include Physical, Industrial, Personnel, Operations (OPSEC), and Information Security; Antiterrorism/Force Protection; Special Access Program (SAP), Insider Threat, Foreign Disclosure (FD), Technical Surveillance Countermeasures (TSCM); Insider Threat and the Special Security Office (SSO) under Intelligence Community Directives (ICD).

1.2 Background

This is a non-personal services contract to support the Defense Threat Reduction Agency (DTRA), Security and Counterintelligence Department (OI-MSC). The Government shall not exercise any supervision or control over the contract service providers performing the services herein. The contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government. Work under this effort may be performed at the DTRA’s locations in Albuquerque (ABQ), New Mexico; Travis Air Force Base, California; Eglin Air Force Base, Florida; Kleber Kaserne, Kaiserslautern, Germany; and primarily, the Defense Threat Reduction Agency in the National Capital Region (NCR) area.

1.3 Scope of Work

The contractor shall provide personnel to perform non-personal security support services to assist Government personnel in support of Security services within the NCR and other DTRA locations. Contractor support services are required to:

This SOW covers services for all duties and responsibilities within OI-MSC, to include its geographically separated locations:

Operations Support and Senior Site Lead Special Security Office (SSO) Research Special Access Program (SAP) Security

Foreign Disclosure (FD) Personnel Security Antiterrorism/Force Protection (AT/FP) Information Security Industrial Security Operations Security Locksmith Escort Services Access Support Entry Control Officer Technical Surveillance Countermeasures (TSCM) Insider Threat Support

2 Applicable Directives

Publications and forms that apply to this Performance Work Statement (PWS) are listed below.

The contractor is obligated to follow these publications and use these forms to the extent necessary to accomplish requirements as specified in other sections of this PWS. All publications and forms listed will be provided by the Government at the start of the contract.

2.1 Publications

Executive Order 12333, United States Intelligence Activities, December 4, 1981, as amendedA1:A41

Executive Order 12829, National Industrial Security Program, January 6, 1993

Intelligence Community Directive 705-1, Physical and Technical Security Standards for Sensitive Compartmented Information Facilities, September 17, 2010

Director of Central Intelligence Directive 5/1, Espionage and Counterintelligence Activities Abroad, December 19, 1984

Intelligence Community Directive 304, Human Intelligence, March 6, 2008 (Amended July 9, 2009)

DoD Directive 5100.81, Department of Defense Support Activities, December 5, 1991

DoD Directive 5105.21, Defense Intelligence Agency, March 18, 2008

DoD Manual 5105.21, Volume 3 Sensitive Compartmented Information (SCI) Administrative Security Manual: Administration of Personnel Security, Industrial Security and Special Activities, October 19, 2012;

Change 1, April 5, 2018

DoD Directive 5105.62, Defense Threat Reduction Agency, Change1, November 10, 2015

DoDD 5144.02 DoD Chief Information Officer (DoD CIO), Change 1, September 18, 2017

DoD Directive 5148.11, Assistant to the Secretary of Defense for Intelligence Oversight, April 24, 2013

DoD Instruction 5200.2, DoD Personnel Security Program, March 21, 2014, Change 2, May 11, 2018

DoD 5200.08R, Physical Security Program, April 9, 2007

DTRA Directive 5200.8, DTRA Physical Security Program, December 22, 2008

DoD Directive 5205.02E, DoD Operations Security Program, June 20, 2012, Change 1, May 11, 2018

DoD Directive 5210.50, Management of Serious Security Incidents Involving Classified Information, October 27, 2014, Change 1, February 16, 2018

DoD Directive 5220.6, Jan 2, 1992 as amended June 8, 2017

DoD Directive 5240.02, DoD Counterintelligence, March 17, 2015, Change 1, May 16, 2018

DoD Directive 8100.02, Use of Commercial Wireless Devices, Services, and Technologies, in the Department of Defense (DoD) Global Information Grid (GIG), April 14, 2004

DoD Instruction 5240.05, Technical Surveillance Countermeasures (TSCM), April 3, 2014, Change 1, April 18, 2018

DoD Manual 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), February 2006, Change 2, May 18, 2018

DOD Instruction 5240.26, Counter Espionage, International Terrorism and the Counterintelligence Insider Threat, May 4, 2015; Change 2, May 1, 2018

DTRA Instruction O-5240.26, Insider Threat Program

DOD Instruction 5200.39, Critical Program Information Identification and Protection Within Research, Development, Test, and Evaluation, May 28, 2015, Change 2, October 15, 2018

DoD Instruction 8560.01 Communications Security (COMSEC) Monitoring, August 22, 2018

DoD 8570.01-M, Information Assurance Workforce Improvement Program, December 19, 2005, Ch4, November 10, 2015

Security Executive Agency Directive 3 (SEAD 3), Reporting Requirements for Personnel with Access to Classified Information or Who Hold a Sensitive Position, June 12, 2017

SEAD 4, National Security adjudicative Guidelines, June 8, 2017

SEAD 5, Collection, Use, and Retention of Publicly Available Social Media Information in PSI and adjudication, May 12, 2016

SEAD 6, Continuous Evaluation, January 12, 2018

SEAD 7, Reciprocity of Background Investigations and National Security Adjudications, November 9, 2018

ICD 704, Personnel Security Standards and Procedures Governing Eligibility for Access to Sensitive Compartmented Information and other Controlled Access Program Information, October 1, 2008

