RFQATTACH.SPE4A618Q1012.0000.PDF

PDF 200 KB Posted

Attached to
CABLE ASSEMBLY, RADI Federal contract opportunity
Solicitation number
SPE4A618Q1012
Issued by
Defense Logistics Agency Aviation

View the file

Other files for this federal contract opportunity

Other files attached to CABLE ASSEMBLY, RADI, newest first.
File Type Posted
SPE4A618Q1012.PDF PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(Please read Instructions BEFORE completing this application.) (The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires October 31, 2020

The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.) 3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED (See instructions.)

b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/MATERIAL

REQUIRED AT CONTRACTOR FACILITY

Confidential Confidential

20180501

DUE DATE (YYYYMMDD)

SPE4A6-18-Q-1012

c. SOLICITATION OR OTHER NUMBER✖

b. SUBCONTRACT NUMBER

a. PRIME CONTRACT NUMBER (See instructions.)

DATE (YYYYMMDD)

c. FINAL (Complete Item 5 in all cases.)

DATE (YYYYMMDD)REVISION NO.b. REVISED (Supersedes all previous specifications.)

DATE (YYYYMMDD)

a. ORIGINAL (Complete date in all cases.)

(Preceding Contract Number) is transferred to this follow-on contract. Classified material received or generated under

YES. If Yes, complete the following:✖ NO4. IS THIS A FOLLOW-ON CONTRACT?

, retention of the classified material is authorized for the period of: In response to the contractor's request dated

YES. If Yes, complete the following:✖ NO5. IS THIS A FINAL DD FORM 254?

c. COGNIZANT SECURITY OFFICE (CSO) (Name, Address, ZIP Code, Telephone)b. CAGE CODEa. NAME, ADDRESS, AND ZIP CODE

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code.)

c. COGNIZANT SECURITY OFFICE(S) (CSOs) (Name, Address, ZIP Code, Telephone)

b. CAGE CODEa. NAME, ADDRESS, AND ZIP CODE

7. SUBCONTRACTOR(S) (Click button to add more subcontractors.)

c. COGNIZANT SECURITY OFFICE(S) (CSOs) (Name, Address, ZIP Code, Telephone) (If applicable, see instructions.)

b. CAGE CODE (If applicable, see instructions.)

a. LOCATION(S) (For actual performance, see instructions.)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

CABLE ASSEMBLY, RADIO FREQUENCY

NSN: 5995-01-467-4319

CAGE: 49956

P/N: 9730184

9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT (Click here if more space is needed.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION

d. FORMERLY RESTRICTED DATA

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.)

b. RESTRICTED DATA

✖e. NATIONAL INTELLIGENCE INFORMATION:

f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION

k. OTHER (Specify) (See instructions.)

j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)

i. ALTERNATIVE COMPENSATORY CONTROL MEASURES (ACCM)

INFORMATION

h. FOREIGN GOVERMENT INFORMATION

g. NORTH ATLANTIC TREATY ORGANIZATION (NATO) INFORMATION

DD FORM 254, NOV 2017 PREVIOUS EDITION IS OBSOLETE. Adobe LiveCycle Designer ES4

Add More Items

Add More Items

Add Page

(1) Sensitive Compartmented Information (SCI)

(2) Non-SCI

Delete Page

Remove

Remove

UNCLASSIFIEDCLASSIFICATION (When filled in):

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT ACTIVITY (Applicable only if there is no access or storage required at contractor facility. See instructions.)

h. REQUIRE A COMSEC ACCOUNT

k. BE AUTHORIZED TO USE DEFENSE COURIERS

j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS✖

i. HAVE A TEMPEST REQUIREMENT

b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY

c. RECEIVE, STORE, AND GENERATE CLASSIFIED INFORMATION OR

MATERIAL✖

f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES

g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL

INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION

CENTER

e. PERFORM SERVICES ONLY

d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED

INFORMATION (CUI).

(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)

m. OTHER (Specify) (See instructions)

12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address.

(See instructions)

DIRECT

Defense Logistics Agency/Aviation Route Public Release request through Contracting Officer or Designated

Official

THROUGH (Specify)✖ PUBLIC RELEASE AUTHORITY:

13. SECURITY GUIDANCE. The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes;

to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Click button to add additional pages as needed to provide complete guidance.)

See continuation pages.

14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

Yes✖No (If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. Use Item 13 or click button if additional space is needed.)

15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the CSO.

(If Yes, explain and identify specific areas and government activity responsible for inspections. Click button or use Item 13 if additional space is needed.)