The National Security Act of 1947, as amended

Intelligence Reform and Terrorism Prevention Act of 2004 (IRTPA), as amended

EO 10450 Security Requirements for Government Employment, as amended

EO 12968, Access to Classified Information, as amended

EO 13467, Reforming Processes Related to Suitability for Government

Employment, Fitness for Contractor Employees, and Eligibility for Access to Classified National Security Information Presidential Decision Directive/NSC-12 Security Awareness and Reporting of Foreign Contracts

NSACSS 3-16, Control of Communications Security (COMSEC) Material, January 23, 2015

CNSSI No. 4001, Controlled Cryptographic Items, May 7, 2013

2.2 Changes

The Government will provide additional references and changes to cited references to the contractor as required. Supplements or amendments to listed publications from any organizational level may be issued during the life of the contract. The contractor must immediately implement those changes that result in a decrease or no change in the contract price and notify the Contracting Officer (KO) in writing of such change. Should a decrease in contract price be anticipated, the contractor must provide a proposal for a reduction in the contract price to the KO. Before implementing any change that will result in an increase in contract price, the contractor must submit to the KO a price proposal within 10 calendar days following receipt of the change by the contractor. The KO and the contractor must negotiate the change into the contract under the provisions of the contract clause entitled "Changes." Failure of the contractor to submit a price proposal within 10 calendar days following receipt of the change would entitle the Government to performance in accordance with the change at no increase in contract price (unless the time requirement is waived by the KO according to paragraph (c) of the Changes clause).

3 Performance Requirements

3.1 Operations Support and Senior Site Lead: The contractor shall:

3.1.1 Conduct duties relevant to all security disciplines and counterintelligence functions.

Write staff actions/reports and coordinate within organizational and with external entities.

Ensure that office staff actions are coordinated and on time.

3.1.2 Keep current on agency mission, new security requirements and how those requirements impact mission. Recommend cost effective means to implement guidance and reduce security risks.

3.1.3 Support the DTRA Security Awareness, Training and Education (SATE) initiative.

3.1.4 Provide critical substantive review or edit of PP-SC related documents, plans, policies, procedures, resource and requirements documents, and agency responses to higher authority for signature by DTRA Director, Executive Director or OI-MSC leadership.

3.1.5 Manage the Enterprise Information System (EIS) by coordinating task actions with OI- MSC Personnel as well as other personnel throughout the Agency. As a Subject Matter Expert (SME), advise OI-MSC personnel on how to perform their EIS tasking functions correctly.

3.1.6 Develop Standard Operating Procedures (SOP’s) for EIS and Staff Office duties. SOPs should cover all responsibilities associated with the Operations and Staff contracted position and updated as needed. Develop and deliver training and briefings to other support personnel when necessary.

3.1.7 Provide a continuity book containing all pertinent information to sustain operations in an abnormal situation or environment. Include all reference materials such as current DTRA and OI-MSC policies, doctrines, and instructions.

3.1.8 Participate in Staff Assistance Visits (SAV) to other inter-agency elements. Review relevant documentation, develop and prepare presentations and briefings as needed during the visits.

3.1.9 Provide support to OI-MSC’s CI and Security Divisions. Assist with the updates and revisions of current OI-MSC policies, instructions, and memorandums.

3.1.10 The Senior Site Lead, known throughout this SOW as the Program Manager (PM), conducts duties and responsibilities normally associated with an on-site program manager.

3.1.10.1 Primary Point of Contact (POC) for all personnel actions, such as recruiting, retention, hiring replacements, and compliance with contractual agreements.

3.1.10.2 Provide up to 20 percent on duty time on-site as program manager duties that support the contract or contractor employees.

3.2 Special Security Office Support: The contractor shall:

3.2.1 Support the SSO by providing services for the receipt, accountability, transmission, reproduction, storage, safeguarding, and destruction of SCI and collateral classified information, records and reports (SCI Information Security) and by processing verifications of authorized personnel for access to appropriate material.

3.2.2 Escort and control access of SSO SCI facilities (SCIF)s at a minimum from 0700 – 1700 for the main DTRA SCIF room B1900; 0730 – 1600 for the JOC SCIF room B1260 and DLA SCIF room 3539; and 1500 – 1600 for the B2 SCIF room B2648 Monday through Friday (excluding federal holidays or days when the DTRA facilities are closed) and occasional requirement for escort duties after 1800 hours (not to exceed an 8-hour work day).

3.2.3 Screen visitors and control access to all SCIFs using a local database, the Joint Personnel Adjudication System (JPAS) and the Scattered Castles database.

3.2.4 Develop and/or modify all SSO step-by-step processes.

3.2.5 Develop and/or modify the SSO SOP and Emergency Action Plan (EAP).

3.2.6 Submit weekly and monthly roll-up work accountability reports.

3.2.7 Conduct all required SCIF inspections, response tests and Intrusion Detection System (IDS) tests.

3.2.8 Conduct SCI indoctrinations and debriefings.

3.2.9 Conduct classification marking reviews of all material leaving the SCIF and provide advice and guidance on the marking of SCI material.

3.2.10 Enter approved equipment being introduced to a SCIF into the equipment log.

3.2.11 Ensure that any equipment that is being removed from a SCIF has been properly sanitized and approved by the SSO Information Assurance Manager (IAM).