YesNo✖

See Reference Items 10j, 11c, 11j, 11l

804-279-1680

e. POC TELEPHONE (Include Area Code.)

stephen.robinson@dla.mil

f. EMAIL ADDRESS (See instructions.)

b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See instructions.)

SPE4A6

d. AAC OF THE CONTRACTING OFFICE (See instructions.)

e. CAGE CODE OF THE PRIME CONTRACTOR (See instructions.)

Robinson, Stephen

d. POC NAME (See instructions.)

Defense Supply Center Richmond 8000 Jefferson Davis Highway Richmond, Va 23297-5100

c. ADDRESS (Include ZIP Code.)

DLA Aviation @ Richmond

a. GCA NAME

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

17. CERTIFICATION AND SIGNATURES. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.

a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See instructions.)

Plassmann, Jeanne M.

804-279-5220

f. TELEPHONE (Include Area Code.)

jeanne.plassmann@dla.mil

g. EMAIL ADDRESS (See instructions.) i. SIGNATUREh. DATE

Contracting Officer

b. TITLE Defense Supply Center Richmond 8000 Jefferson Davis Highway Richmond, VA 23295-5100

c. ADDRESS (Include ZIP Code.)

2018-04-25

DLA DI Industrial Security

f. OTHERS AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)✖

e. ADMINISTRATIVE CONTRACTING OFFICER✖

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION

c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR✖

b. SUBCONTRACTOR

a. CONTRACTOR✖

DD FORM 254 (BACK), NOV 2017

Add Page

SPE4A6

UNCLASSIFIEDCLASSIFICATION (When filled in):

SIGNATURE

SPE4A6-18-Q-1012 Continuation Page.pdf

Add Attachment View Selected Attachment Remove Selected Attachment

Add Page

Delete Page

Delete Page

Delete Page

Add Page

15. INSPECTIONS (Continued)

14. ADDITIONAL SECURITY REQUIREMENTS (Continued)

13. SECURITY GUIDANCE (Continued)

Pages1of1Continuation PageDD FORM 254, NOV 2017 New Page

Additional persons assisting with completion of form (signatures and titles)

Delete Page

SECURITY GUIDANCE (BLOCK 13) CONTINUATION PAGES

FOR SOLICITATION# SPE4A6-18-Q-1012

Per the DD Form 441, Department of Defense Security Agreement, Section VI, signed by the United States Government through the Defense Security Service and the Contractor, the government is not obligated to provide funds and shall not be liable for any security costs or claims of the Contractor arising out of the DD Form 441 Agreement, its instructions, or the requirements identified in the DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), and its changes/revisions.

The Contractor is required to flow-down all applicable requirements of the DD Form 254 to its Subcontractor(s).

Reporting Requirements:

The Contractor shall provide the following to the DLA PLFA Industrial Security Manager (PISM) (contact information listed in block 13 of page two of the DD Form 254):

• Courtesy copy the DLA HQ Industrial Security Program Office on any security incident report (initial and final) involving the loss, compromise, or suspected compromise of classified information sent to the Defense Security Service. The Contractor shall provide a copy to the DLA within the same reporting timeframe as is required by the Defense Security Service.

• Courtesy copy the DLA HQ Industrial Security Program Office on any report involving a cyber-intrusion of DLA program information sent to the Federal Bureau of Investigation and the Defense Security Service per NISPOM Chapter 1, Section 301 and Industrial Security Letter 2013-05.

• Provide a copy of any Defense Security Service letter that indicates a less than satisfactory security rating and/or that negatively impacts the Facility Clearance Level (FCL) of the company within 48-hours of receipt.

• Provide electronic copies of Subcontractor DD Form 254s issued by the Prime and the Subcontractor. The Prime Contractor shall act as the focal point for collecting their Subcontractor’s DD Form 254s and the Prime is responsible for forwarding these DD Form 254s to the DLA HQ Industrial Security Program Office.

• DLA HQ Industrial Security Program Office:

Defense Logistics Agency ATTN: DI / Industrial Security Program Manager 8725 John J. Kingman Road Fort Belvoir, VA 22060-6221 Phone: (703) 767-4376 Email: erica.quinley@dla.mil

Subcontractor Classified Access Approvals:

The Prime Contractor and Subcontractor are authorized to flow access to and/or dissemination of classified information to the level specified in Block 1a to their Subcontractors. Dissemination is

Block 13 Continuation Pages for Solicitation#: SPE4A6-18-Q-1012 only authorized and applicable for information safeguarded at the Contractor’s facility. The Contractor shall provide the appropriate accesses to its Subcontractors as required per NISPOM 5-502. The Prime Contractor and Subcontractor must verify Facility Clearance, Safeguarding Capability and Access Authorizations prior to the dissemination of classified information.

Certain accesses require GCA approval prior to subcontracting and are specified herein, if applicable.

Pre-Award Access

This section concerns the release of classified information to the contractor prior to the award of a DLA classified contract. DLA classified information may only be released to the Contractor for submission preparation purposes following verification of the Contractor’s facility clearance and safeguarding. The DD Form 254 shall act as security guidance for the safeguarding of program-related classified information at the Contractor facility. The Defense Security Service maintains security cognizance of classified information stored at a Contractor facility. However, the following stipulations apply:

• IAW NISPOM paragraphs 5-200 and 5-600, Contractors shall ensure full written accounting and control over all DLA classified information provided to the Contractor by DLA or created as copies by the Contractor.

• IAW NISPOM paragraphs 5-501 and 5-502, distribution of DLA classified information shall only be made to those cleared Contractor personnel working on the Contractor’s response to the request for information, unless otherwise authorized by the Program Manager (PM).

• IAW NISPOM paragraph 5-509, for purposes of this submission request, further distribution of DLA classified information shall only be authorized by the DLA PM overseeing this request for information.

• IAW NISPOM paragraphs 5-702, 5-703, and 5-704, all classified information provided for use in submission preparation shall be returned to DLA or destroyed.

Reference Item 10.j: See For Official Use Only/Controlled Unclassified Information (FOUO/CUI) Supplement below. The Contractor is required to provide the supplement to all uncleared Subcontractors requiring access to FOUO/CUI information.

Reference Item 11.c: The Contractor has a responsibility to understand and use all applicable Security Classification Guidance (SCG) provided by the government (reference NISPOM 4- 102). The DLA has provided a list below of necessary SCGs required to conduct derivative classification. The Contractor shall request the required SCGs from the Contracting Officer, Contracting Officer’s Representative (COR) or designated representative. DLA has the obligation to review existing guidance periodically during the performance stages of the contract and to issue a revised DD Form 254 when a change to the SCGs occurs or when additional SCGs are needed (reference NISPOM Chapter 4, Section 103b.). All classified information received or generated is the property of the U.S. Government. At the termination or expiration of this contract, the GCA will be contacted for proper disposition instructions. The Contractor shall flow-down required SCGs on its Subcontractor DD Form 254s and shall provide copies of the SCGs to its Subcontractor. The following security classification guidance applies:

1. Other Security Classification Guides will be provided as required.

Reference Item 11.j:

1. The Contractor is required to apply Operations Security (OPSEC) to enhance protection of classified and unclassified critical information pursuant to DoD Directive 5205.02, “DoD OPSEC Program; DoD 5205.02-M, “OPSEC Program Manual;” National Security Decision Directive Number 298, “National Operations Security Program;” DLA Instruction 5205.02, “Operations Security (OPSEC) Program,” April 15, 2015; and supplementary instructions.

Service OPSEC guidance may also apply if the contracted activity is performed in a Service-level operational environment. Contractors are required to complete OPSEC refresher training on an annual basis and provide timely and appropriate responses to Agency OPSEC Managers, when necessary.

2. The contractor will accomplish the following minimum requirements in support of the DLA OPSEC Program. Protect those items of critical information, applicable to operations. Items of critical information are those facts, which individually, or in the aggregate, reveal sensitive details about the mission, operation, etc., and thus require protection from adversarial collection or exploitation.

3. Include OPSEC as part of its ongoing security awareness program and take all required OPSEC training provided by DLA.

4. Protect sensitive unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of operations performed by the contractor in support of the mission.

Reference Item 11.l:

Contractor’s Unclassified Automated Information System (AIS):

1. The Contractor shall safeguard and protect CUI provided by or generated for the Government (other than public information) that transits or resides on any non-Government information technology system IAW the procedures in DoDI 8582.01, “Security of Unclassified DoD Information on Non-DoD Information Systems,” June 6, 2012, Enclosure 3 and NIST SP 800- 171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,” June 2015. Information shall be protected from unauthorized access, disclosure, incident or compromise by extending the safeguarding requirements and procedures in DFARS clause 252.204-7012, Safeguarding of Covered Defense Information and Cyber Incident Reporting. The NIST SP 800-171 security controls specified in 252.204-7012 were extended to include Controlled Unclassified Information (CUI) information which resides on, or transits through the contractor’s (prime and all sub-contractors) unclassified information technology systems.

2. The contractor shall ensure that all persons accessing CUI, which includes FOUO, meet the qualifications for an Automated Data Processing/Information Technology (ADP/IT)-III Position requirement) to access DLA unclassified AIS.

3. The “For Official Use Only/Controlled Unclassified Information Supplement” provides additional guidance for the handling, marking, transmission, reproduction, safeguarding, and disposition of FOUO/CUI.