3.2.12 Process SCI permanent certifications (inbound and outbound).

3.2.13 Issue courier cards, courier briefings and prepare commercial airlines authorization letters.

3.2.14 Assist with the management of the foreign travel reporting program for the SSO.

3.2.15 Assist with the management of the contractor SCI nomination program for the SSO.

3.2.16 Coordinate meetings and conferences held in the SCIFs.

3.2.17 Provide administrative data entry.

3.2.18 Provide files and record Maintenance.

3.2.19 Provide internal mail distribution.

3.2.20 Provide Defense Courier Service (DCS) package pick-up.

3.2.21 Track completion rates of the required annual SCI refresher training(s)

3.2.22 Prepare Fixed Facility Checklists (FFC) and TEMPEST Addendums and modify as needed for each DTRA SCIF.

3.2.23 Required skills for contractor SCIF personnel: The contractor personnel shall:

3.2.23.1 Possess integrated security services skill sets in the following areas: SSO operations; SCIF operations; SCI Personnel Security; SCI Information Security; SCI Physical Security; SCI TEMPEST actions and procedures; and, SCI Industrial Security. The contractor shall have recent, in-depth, government/contractor SSO operations experience, and recent, in-depth SCIF operations experience.

3.2.23.2 Provide mid-level contractor personnel that are thoroughly familiar with DoDM

5105.21 Volumes 1-3, to administer the receipt, control, and accountability of SCI. Be familiar with the ICD 705, Intelligence Community Standard (ICS) 705-1 and 705-2, for construction, accreditation, and technical requirements for SCIFs. Support delivery of services for SCIFs and perform the day-to-day SCI security oversight functions for the SSO and subordinate SCIFs.

3.2.23.3 Possess strong customer service skills to handle customer’s questions, complaints, and requested support in a professional, personable and courteous manner. Areas of expertise shall include computer operations, SCIF procedures, use of secure telephones, removal of classified information, indoctrinating personnel, and accepting security clearances from external agencies to other security and non-security issues occurring during day-to-day SCIF operations.

3.2.24 Maintain the Support Program Communication Security (COMSEC) account by ensuring accountability of Crypto material, key, and key-loading equipment.

3.2.25 Maintain Crypto-cleared personnel and adhere to all applicable COMSEC regulations and guidelines.

3.2.26 Be prepared to receive, stage, transport, store, safeguard, install, initialize, and operate Cryptographically Controlled Items (CCI), COMSEC equipment, and associated Key Material (KEYMAT) of the relevant types required for the Support Program including but not limited to Secure Telephone Equipment (STE), KG-175A, etc.

3.3 Special Access Program Security Support: The contractor shall:

3.3.1 (FOUO) Assist in writing and implementing SAP security policy, SOPs, Concepts of Operations (CONOPS), and Transportation Security Plans (TSPs) and advises and assist PM in the development of Security Classification Guides (SCGs) for complex SAPs. Personnel performing this duty must possess strong writing skills.

3.3.2 (FOUO) Advise senior officials on a broad range of program security issues including system threat vulnerability assessments, system security requirements, architectures, and security risk mitigation plans. Assist clients in researching and defining security problems. Personnel performing this duty must possess strong oral communication skills, the ability to relate to a diverse customer base, and general knowledge of DoD operations. Must be capable of operating in the NCR and other locations as required.

3.3.3 (FOUO) Monitor assessment and authorization process for program areas and Information Technology systems.

3.3.4 (FOUO) Assist in developing and administering a SAP security awareness education program that includes annual refresher training and utilizes continuing education tools such as newsletters, pamphlets, and briefings, etc.

3.3.5 (FOUO) Provide support for all DTRA SAPs, Compartments, Sub-Compartments and Projects. This includes coordination for all DTRA personnel requiring access to other federal agency’s SAPs (Program Access Requests), developing Co-Use Agreements (CUA), Memorandum of Agreement (MOA), and Memorandum of Understanding (MOU). Facilitates Special Access Program Nomination Process (SAPNP) reviews for all personnel submitted for access to DTRA SAPs, Compartments, Sub-Compartments, and Projects.

3.3.6 (FOUO) Develop all SAPF accreditation documentation for each SAPF and organizes its tabbed binder. Additionally electronic sources and data should be filed within a defined graphic user interface database.

3.3.7 (FOUO) Assist in the inspection of SAPFs under DTRA control to ensure compliance with established applicable documents as listed in Section 5.0. This will be done on an annual basis or as requested by the government. Must possess the ability to document the results of the inspection in writing and effectively present briefings of a visual and oral nature regarding those results.

3.3.8 (FOUO) Interface with personnel at the OSD level related to security matters and be capable of explaining the reason security actions were taken or are about to be taken in support of the program.

3.3.9 (FOUO) Assist in conducting industrial security inspections at program contractor locations and assisting in “get well” processes following those inspections with security shortfalls, deficiencies or significant findings or an unsatisfactory rating.

3.3.10 (FOUO) Provide direct support to the DTRA Focal Point program through validation of need to know, scheduling briefing, submitting accesses and other tasking as required by policy.

3.4 Foreign Disclosure (FD) Support: The contractor shall:

3.4.1 Prevent collection of information about U.S. personnel and activities by adversary.

Prevent unauthorized release of information to foreign nationals and Governments. Assist in the development of FD policies and procedures. Assist in the development of FD processes and procedures to address DTRA mission, travel, and foreign visitors to DTRA facilities. This includes assisting with reviews of internal processes and information.

3.4.2 Develop and present FD presentations to a diverse audience.

3.4.3 Provide specialized staff support to the OI-MSC, to include but not limited to processing OI-MSC related documentation, tasks specifically focused on the Agency FD Program and support activities associated with the National Disclosure Policy-1 (NDP-1).