4. DLA reserves the right to conduct compliance inspections of Contractor unclassified information systems and other repositories for the protection of FOUO/CUI.

Reference Item 12: The Prime Contractor shall forward all requests for public release authorization through the Contracting Officer or designated representative to the listed DLA program office. Per NISPOM section 5-511, the Contractor shall include all necessary information to assist with the decision of the DLA program office. Per NISPOM Chapter 7, Section 102c., the Prime Contractor shall act as the focal point for all Subcontractor requests for public release. A lack of response from the DLA program office does not constitute as public release authorization. The Prime Contractor shall not release information to the public prior to receiving written authorization from the DLA program office (this requirement includes any information system that provides public access).

Reference Item 13:

The following drawings are required for this contract instrument:

Classification Number: 0801 Level of Classification: Confidential Document Number: 1038449 Cage: 49956 Document Data Code: CN Revision Level: D Revision Date: 03/24/2005 Distribution Statement: D Declassification Date: 08/01/2023 Date of Source: 08/02/2011

FOR OFFICIAL USE ONLY/CONTROLLED UNCLASSIFIED

INFORMATION SUPPLEMENT

1. Definitions.

a. Controlled Unclassified Information (CUI). Unclassified information which requires access and distribution limitations prior to appropriate coordination and an official determination by cognizant authority approving clearance of the information for release to one or more foreign governments or international organizations, or for official public release. Per DoD Manual 5200.01, Volume 4 it includes the following types of information: "For Official Use Only" (FOUO); “Sensitive But Unclassified” (State Department information); “DEA Sensitive Information” (Drug Enforcement Agency information); “DoD Unclassified Controlled Nuclear Information”; “Sensitive Information” as defined in the Computer Security Act of 1987; and information contained in technical documents (i.e., Technical Data) as discussed in DoD 5230.24, 5230.25, International Traffic in Arms Regulation (ITAR), and the Export Administration Regulations (EAR). Other sensitive information includes Personally Identifiable Information (PII), information covered by the Privacy Act of 1974, and company proprietary information. DoDM 5200.01, Volume 4, DoDD 5205.02, DoDD 5230.9, and DoDI 8550.01 provide additional guidance on the handling of information described in this paragraph.

b. Dual Citizenship. A dual citizen is a citizen of two nations. For the purposes of this document, an individual must have taken an action to obtain or retain dual citizenship.

Citizenship gained as a result of birth to non-U.S. parents or by birth in a foreign country to U.S.

parents thus entitling the individual to become a citizen of another nation does not meet the criteria of this document unless the individual has taken action to claim and to retain such citizenship.

c. For Official Use Only (FOUO). FOUO is a dissemination control applied by the DoD to unclassified information that may be withheld from public disclosure under one or more of the nine exemptions of the Freedom of Information Act (FOIA) (See DOD 5400.7-R). FOUO is not a form of classification to protect U.S. national security interests.

d. National of the United States.Title 8, U.S.C. Section 1101(a)(22), defines a National of the U.S. as:

(1) A citizen of the United States, or,

(2) A person who, but not a citizen of the U.S., owes permanent allegiance to the U.S.

NOTE: 8 U.S.C. Section 1401, paragraphs (a) through (g), lists categories of persons born in and outside the U.S. or its possessions that may qualify as Nationals and Citizens of the U.S. This subsection should be consulted when doubt exists as to whether or not a person can qualify as a National of the U.S.

e. U.S. Person. Any form of business enterprise or entity organized, chartered, or incorporated under the laws of the United States or its possessions and trust territories and any person who is a citizen or national (see National of the United States) of the United States, or permanent resident of the United States under the Immigration and Nationality Act.

2. Access.

a. No person may have access to information designated as CUI unless that person has been determined to have a valid need for such access in connection with the accomplishment of a lawful and authorized Government purpose. The final responsibility for determining whether an individual has a valid need for access to information designated as CUI rests with the individual who has authorized possession, knowledge, or control of the information, not with the prospective recipient.

b. e. When CUI is to be provided to or generated by DoD contractors, the controls and protective measures to be applied shall be described in the pertinent contract documents (e.g., contract clause; statement of work; or DD Form 254, “Department of Defense Contract Security Classification Specification”). Solicitations and contracts shall use a non-disclosure of information clause that prohibits release of unclassified information to the public without approval of the contracting activity (e.g., clause 252.204-7000 of the Defense Federal Acquisition Regulation Supplement). The clause shall also be made applicable to subcontractors.

c. ALL DoD unclassified information MUST BE REVIEWED AND APPROVED FOR

RELEASE through standard DoD Component processes before it is provided to the public (including via posting to publicly accessible websites) in accordance with DoDD 5230.09, Clearance of DoD Information for Public Release, and other applicable regulations. Unclassified information previously approved for release to the public may be shared with any foreign government or organization.

d. Release or disclosure of CUI to foreign governments or international organizations shall be in accordance with DoDD 5230.20, Visits and Assignments of Foreign Nationals, and other policy and procedures that may be established by the USD(P) and the Defense Logistics Agency.

e. Some CUI is export-controlled information which may additionally be protected by law, Executive order, regulation, or contract. DoD officials must pay particular attention to export control regulations and to access restrictions on each type of CUI to ensure compliance with export requirements, especially when non-U.S. citizens are assigned to or visit their organizations.

f. Release or disclosure of CUI to non-U.S. citizens employed by the Department of Defense is permitted, provided access is within the scope of their assigned duties; access would further the execution of a lawful and authorized DoD mission or purpose and would not be detrimental to the interests of the Department of Defense or the U.S. Government; there are no contract restrictions prohibiting access; and the access complies with the requirements of export control regulations, as applicable. In such cases, the non-U.S. citizen shall execute a nondisclosure agreement approved by appropriate DoD Component authorities.

g. CUI may be identified in security classification guides to ensure the information receives appropriate protection. If the security classification guide is subsequently cancelled, a separate memorandum or other guidance document may be issued to identify the declassified information, if any, that qualifies as CUI as well as any CUI previously cited in the guide.

h. For unauthorized disclosures of CUI, no formal security inquiry or investigation is required.

However, appropriate management action shall be taken to fix responsibility for unauthorized disclosure of CUI whenever feasible or required by other guidance, and appropriate disciplinary action shall be taken against those responsible.

i. Non-Sensitive Positions (ADP/IT-III positions). Non-sensitive positions associated with FOUO/CUI are found at Contractor facilities processing such information on their (Contractor's) unclassified computer systems. All unclassified computer systems will be protected in accordance with DFARS 252.204-7012, Safeguarding of Covered Defense Information and Cyber Incident Reporting and NIST SP 800-171, with access to CUI/FOUO conducted in accordance with applicable policy. Personnel nominated to occupy ADP/IT-III designated positions must have at least a National Agency Check with Inquiries (NACI). The Contractor shall contact DLA Office of Personnel Security at DIPersonnelSecurity(PERSEC)Operations@dla.mil, and provide the requested information.

DLA Office of Personnel Security will assist the Contractor complete the necessary paperwork and fingerprints.

3. Identification Markings. FOUO/CUI shall be marked in accordance with DoDM 5200.01, Volume 4, Enclosure 3, Section 2.c.

4. Handling. Storage of FOUO/CUI outside of Contractor facilities (i.e. residence, telework facility, hotel, etc.) shall be in a locked room, drawer, filing cabinet, briefcase, or other storage device, so that access to the material by unauthorized individuals. Continuous storage of FOUO/CUI outside of a Contractor facility shall not exceed 30 days unless government approval is granted.

5. Transmission/Dissemination/Reproduction.

a. Subject to compliance with official distribution statements, FOUO markings (e.g., Export Control, Proprietary Data) and/or Non-Disclosure Agreements which may apply to individual items in question; authorized Contractors, consultants and grantees may transmit/disseminate FOUO/CUI information to each other, other DoD Contractors and DoD officials who have a legitimate need to know in connection with any DoD authorized contract, solicitation, program or activity. The government Procuring Contracting Officer (PCO) will confirm with the Contracting Officer's Representative or Task Order Monitor "legitimate need to know" when required. Contractors shall employ Public Key Infrastructure (PKI) and Public Key (PK) enabling technologies for the electronic transmission of FOUO/CUI. The following general guidelines apply:

(1) In accordance with DoD Manual 5200.01, Volume 4, “Controlled Unclassified Information (CUI),” Enclosure 3, external electronic data transmissions of CUI/FOUO shall be only over secure communications means approved for transmission of such information.

(2) Encryption of e-mail to satisfy this requirement shall be in accordance with DoD

Instruction 8582.01, “Security of Unclassified DoD Information on Non-DoD Information Systems,” June 6, 2012, being accomplished by use of DoD approved Public Key Infrastructure Certification or by the company’s participation in the “Federal Bridge.”

b. Failure of the Contractor to encrypt FOUO/CUI introduces significant risks to the DLA mission. It is essential for the Contractor to understand that mitigation options that are available.

The Contractor must understand that failure to encrypt FOUO/CUI carries with it certain risks to the mission. These risks can be mitigated with the thoughtful application of processes, procedures, and technology. Some of the available mitigation tools include:

(1) Approved DoD PKI/CAC hardware token certificates or DoD trusted software certificates for encrypting data in transport.