3.4.3.1 Perform independent analysis and evaluation of current DTRA policies and procedures to determine compliance with national and DoD policies and requirements.

3.4.3.2 Update and/or revise current DTRA and OI-MSC policies and guidance for FD.

3.4.3.3 Support the DTRA Security Awareness Program by providing FD and Foreign Visit training, briefings, articles, and other products.

3.4.3.4 Draft, write or edit FD related documents, plans, policies, procedures, resource and requirements, and Agency responses to higher authority for signature by DTRA Director, Deputy Director, or Chief, OI-MSC.

3.4.3.5 Write FD articles for posting on the DTRA net or DTRA Sentinel Newsletter, as directed.

3.5 Personnel Security Support: The contractor shall:

3.5.1 Process personnel to determine the appropriate security clearance and/or SCI eligibility prior to granting access to DTR/SCC-WMD facilities and information. In addition, support the DTRA/SCC-WMD Personnel Security (PS) Program includes:

3.5.1.1 Request/Review/Initiate/Track Background Investigations.

3.5.1.2 Provide accurate and analytical establishment, maintenance, review, receipt, accountability, transmission, reproduction, storage, safeguarding, and destruction of collected personal history, case files, data entry, records, files, and reports according to PS policy and procedures.

3.5.1.3 Coordinate with the appropriate agencies for reciprocal recognition of existing investigations and adjudications prior to the initiation using consistent PS standards prior to initiation.

3.5.1.4 Review and process of hiring nomination packages to determine they are complete, detect anomalies, and process for designated position sensitivity levels.

3.5.2 Develop and deliver PS briefings and debriefings.

3.5.3 Develop and/or modify all PS step-by-step processes and SOPs for Government PM/COR approval.

3.5.4 Conduct continuous review of PS reportable items. Accurately establish, manage, administer, monitor, release, and place into historical DTRA/SCC personnel JPAS, eQIP and local Security Database records. Immediately report to the Government PM/COR if/when potential derogatory information becomes known on personnel that affects their continued eligibility to sensitive and classified positions.

3.5.5 Develop, review, and maintain PS In/Out Processing Center administration duties.

Accurately review all PS In and Out Processing prior to allowing access to DTRA facilities and local area networks.

3.5.6 Develop, review and maintain step-by-step processes for visitor services and SOPs for Government PM/COR approval.

3.5.7 Process requests for visit authorizations (inbound and outbound).

3.5.8 Issue collateral courier cards and courier briefings.

3.5.9 Prepare applications for Pentagon and NCR badge for Government PM/COR review and signature.

3.5.10 Identify visitors and ensure visitors are properly cleared with a need to know prior to granting access to DTRA/SCC-WMD facilities or local area networks by issuance of the appropriate DTRA/SCC-WMD badge, CAC or IDs.

3.6 Antiterrorism/Force Protection (AT/FP) Support: The contractor shall:

3.6.1 Develop, present and facilitate AT/FP training as directed. Conduct Annual Antiterrorism Level I Awareness training. Maintain statistical data on training activities at the HQ and subordinate locations.

3.6.2 Monitor the Agency’s overseas travelers to ensure all AT/FP requirements are met.

3.6.3 Review Vulnerability Assessments (VAs) according to DoDI 2000.16 guidance.

Identify relevant risks to DTRA assets and personnel specified in the VAs.

3.6.4 Identify the potential terrorist threats to DTRA personnel and assets to assist in developing an effective antiterrorism program. Support the AT/FP Program by providing assistance in developing, presenting, and updating threats analysis. This includes providing the factors of terrorist operational capability, activity, intentions, and operating environment that commanders at all levels understand the threat and can assess their ability to prevent, survive, and prepare to respond to an attack.

3.6.5 Support situational awareness through an analytical AT/FP approach that includes reviewing intelligence and open source information; recommending AT/FP informational, instructional and decision briefings; and preparing advisories to increase AT/FP awareness within the workforce. Prepare and deliver situational awareness support through analytical AT/FP program assistance.

3.6.6 Draft and develop AT/FP plans and procedures critical to deterrence, detection, defense, and response to terrorist incidents. Interpret higher level AT/FP policy and guidance; develop and implement DTRA specific AT/FP policy and guidance; and review internal and external AT/FP plans. Plans drafted by the AT/FP team will include the following key elements, as directed by DoDI 2000.16, Vol 1, Standard 7:

3.6.6.1 Terrorism Threat Assessment

3.6.6.2 Vulnerability Assessment

3.6.6.3 Risk Assessment

3.6.6.4 AT Physical Security measures

3.6.6.5 Terrorist Incident Response measures

3.6.6.6 Terrorist Consequence Management measures

3.6.6.7 Attend AT/FP working Groups/Committees

3.6.7 (FOUO) Participate in AT/FP Working Groups/Committees to recognize terrorist patterns and share information. Recommend various papers and document outcomes/highlights of information shared in these working groups/committees.

3.6.8 Complete Antiterrorism Level II course and demonstrate experience in AT/FP as listed above, in 3.6.6. Maintain AT Level II certification in accordance with DoDI 2000.16,Vol 1.

3.6.9 Develop, present, and update threat analysis that includes the factors of terrorist operational capabilities, activities, intentions, and operating environment.