(2) Industry best practice of Virtual Private Network (VPN) Internet Protocol

Security (IPSEC) for intra-organization transport.

(3) Industry best practice of Secure Sockets Layer Portal Web Services for document sharing and storage.

(4) Approved DoD standard solutions for encrypting data at rest.

(5) Approved DoD E-Collaboration services via DLA Portal or Defense Information

Systems Agency (DISA) Network Centric Enterprise Services (NCES).

(6) Any FIPS 140-2 validated encryption [e.g., IPSEC, Secure Socket Layer/Transport

Layer Security (SSL/TLS), Secure/Multipurpose Internet Mail Extensions (S/MIME)].

(7) Procure and employ Secure Telephone Equipment (STE).

(8) Procure and employ secure facsimile (FAX) capability.

(9) Utilize secure VTC capabilities.

(10) Hand-carry FOUO/CUI.

(11) Utilize mailing through U.S. Postal Service.

(12) Utilize overnight express mail services.

c. FOUO/CUI shall be processed and stored internally on Automated Information Systems (AIS) or networks 1) when distribution is to an authorized recipient and 2) if the receiving system is protected by either physical isolation or a password protection system. Holders shall not use general, broadcast, or universal e-mail addresses to distribute FOUO/CUI. Discretionary access control measures may be used to preclude access to FOUO/CUI files by users who are authorized system users, but who are not authorized access to FOUO/CUI. External transmission of FOUO/CUI shall be secured using NIST-validated encryption. FOUO/CUI cannot be placed on any publically-accessible medium.

d. Reproduction of FOUO/CUI may be accomplished on unclassified copiers within designated government or Contractor reproduction areas.

6. Storage. During working hours, reasonable steps shall be taken to minimize the risk of access by unauthorized personnel (e.g., not reading, discussing, or leaving FOUO/CUI information unattended where unauthorized personnel are present). After working hours, FOUO/CUI information may be stored in unlocked containers, desks, or cabinets if contract building security is provided. If such building security is not provided or is deemed inadequate, the information shall be stored in locked desks, file cabinets, bookcases, locked rooms, etc.

7. Disposition.

a. When no longer required, FOUO/CUI shall be returned to the DLA office that provided the information or destroyed by any of the following means:

a. Burning (Use of burn bags and an authorized burn facility)

b. Cross-cut shredding (Shredders must be listed on the NSA Evaluated Products

List)

c. Any method approved for the destruction of classified material.

b. Removal of the FOUO/CUI status can only be accomplished by the government originator. The DLA COR shall review and/or coordinate with proper authority the removal of FOUO/CUI status for information in support of contract activity.

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(Please read Instructions BEFORE completing this application.) (The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires October 31, 2020 The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED (See instructions.)

b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/MATERIAL REQUIRED AT CONTRACTOR FACILITY

DUE DATE (YYYYMMDD)

c. SOLICITATION OR OTHER NUMBER

b. SUBCONTRACT NUMBER

a. PRIME CONTRACT NUMBER (See instructions.)

DATE (YYYYMMDD)

c. FINAL (Complete Item 5 in all cases.)

DATE (YYYYMMDD)

REVISION NO.

b. REVISED (Supersedes all previous specifications.)

DATE (YYYYMMDD)

a. ORIGINAL (Complete date in all cases.)

(Preceding Contract Number) is transferred to this follow-on contract.

Classified material received or generated under YES. If Yes, complete the following:

NO

4. IS THIS A FOLLOW-ON CONTRACT?

, retention of the classified material is authorized for the period of:

In response to the contractor's request dated YES. If Yes, complete the following:

NO

5. IS THIS A FINAL DD FORM 254?

c. COGNIZANT SECURITY OFFICE (CSO) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code.)

c. COGNIZANT SECURITY OFFICE(S) (CSOs) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

7. SUBCONTRACTOR(S) (Click button to add more subcontractors.)

c. COGNIZANT SECURITY OFFICE(S) (CSOs) (Name, Address, ZIP Code, Telephone) (If applicable, see instructions.)

b. CAGE CODE (If applicable, see instructions.)

a. LOCATION(S) (For actual performance, see instructions.)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT (Click here if more space is needed.)

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION

d. FORMERLY RESTRICTED DATA

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.)

b. RESTRICTED DATA

e. NATIONAL INTELLIGENCE INFORMATION:

f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION

k. OTHER (Specify) (See instructions.)

j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)

i. ALTERNATIVE COMPENSATORY CONTROL MEASURES (ACCM) INFORMATION

h. FOREIGN GOVERMENT INFORMATION

g. NORTH ATLANTIC TREATY ORGANIZATION (NATO) INFORMATION

DD FORM 254, NOV 2017

PREVIOUS EDITION IS OBSOLETE.

Adobe LiveCycle Designer ES4

(1) Sensitive Compartmented Information (SCI)

(2) Non-SCI CLASSIFICATION (When filled in):

CLASSIFICATION (When filled in):

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT ACTIVITY (Applicable only if there is no access or storage required at contractor facility. See instructions.)

h. REQUIRE A COMSEC ACCOUNT

k. BE AUTHORIZED TO USE DEFENSE COURIERS

j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

i. HAVE A TEMPEST REQUIREMENT

b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY

c. RECEIVE, STORE, AND GENERATE CLASSIFIED INFORMATION OR MATERIAL

f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S. POSSESSIONS AND TRUST TERRITORIES

g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER

e. PERFORM SERVICES ONLY

d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED

INFORMATION (CUI).

(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)

m. OTHER (Specify) (See instructions)

12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address.

(See instructions)

DIRECT

THROUGH (Specify)

PUBLIC RELEASE AUTHORITY:

13. SECURITY GUIDANCE. The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes;

to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Click button to add additional pages as needed to provide complete guidance.)

14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

Yes No (If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. Use Item 13 or click button if additional space is needed.)

15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the CSO.

(If Yes, explain and identify specific areas and government activity responsible for inspections. Click button or use Item 13 if additional space is needed.)

Yes No

e. POC TELEPHONE (Include Area Code.)

f. EMAIL ADDRESS (See instructions.)

b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See instructions.)

d. AAC OF THE CONTRACTING OFFICE (See instructions.)

e. CAGE CODE OF THE PRIME CONTRACTOR (See instructions.)

d. POC NAME (See instructions.)

c. ADDRESS (Include ZIP Code.)

a. GCA NAME

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

17. CERTIFICATION AND SIGNATURES. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.

a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See instructions.)

f. TELEPHONE (Include Area Code.)

g. EMAIL ADDRESS (See instructions.)

i. SIGNATURE

h. DATE

b. TITLE

c. ADDRESS (Include ZIP Code.)

f. OTHERS AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)

e. ADMINISTRATIVE CONTRACTING OFFICER

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION

c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR

b. SUBCONTRACTOR

a. CONTRACTOR

DD FORM 254 (BACK), NOV 2017

CLASSIFICATION (When filled in):

CLASSIFICATION (When filled in):

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

7. SUBCONTRACTOR(S) (Continued)

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. NAME, ADDRESS, AND ZIP CODE

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. LOCATION(S) (For actual performance, see instructions.)

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. LOCATION(S) (For actual performance, see instructions.)

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. LOCATION(S) (For actual performance, see instructions.)

c. COGNIZANT SECURITY OFFICE(S) (Name, Address, ZIP Code, Telephone)

b. CAGE CODE

a. LOCATION(S) (For actual performance, see instructions.)

8. ACTUAL PERFORMANCE (Continued)

9. GENERAL UNCLASSIFIED IDENTIFICATION OF THIS PROCUREMENT (Continued)

DD FORM 254, NOV 2017

Pages of Continuation Page CLASSIFICATION (When filled in):

CLASSIFICATION (When filled in):

15. INSPECTIONS (Continued)

14. ADDITIONAL SECURITY REQUIREMENTS (Continued)

13. SECURITY GUIDANCE (Continued) Pages of Continuation Page

DD FORM 254, NOV 2017

Additional persons assisting with completion of form (signatures and titles) CLASSIFICATION (When filled in):

CLASSIFICATION (When filled in):

9.0.0.2.20120627.2.874785

WHS/ESD/DD

DD 254, Nov 2017, "DoD Contract Security Classification Specification" No No No No Yes SPE4A6-18-Q-1012 Continuation Page.pdf

a. Facility clearance level. Select one.: 3
b. Level of safeguarding for classified information/material required at contractor facility. Select one.: 3
2.c. Due date (four digit year, two digit month, two digit day.: 20180501.00000000
2.c. Solicitation or other number.: SPE4A6-18-Q-1012
Mark X if solicitation or other number.: Yes
2.b. Subcontract number.:
Mark X if Subcontract.: Off
2.a. Prime contract number.:
Date (4 digit year, 2 digit month, 2 digit day).:
Date (4 digit year, 2 digit month, 2 digit day).:
3.b. If revised, revision number.:
Date (Complete in all cases) (4 digit year, 2 digit month, 2 digit day).:
12. Public Release. Proposed public releases shall be submitted for approval prior to release: X first box if Direct, second box if Through.:
4. If yes: Classified material received or generated under. Enter the preceding contract number, (enter Preceding contract number) is transferred to this follow on contract.:
Retention of the classified material is authorized for the period of::
5. If yes, complete the following: In response to the contractors request dated::
6.c. Cognizant security office. (Name, address, and zip code).:
6.b. CAGE code.:
6. Contractor. a. Name, address, and zip code.:
c. Cognizant security office. (Name, address, and zip code).:
b. CAGE code.:
7. Subcontractor(s). a. Name, address, and zip code.:
8.c. Cognizant security office (Name, address, and zip code).:
8.b. CAGE code.:
8. Actual performance. a. Location.:
9. General unclassified description of this procurement.: CABLE ASSEMBLY, RADIO FREQUENCY