3.6.10 Prepare and deliver situational awareness briefings. Briefing should include the review of intelligence and open source information and recommendations for AT/FP actions to appropriate leadership to mitigate risk; the development of AT/FP informational, instructional, and decision briefings; and, advice to leadership to maintain the appropriate AT/FP awareness level within the workforce.

3.6.11 Participate in DTRA specific Emergency Management (EM) and Force Protection (FP) incident response requirements and assist with planning and execution of EM and FP exercises.

3.7 Information Security Support (ISP): The contractor shall:

3.7.1 Provide support with the execution of the Agency’s Information Security Program (ISP), which includes the classification/declassification program and security education and training programs.

3.7.2 Develop and prepare draft SOPs, which incorporate specific implementing guidance, requirements, and all essential guidance to ensure standardization throughout the agency. The essential elements will be outlined and approved by the Government Project Officer (PO). The format will be in accordance with DTRA Instruction 5025.2. Each SOP will be revised and reviewed annually to ensure it is up to date and reflects current policy. Final SOPs will be delivered in hard copy and in an electronic format. The Government will provide resources data as required.

3.7.3 Provides support to the Agency Automatic Declassification Program. Establish contacts and display proven ability in the Automatic Declassification community.

3.7.4 Maintain and support the Agency Mandatory Declassification Program. Establish policies and procedures for processing mandatory declassification review requests.

3.7.5 Support Security and Counterintelligence by providing ISP support Agency wide.

3.7.6 Develop, coordinate, and implement Security and Counterintelligence policies and report any failures to comply with policy to the company PM and/or Government PM/COR.

3.7.7 Collaborate with DTRA Directorates and Field Offices, and with the Chief, Security and Counterintelligence, and/or government PM to develop, coordinate and publish DTRA security procedures and documents.

3.7.8 Provide recommendations and options for intra- and inter-Agency coordination to the Chief, Security and Counterintelligence and/or government PM.

3.7.9 Develop and conduct ISP training presentations and briefs.

3.7.10 Develop ISP products for the security education and awareness training program.

3.7.11 Review all Agency Security Classification Guides (SCGs) for administrative and formatting purposes in coordination with responsible Directorate or Field Office PM and Security Manager to ensure SCGs are reviewed and updated every five years in accordance with DoDM 5200.01 prior to the DTRA Original Classification Authority (OCA) signature.

3.7.12 Conduct security classification marking review on DTRA Form 58 packages prior to release form Agency.

3.7.13 Support DTRA’s Security program by conducting Preliminary Inquiries.

3.8 Industrial Security Support: The contractor shall:

3.8.1 Maintain and update directives, instructions, and SOPs for the management and execution of the Agency’s Industrial Security program and NATO program which incorporate specific implementing guidance, requirements, and all essential guidance to ensure standardization throughout the Agency. Each SOP and Instruction will be reviewed and updated annually to ensure currency and relevancy.

3.8.2 Process Contract Security Classification Specification, DD Form 254, in support of the Agency’s Industrial Security Program. Coordinate with the contracting office to close out DD Form 254s.

3.8.3 (FOUO) Support Agency-wide Security and Counterintelligence efforts.

3.8.4 Prepare presentations and briefings when required.

3.8.5 Support DTRA’s Security program by conducting Preliminary Inquiries.

3.8.6 Demonstrate thorough knowledge of DoD 5220.22-M, NISPOM, and USSAN 1-07.

3.9 Operations Security Support: The contractor shall:

3.9.1 Protect the Agency’s critical information by implementing all aspects of DoD Directive 5205.02E, DoD Operations Security (OPSEC) Program, and DoD 5205.02M, DoD Operations Security (OPSEC) Manual.

3.9.2 Conduct security reviews of Agency documents being considered for public release through the Agency’s Public Affairs Office.

3.9.3 Develop and maintain the Agency’s OPSEC Directive and Instruction.

3.9.4 Develop OPSEC plans in support of various programs, tests, and exercises sponsored and supported by the Agency.

3.9.5 Conduct face-to-face OPSEC training for new Agency personnel. Also, provide custom-tailored OPSEC training throughout the Agency as requested.

3.9.6 Conduct OPSEC assessments of sub-components.

3.9.7 Coordinate and support OPSEC surveys conducted by third-party organizations, such as the Joint Information Operations Warfare Center and the 1st Information Operations Command.

3.9.8 (FOUO) Coordinate with Program Protection Office to assist in the identification of Critical Program Information (CPI), Critical Technical Information (CTI), and Program Protection Plans (PPP).

3.9.9 (FOUO) Develop task-specific presentations and briefs.

3.9.10 (FOUO) Develop products for the security education and awareness training program.

3.9.11 (FOUO) Support Agency-wide Security and Counterintelligence efforts.

3.9.12 Support DTRA’s Security program by conducting Preliminary Inquiries.

3.9.13 Demonstrate knowledge of and the ability to implement the Five-Step OPSEC Process.

3.10 Locksmith Services: The Contractor shall:

3.10.1 (FOUO) Establish and implement a key control method ensuring all keys/key cards issued to the contractor by the Government are not lost or misplaced and are not used by unauthorized persons.

NOTE: All references to keys include key cards. No keys issued to the contractor by the Government shall be included in the Quality Control Plan. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the Government PM or COR.

NOTE: In the event keys, other than master keys are lost or duplicated, the contractor shall upon direction of the PM/COR, re-key or replace the affected lock of locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. If the Government performs replacement of the locks or re-keying, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payments due to the contractor.

3.10.2 Prohibit the use of Government issued keys by any persons other than the contractor’s employees. The contractor shall prohibit the opening of locked areas by contractor employees to permit entrance of persons other than contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the PM/COR.

3.10.3 Maintain Locksmith GSA certification with a GSA Safe Inspection certification for the duration of this contract. Additionally, maintain the following certifications as appropriate:

3.10.3.1 LKM10K Certification

3.10.3.2 S & G 2890B Certification

3.10.3.3 KabaX10 Locks

3.10.3.4 S & G 2740 Locks

Note: Al locks listed above require recertification each time a new version of the lock is released.

Therefore, the Agency Locksmith will only be required to maintain certification on locks in use at DTRA facilities.

3.10.4 Install, repair, and maintain door locks, cipher locks, electromechanical locks, drill and repair Government safes (including security containers), and perform combination changes including cutting and maintaining keys.

3.10.5 Maintain accountability of all security containers; maintain the Agency’s work order database, and coordinates all locksmith related work orders with the affected customer.

3.10.6 Provide full time locksmith support during Agency work hours as stated in Section 4.2.

Provide 24-hour emergency on-call locksmith services, with a two-hour response time during non-duty hours. The locksmith shall be stationed at the DTRA HQ facility and shall support the other local DTRA facilities.

3.10.7 Conduct annual GSA container inspections/inventories at Agency HQ and at each of the major Field Offices (Reston, Kleber, Eglin AFB, Kirtland AFB, and Travis AFB. Conduct GSA container inspection and inventory at other Agency locations as needed.

3.10.8 Support open storage accreditation and re-accreditation inspections when required.

3.11 Escort Services: The contractor shall:

3.11.1 Provide Escorts for un-cleared technician (and general facility), carpet cleaning, canteen and cafeteria personnel as required.

NOTE: Must maintain the confidentially of all official business conducted while performing their official duties. Must not allow un-cleared personnel to remove anything other than trash from an office space without prior approval from the space occupant or a supervisor.

3.11.2 Read and adhere to DTRC Physical Security SOP #3, Escort Procedures.

3.11.3 Provide Additional Escort Services as follows:

3.11.3.1 Security Escort (SE) shall accompany un-cleared personnel within DTRA spaces.

SE will announce any un-cleared personnel when entering a controlled access area or area where classified is readily visible or actively being used/displayed/processed.

3.11.3.2 Exercise good judgment at all times and provides effective, appropriate actions to counteract potential security infractions.

3.11.3.3 Comply with government regulations and procedures.

3.11.3.4 Report to COR any improper or suspicious behavior/activity within the work areas, courtyards, or in DTRA parking lots.

3.11.3.5 Comply with DTRA security policies at all times.

3.11.3.6 Notify the OSCM (ABQ location) and SSL (DTRC) of any concerns, questions, events, incidents, etc.

3.11.3.7 Maintain positive visual control of escorted personnel at all times in all locations.

3.11.3.8 Challenge person(s) in possession of prohibited items to ensure only authorized items are brought into DTRA spaces.

3.11.3.9 Notify OSCM/SSL of the complete details for any security incidents, events, or occurrences within 10 minutes of discovery.

3.11.4 Comply with the following Emergency Procedures:

3.11.4.1 Be thoroughly familiar with DTRA directives as required during emergencies (fire, bomb threat, medical, etc.). Take appropriate actions per type of emergency.

3.11.4.2 Ensure all escorted personnel have exited DTRA spaces unless the situation presents an unsafe environment to do so.

3.11.4.3 Notify the COR regarding emergency situations as soon as possible after the emergency situation ends.

3.11.4.4 Follow the instruction of the Emergency Control Officer, On-scene Commander, or emergency response personnel.

3.11.4.5 Maintain poise and self-control at all times.

3.11.5 SE should meet the following physical requirements:

3.11.5.1 Able to stand and walk for extended periods of time.

3.11.5.2 Able to function in all types of weather environments.

3.11.5.3 Able to remain alert and orientated at all times while on duty.

3.11.5.4 Able to perform all necessary physical duties unaided (i.e., walking, standing, etc.).

Note: For Escort positions, adequate personnel shall be available to cover for times when personnel are not available due to sick time, vacations, or other situations The contractor must fill a vacant position within 2 hours of notification.

Note: For ABQ, the Branch Chief (or his/her appointee) will serve as the on-site PM and report issues/problems to the COR.

3.12 Access Support (Front Lobby/SSO): The contractor shall:

3.12.1 Answer telephone calls, greet customers (both visitors and permanent parties), respond to security emails, take messages and route calls to a responsible Security Team Lead.

3.12.2 Inventory and ensure all badges are present and/or accounted for at the beginning and end of each tour of duty and maintain a record of all badges issued. Immediately notify the PM/COR and team lead of unaccounted for badges. Possess a general knowledge of Microsoft Office (Word, Excel, PowerPoint, Access, and Outlook) programs and databases in order to perform the varied administration duties required by the Security Division.

3.12.3 Process all visiting customers to the DTRC. Ensure that all visitors entering the DTRC are in possession of a valid DTRA security access badge. Verify the visitor’s identification from a picture ID, validate visitor clearance status and process badges utilizing the automated security database, JPAS, and if applicable, call to the SSO in less than five (5) minutes, except in unusual circumstances. Whenever a security clearance cannot be validated, the visitor shall be added to the system and issued an “Escort Required” badge.