NSN: 5995-01-467-4319

CAGE: 49956

P/N: 9730184

10. Contractor will require access to: X if COMSEC information.: Off
X if restricted data.: Off
X if NATO information.: Off
X if other.: Off
X if CUI.: Yes
X if alternative compensatory control measures (ACCM) information.: Off
X if foreign government information.: Off
X if formerly restricted data.: Off
X if formerly restricted data.: Off
X if formerly restricted data.: Off
X if special access program (SAP) information.: Off
X if CNWDI.: Off
Specify other require;ments (see instructions).:
Button1:
Button2:
CheckBox1: 0
DelPage9:
DelPage7:
Classification (when filled in).: UNCLASSIFIED
Classification (when filled in).: UNCLASSIFIED
11. In performing this contract, the contractor will: X if have access to classified information only at another contractor's facility or a government activity.: Off
X if receive and store classified documents only.: Off
X if require a COMSEC account.: Off
X if be authorized to use the Defense Courier Service.: Off
X if have access to CUI.: Yes
X if have OPSEC requirements.: Yes
X if have a TEMPEST requirement.: Off
X if receive, store, and generate classified material.: Yes
X if have access to U.S. classified information outside the U.S., Puerto Rico, U.S. possessions and trust territories.: Off
X if authorized to use the services of DTIC or other secondary distribution center.: Off
X if perform services only.: Off
X if fabricate, modify, or store classified hardware.: Off
X if other.: Off
If through, specify.: Defense Logistics Agency/Aviation
Public release authority:: Route Public Release request through Contracting Officer or Designated Official
13. Security guidance.: See continuation pages.
13. Security guidance.:
15. Inspections. X first box if yes, second box if no.:
15. Inspections. X first box if yes, second box if no.:
15. Inspection. If yes is checked, explain and identify specific areas or elements carved out and the activity responsible for inspections.:
14. Additional security requirements. If yes, identify.: See Reference Items 10j, 11c, 11j, 11l
e. POC telephone number (include area code).: 804-279-1680
f. Email address (see instructions).: stephen.robinson@dla.mil
d. Activity address code of the contracting office.: SPE4A6
d. POC name (last, first, middle initial).: Robinson, Stephen
d. Cognizant security office. (Name, address, and zip code).: Defense Supply Center Richmond

8000 Jefferson Davis Highway Richmond, Va 23297-5100

16.a. Government contracting authority (GCA) name.: DLA Aviation @ Richmond
17.a. Typed name of government or contractor security official (last, first, middle initial).: Plassmann, Jeanne M.
f. Telephone number (include area code).: 804-279-5220
g. Email address (see instructions).: jeanne.plassmann@dla.mil
b. Title.: Contracting Officer
c. Address (include ZIP Code).: Defense Supply Center Richmond

8000 Jefferson Davis Highway Richmond, VA 23295-5100

h. Date signed.: 20180425
i. Signature (click to sign).:
Specify other distribution.: DLA DI Industrial Security
17.f. Mark X if others as necessary.: Yes
17.e. Mark X if administrative contracting officer.: Yes
17.d. Mark X if U.S. activity responsible for overseas security administration.: Off
17.c. Mark X if Cognizant Security Office for prime and subcontractor.: Yes
17.b. Mark X if Subcontractor.: Off
17. Required distribution. a. Mark X if Contractor.: Yes
b. Activity address code of the contracting office.: SPE4A6
e. CAGE code of the prime contractor.:
SignatureField1:
attachmentsList:
AddAttachment:
ViewAttachment:
RemoveAttachment:
DelPage13:
DelPage14:
DelPage15:
Classification (when filled in).: UNCLASSIFIED
9. General identification of this procurement.:
Total number of pages.: 1.00000000
Page number of this page.: 1.00000000
Button3:
DeletePage:
Signature.:
Title.:
Title.:
Title.:
Title.:
Signature.:
Signature.:
Signature.:

File details come from the government source that posted it.