3.12.4 Contact visitor’s DTRA sponsor to inform sponsor of the visitor entering DTRA facilities.

3.12.5 Brief sponsors of visitors issued “Escort Required” badges, on their responsibilities as escorts for un-cleared personnel.

3.12.6 Verify all badges are properly turned in or invalidated when the individual no longer is granted or needs access. All turn-ins must be annotated in the security database(s) or the proper badge log.

3.12.7 Maintain accurate forms, databases and logs for all daily visits and badge inventories.

Compose, edit and prepare memorandums, reports, forms, and other security-related material as required for final review by Security Team Lead.

3.12.8 Be proficient in PowerPoint, Access, and Outlook programs and databases in order to perform the varied administration duties required by the Security Division.

3.12.9 Validate all requests are current in JPAS prior to issuing a badge. Issue appropriate badge for the security clearance level.

3.12.10 Maintain the confidentiality of all official business conducted while performing duties in support of this contract.

3.12.11 Provide weekly reports and metrics to the PM/COR.

3.12.13 Germany. The access control personnel will also provide escort duties as needed.

3.13 Entry Control Officer (ECO) Services: The contractor shall:

3.13.1 Exercise good judgment at all times and provides effective, appropriate actions to counteract potential security infractions.

3.13.2 Comply with all government regulations and procedures.

3.13.3 Report to COR/PM improper, or suspicious behavior/activities within the work areas, courtyards, or in DTRA parking lots.

3.13.4 Report if prohibited items, identified in the Prohibited Items Policy are being brought into DTRA facilities.

3.13.5 Comply with DTRA security policies at all times.

3.13.6 Answer telephone calls, acknowledge each person, respond to inquiries or take messages and/or contact appropriate sponsor or POC.

3.13.7 Notify the OSCM/SSL of all concerns, questions, events, incidents, etc.

3.13.8 Validate clearances of visitors and incoming personnel and issue appropriate badges.

3.13.9 Ensure that all personnel entering DTRA facilities are in possession of a valid DTRA security access badge.

3.13.10 Establish positive identification by visually checking the badge photo with the individual possessing the badge. May require checking other forms of identification.

3.13.11 Verify the visitor’s identification from a Government issued picture ID, validate visitor clearance status, and process badges utilizing the automated security database, when a security clearance cannot be validated, the visitors information shall be added to the Visitor Register Log and issued an “Escort Required” Badge.

3.13.12 Ensure badges are available in advance based on lists or requests for conferences, meetings, VIP, etc.

3.13.13 Ensure all badges are properly turned in or invalidated when the individual no longer is granted or needs access. All turn-ins shall be annotated in the proper badge log.

3.13.14 Determine if security access badges are currently valid. If expired or otherwise invalid, deny entry, confiscate the badge and advise the individual to call the DTRA Visitor Control Office.

3.13.15 Check security access badges for obvious visual discrepancies. If discrepancies are noted, deny entry, detain the individual, and contact the DTRA Visitor Control Office for further instructions.

3.13.16 Determine condition of security access badges. If it is frayed, worn, or badly mutilated, instruct the individual to call the DTRA Visitor Control Office.

3.13.17 Deny access to DTRA personnel or visitors who forgets their badges until their clearance and identity can be verified by cross checking the individual’s identification card (Military or Civilian) against the DTRA Secure Access Browser application. The DTRA Visitor Control Office will resolve any problems once clearance and identity have been verified and contractor can issue the appropriate temporary badge and allow entry.

3.13.18 Issue a temporary badge with a “0” to visitors and other personnel without appropriate DTRA Facility access. These personnel must be escorted by a permanent DTRA employee to gain access to the facility, and must be escorted at all times while in DTRA facilities. Once clearance and identity have been verified, contact the permanent DTRA employee via phone and have them come to the Entry Control Point (ECP). Have both parties fill out their appropriate entries on the visitor log completely and legibly written/printed.

3.13.19 Brief sponsors of visitors issued “Escort Required” badges, on their responsibilities as escorts for unclear personnel.

3.13.20 Immediately contact team lead, OSCM and/or SSL for any situation and issues prior to taking any action if no policy is in place or if uncertain of how to deal with them.

3.14 Technical Surveillance Countermeasures (TSCM) Support: The contractor shall:

3.14.1 (FOUO) Conduct TSCM activities IAW DoDI 5240.05, DoD S-5240.05-M-1 and DoD 5240.1-R and all other applicable TSCM guidance promulgated or adhered to by the DoD.

Guidelines listed in Section 5, References.

3.14.2 (FOUO) Provide training products and briefings to increase awareness of the technical threat to DTRA personnel.

3.14.3 (FOUO) Provide analytical reports and products to DTRA leadership.

3.14.4 (FOUO) Maintain metrics of TSCM activities for quarterly reporting to higher HQ.

3.14.5 Read, understand and apply printed rules, detailed orders, instructions and training materials.

3.14.6 Prepare clear, concise, accurate and detailed reports.

3.14.7 Provide excellent customer service in a professional manner at all times.

3.14.8 (FOUO) Lift and carry cases not to exceed 40 pounds without aid.

3.14.9 (FOUO) Operate equipment not exceeding 35 pounds without aid, while atop a ladder to heights not to exceed 30 feet.

3.14.10 (FOUO) Conduct any or all of these duties wearing appropriate safety equipment at all times under hazardous circumstances. The following are examples:

3.14.10.1 Atop buildings

3.14.10.2 In confined spaces that may be poorly lit and poorly ventilated.

3.14.10.3 In areas that may contain dirt, dust, mold, algae, contaminated water, insects, arthropods, fish, mammals, and other natural and man-made hazards.

3.14.10.4 In a variety of temperatures and humidity extremes.

3.14.11 (FOUO) Receive correspondence or deliveries on behalf of DTRA, Technical Counterintelligence Service Branch (OI-MSCSO), and notify the responsible DTRA addresses as soon as possible and follow up such notification with email.

3.14.12 (FOUO) Respond appropriately to the discovery of a suspected technical surveillance device in accordance with DoD S-5240.05-M-1.

3.14.13 (FOUO) Conduct TSCM missions at various locations locally, within the CONUS or OCONUS. Travel to OCONUS locations should not exceed 10 percent of duty time. All travel will be conducted in compliance with the rules and guidelines set forth by U.S. Federal Travel Regulations (FTR).

3.14.14 (FOUO) Conduct TSCM missions at any time of the day, as required by DTRA operations and scheduled events. Contractor may have to adjust work hours accordingly as stated in Section 4.2.

3.14.15 (FOUO) Operate Government Owned Vehicles (GOV) when conducting official duties.

3.14.15.1 (FOUO) Authorized to travel and transport equipment using DoD aircraft and vehicles, specifically Operation Support Airlift, MilAir, and all other government owned vehicles and vessels, as approved by Security and Counterintelligence, Chief (Approval required for each mission).

3.14.16 (FOUO) Attend National-Level meetings and conferences as training opportunities or to represent DTRA’s TSCM program.

3.14.17 (FOUO) Inventory, conduct preventive maintenance, and maintain equipment records on all TSCM equipment.

3.14.18 (FOUO) Conduct TSCM at classified meetings and conferences IAW Volume 3 of DoD 5200.01M.

3.14.19 (FOUO) Provide a final report to the customer, the SCI facility, or other facility accreditation authority no later than 30 business days after completion a TSCM mission.

3.14.20 (FOUO) Record TSCM reporting and feedback into the USD(I)-approved CI information.

3.14.21 (FOUO) Support the development of CI-focused TSCM targeting using a risk-based approach with the goal of identifying and exploiting technical collection efforts targeting DTRA interests.

3.14.22 Training:

3.14.22.1 Meet the minimum training requirements for unsupervised access to DoD networks in accordance with DoD Directive 8570.01, Information Assurance Training, Certification, and Workforce Management, August 15, 2004.

3.14.22.2 Complete the minimum refresher training to retain unsupervised access to DoD networks in accordance with DoD Directive 8570.01, Information Assurance Training, Certification, and Workforce Management, August 15, 2004.

3.14.22.3 Complete basic first aid, CPR, and AED training and maintain certification.

3.14.22.4 Complete a minimum of 40 hours of discipline-specific development or refresher training annually to remain proficient in TSCM.

3.14.22.5 Complete all DTRA annual training requirements as stated in PWS.

3.14.22.6 In addition to the annual DTRA training requirements, complete all TSCM and CI training as required. Examples may include, but aren’t limited to, radiation safety training (required to operate X-Ray equipment), Intelligence Oversight training, site specific requirements (wildlife safety, protected species), and/ or familiarization/operation/maintenance of any new equipment/training essential to complete the mission. These training requirements are to be considered part of the contractor’s official duties.

3.15 Insider Threat Support: The contractor shall:

3.15.1 (FOUO) Demonstrate ability to identify and report indicators of insider threat events;

analyze network traffic, system log files, User Activity Monitoring (UAM) data, and other artifacts to determine potential risk indicators, insider threat activities, and/or policy violations with insider threat implications and identify vulnerable computers or systems that may be used for data compromise.

3.15.2 (FOUO) Perform analytical support, draft no fewer than two (2) referrals a week, and properly document steps taken to assist inquiries into behavior deemed within the scope of insider threat; namely threats to DTRA personnel, technology infrastructure, information, and facilities.

3.15.3 (FOUO) Prepare and deliver briefings on topics relevant to Insider Threat to a variety of personnel and upper level management as needed.

3.15.4 (FOUO) Respond to internal DTRA and external requests for information within assigned suspense dates.

3.15.5 (FOUO) Maintain functioning information-sharing relationships within the insider threat hub as well as insider threat working group members from Counterintelligence, Personnel Security, Information Technology, Office of General Counsel, Office of Inspector General, and Human Resources as needed.

3.15.6 (FOUO) Provide weekly status reports documenting work accomplishments and any occurrence of events with Insider Threat implications, including but not limited to: unauthorized use of information systems, transmissions of sensitive/classified information outside of government controlled networks, hacking and penetration attempts from within.

3.15.7 (FOUO) Receive periodic training in the proper use, retention, and safeguarding of all insider threat related information.

3.15.8 (FOUO) Have attended, or within six months of hire, be registered to attend the National Insider Threat Task Force Insider Threat Hub Operations Course. Extensions may be granted by the Insider Threat Program Manager if class dates are not available within the six month time frame.

3.15.9 (FOUO) Be certified, or within six months of hire, be registered to take the Counter Insider Threat Professional certification exam in order to become a certified Counter Insider Threat professional. Extensions may be granted by the Insider Threat Program Manager if test dates are not available within the six month time frame.

3.15.10 (FOUO) Become familiar with the laws and regulations governing privacy, use, and protection of personal information, and the civil rights and civil liberties of individual employees.

3.15.11 (FOUO) Have significant experience and skill in one or more of the following areas:

Security,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .