SPRBL1-18-R-0039_Attachment-0001_DD-254.pdf

PDF 1 MB Posted

Attached to
SPRBL1-18-R-0039 Federal contract opportunity
Solicitation number
SPRBL1-18-R-0039
Issued by
Defense Logistics Agency Land and Maritime

About this file

SPRBL1-18-R-0039_Attachment-0001_DD-254

View the file

Other files for this federal contract opportunity

Other files attached to SPRBL1-18-R-0039, newest first.
File Type Posted
SPRBL1-18-R-0039_J&A_(Redacted).pdf PDF
SPRBL1-18-R-0039-0001.pdf PDF
SPRBL1-18-R-0039.pdf PDF
SPRBL1-18-R-0039_Exhibit-A_Technical-Requirements-and-CDRLs.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEPARTMENT OF DEFENSE 1. CLEARANCE AND SAFEGUARDING

CONTRACT SECURITY CLASSIFICATION SPECIFICATION a. FACILITY CLEARANCE REQUIRED

SECRET

(The requirements of the DoD Industrial Security Manual apply to all aspects of this effort)

b. LEVEL OF SAFEGUARDING REQUIRED

SECRET

2. THIS SPECIFICATION IS FOR: (X and complete as applicable) 3. THIS SPECIFICATION IS: (X and complete as applicable)

a. PRIME CONTRACT NUMBER a. ORIGINAL (Complete date in all cases) Date (YYYYMMDD) 20170105

b. SUBCONTRACT NUMBER b. REVISED (Supersedes all previous specs)

Revision No. Date (YYYYMMDD)

c. SOLICITATION OR OTHER NUMBER Due Date (YYYYMMDD) c. FINAL (Complete Item 5 in all cases) Date (YYYYMMDD)

SPRBL1-18-R-0039

4. IS THIS A FOLLOW-ON CONTRACT? YES NO. If Yes complete the following

Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract

5. IS THIS A FINAL DD FORM 254? YES NO. If Yes complete the following

In response to the Contractor's request dated , retention of the identified classified material is authorized for the period of .

6. CONTRACTOR (Include Commercial and Government Entity ( CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

7. SUBCONTRACTOR

a. NAME, ADDRESS, AND ZIP CODE b. CAGE CODE c. COGNIZANT SECURITY OFFICES ( Name, Address, and Zip Code)

8. ACTUAL PERFORMANCE

a. LOCATION b. CAGE CODE c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

Same as 6.a OR See Block 13 Reference Item 8.a

9. GENERAL IDENTIFICATION OF THIS PROCUREMENT

Horizontal Technology Integration (HTI), Second Generation Forward Looking Infrared (2GF), Repair and Spares Sustainment support services for Communications and Electronics Command (CECOM), Integrated Logistics Support Center (ILSC).

10. THIS CONTRACT WILL REQUIRE ACCESS TO: YES NO 11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: YES NO

a. COMMUNICATIONS SECURITY (COMSEC)

INFORMATION

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER

CONTRACTOR’S FACILITY OR A GOVERNMENT ACTIVITY

b. RESTRICTED DATA b. RECEIVE CLASSIFIED DOCUMENTS ONLY

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION c. RECEIVE AND GENERATE CLASSIFIED MATERIAL

d. FORMERLY RESTRICTED DATA: d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

e. INTELLIGENCE INFORMATION: e. PERFORM SERVICES ONLY

(1) Sensitive Compartmented Information (SCI) f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO

RICO, U.S. POSSESSIONS AND TRUST TERRITORIES

(2) Non-SCI g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL

INFORMATION CENTER (DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER

f. SPECIAL ACCESS INFORMATION h. REQUIRE A COMSEC ACCOUNT

g. NATO INFORMATION i. HAVE A TEMPEST REQUIREMENT

h. FOREIGN GOVERNMENT INFORMATION j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

i. LIMITED DISSEMINATION INFORMATION k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE

j. FOR OFFICIAL USE ONLY INFORMATION l. OTHER (Specify)

k. OTHER Specify)

Security Classification Guides, See Ref 13

− Restrict Access to Contractor’s Unclassified Automated Information System (AIS).

Sensitive IT duties required: See sheet 13A

DD Form 254, DEC 1999 Previous editions are obsolete

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039 Attachment 0001

X

12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the industrial Security Manual or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public release shall be submitted for approval prior to release

Direct Through (Specify):

Defense Logistics Agency/Land and Maritime Route Public Release request through Contracting Officer or Designated Official to the Directorate for Freedom of Information and Security Review, Office of the Assistant Secretary of Defense (Public Affairs)* for review.

*In the case of non-DoD User Agencies, requests for disclosure shall be submitted to that agency.

13. SECURITY GUIDANCE. The security classification guidance needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the Contractor is authorized and encouraged to provide recommended changes: to challenge the guidance or classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any document/guides/extracts referenced herein.

Add additional pages as needed to provide complete guidance.

Per the DD Form 441, Department of Defense Security Agreement, Section VI, signed by the United States Government through the Defense Security Service and the Contractor, the government is not obligated to provide funds and shall not be liable for any security costs or claims of the Contractor arising out of the DD Form 441 Agreement, its instructions, or the requirements identified in the DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), and its changes/revisions.

The Contractor is required to flow-down all applicable requirements of the DD Form 254 to its Subcontractor(s).

Direct all questions pertaining to the DD Form 254 to the DLA PLFA Industrial Security Manager (PISM) office by phone at 614-692-4801 or by email at dlacolinfosecurity@dla.mil.

DLA PISM:

JACK WHITE

Industrial Security Program Manager Land and Maritime, Columbus

See Continuation Pages Yes No 14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to ISM requirements, are established for this contract. (If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the cognizant security office. Use Item 13 if additional space is needed.)

See Reference Items 10a, 10j, 10e(2), 10j, 10k, 11c, 11d, 11g, 11h, 11i, 11j, 11k, 11l

15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the cognizant security office. (If Yes, explain and identify specific areas or elements carved out and the activity responsible for inspections. Use Item 13 if additional space is needed.

Yes No

16. CERTIFICATION AND SIGNATURE. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below.

a. TYPED NAME OF CERTIFYING OFFICIAL

Theresa Boutchyard

b. TITLE

Contracting Officer

c. TELEPHONE (Include Area Code)

443-861- 4532

d. ADDRESS (Include ZIP Code) 17. REQUIRED DISTRIBUTION

6565 Surveillance Loop a. CONTRACTOR

Building 6001, Room C1301 b. SUBCONTRACTOR

Aberdeen Proving Ground, MD 21005-1846 c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR

e. SIGNATURE

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION

e. ADMINISTRATIVE CONTRACTING OFFICER

f. OTHERS AS NECESSARY DLA Indsec/DSCC-VT DD Form 254 Reverse, DEC 1999

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039 Attachment 0001

SECURITY GUIDANCE (BLOCK 13) CONTINUATION PAGES

Contract #TBD / Solicitation #SPRBL1-18-R-0039

Reporting Requirements:

The Contractor shall provide the following to the DLA PLFA Industrial Security Manager (PISM) (contact information listed in block 13 of page two of the DD Form 254):

• Courtesy copy the DLA HQ Industrial Security Program Office on any security incident report (initial and final) involving the loss, compromise, or suspected compromise of classified information sent to the Defense Security Service. The Contractor shall provide a copy to the DLA within the same reporting timeframe as is required by the Defense Security Service.

• Courtesy copy the DLA HQ Industrial Security Program Office on any report involving a cyber-intrusion of DLA program information sent to the Federal Bureau of Investigation and the Defense Security Service per NISPOM Chapter 1, Section 301 and Industrial Security Letter 2013-05.

• Provide a copy of any Defense Security Service letter that indicates a less than satisfactory security rating and/or that negatively impacts the Facility Clearance Level (FCL) of the company within 48-hours of receipt.

• Provide electronic copies of Subcontractor DD Form 254s issued by the Prime and the Subcontractor. The Prime Contractor shall act as the focal point for collecting their Subcontractor’s DD Form 254s and the Prime is responsible for forwarding these DD Form 254s to the DLA HQ Industrial Security Program Office.

• DLA HQ Industrial Security Program Office:

Defense Logistics Agency ATTN: DI / Industrial Security Program Manager 8725 John J. Kingman Road Fort Belvoir, VA 22060-6221 Phone: (703) 767-4376 Email: erica.quinley@dla.mil

Subcontractor Classified Access Approvals:

The Prime Contractor and Subcontractor are authorized to flow access to and/or dissemination of classified information to the SECRET level to their Subcontractors. Dissemination is only authorized and applicable for information safeguarded at the Contractor’s facility. The Contractor shall provide the appropriate accesses to its Subcontractors as required per NISPOM 5-502. The Prime Contractor and Subcontractor must verify Facility Clearance, Safeguarding Capability and Access Authorizations prior to the dissemination of classified information.

This section concerns the release of classified information to the contractor regarding the government’s SOLICITATION; DLA classified information may only be released to the Contractor for submission preparation purposes following verification of the Contractor’s facility clearance and safeguarding. The DD Form 254 shall act as security guidance for the

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039 safeguarding of program-related classified information at the Contractor facility. The Defense Security Service maintains security cognizance of classified information stored at a Contractor facility. However, the following stipulations apply:

• IAW NISPOM paragraphs 5-200 and 5-600, Contractors shall ensure full written accounting and control over all DLA classified information provided to the Contractor by DLA or created as copies by the Contractor.

• IAW NISPOM paragraphs 5-501 and 5-502, distribution of DLA classified information shall only be made to those cleared Contractor personnel working on the Contractor’s response to the request for information, unless otherwise authorized by the Program Manager (PM).

• IAW NISPOM paragraph 5-509, for purposes of this submission request, further distribution of DLA classified information shall only be authorized by the DLA PM overseeing this request for information.

• IAW NISPOM paragraphs 5-702, 5-703, and 5-704, all classified information provided for use in submission preparation shall be returned to DLA or destroyed.

Reference Item 10.a and 11.h: The Contractor shall comply with the requirements of NISPOM Chapter 9, Section 4 and National Security Agency/Central Security Service Policy Manual Number 3-16, Control of Communications Security (COMSEC) Material, for access to and safeguarding of COMSEC information.

Reference Item 10.j: See For Official Use Only/Controlled Unclassified Information (FOUO/CUI) Supplement below. The Contractor is required to provide the supplement to all uncleared Subcontractors requiring access to FOUO/CUI information.

Reference Item 11.c: The Contractor has a responsibility to understand and use all applicable Security Classification Guidance (SCG) provided by the government (reference NISPOM 4- 102). The DLA has provided a list below of necessary SCGs required to conduct derivative classification. The Contractor shall request the required SCGs from the Contracting Officer, Contracting Officer’s Representative (COR) or designated representative. The DLA has the obligation to review existing guidance periodically during the performance stages of the contract and to issue a revised DD Form 254 when a change to the SCGs occurs or when additional SCGs are needed (reference NISPOM Chapter 4, Section 103b.). The Contractor shall flow-down required SCGs on its Subcontractor DD Form 254s and shall provide copies of the SCGs to its Subcontractor. The following security classification guidance applies:

1. The drawing(s) and or SCG(s) listed in reference 13 are the source document(s) for this contract.

2. Other Security Classification Guides will be provided as required.

Reference Item 11.d: The Contractor is required to provide adequate storage and transportation for classified hardware to the level of (SECRET). If the classified hardware is of such a size or quantity that it cannot be safeguarded in a regular-sized GSA-approved storage container, a Closed Area, Vault, or additional security containers may be required. Per the NISPOM, the Defense Security Service has responsibility for the authorization and approval of all Closed Areas and/or Vaults within the Contractor’s facility.

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039

Reference Item 11.g: The Contractor is authorized to use the services of the Defense Technical Information Center (DTIC) or other secondary distribution center. As required, the Contractor will prepare and submit the DD Form 1540, “Registration for Scientific and Technical Information Services” and DD Form 2345, “Militarily Critical Technical Data Agreement” to the contracting office for approval. Subcontractors are required to submit requests through the Prime Contractor.

Reference Item 11.i: TEMPEST countermeasures within the Continental United States shall not be imposed unless recommended by a Certified TEMPEST Technical Authority (CTTA) (CTTA approved by the Service Element issuing a contract), approved by the DLA office of the Director of Technical Intelligence, and directed by the Contracting Officer.

Reference Item 11.j:

1. The Contractor is required to apply Operations Security (OPSEC) to enhance protection of classified and unclassified critical information pursuant to DoD Directive 5205.02, “DoD OPSEC Program; DoD 5205.02-M, “OPSEC Program Manual;” National Security Decision Directive Number 298, “National Operations Security Program;” DLA Instruction 5205.02, “Operations Security (OPSEC) Program,” April 15, 2015; and supplementary instructions.

Service OPSEC guidance may also apply if the contracted activity is performed in a Service-level operational environment. Contractors are required to complete OPSEC refresher training on an annual basis and provide timely and appropriate responses to Agency OPSEC Managers, when necessary.

2. The contractor will accomplish the following minimum requirements in support of the DLA OPSEC Program. Protect those items of critical information, applicable to operations. Items of critical information are those facts, which individually, or in the aggregate, reveal sensitive details about the mission, operation, etc., and thus require protection from adversarial collection or exploitation.

3. Include OPSEC as part of its ongoing security awareness program and take all required OPSEC training provided by DLA.

4. Protect sensitive unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of operations performed by the contractor in support of the mission.

Reference Item 11.l:

Contractor’s Unclassified Automated Information System (AIS):

1. The Contractor shall safeguard and protect CUI provided by or generated for the Government (other than public information) that transits or resides on any non-Government information technology system IAW the procedures in DoDI 8582.01, “Security of Unclassified DoD Information on Non-DoD Information Systems,” June 6, 2012, Enclosure 3 and NIST SP 800- 171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,” June 2015. Information shall be protected from unauthorized access, disclosure, Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039 incident or compromise by extending the safeguarding requirements and procedures in DFARS clause 252.204-7012, Safeguarding of Covered Defense Information and Cyber Incident Reporting. The NIST SP 800-171 security controls specified in 252.204-7012 were extended to include Controlled Unclassified Information (CUI) information which resides on, or transits through the contractor’s (prime and all sub-contractors) unclassified information technology systems.

2. The contractor shall ensure that all persons accessing CUI, which includes FOUO, meet the qualifications for an Automated Data Processing/Information Technology (ADP/IT)-III Position requirement).

3. The “For Official Use Only/Controlled Unclassified Information Supplement” provides additional guidance for the handling, marking, transmission, reproduction, safeguarding, and disposition of FOUO/CUI.

4. DLA reserves the right to conduct compliance inspections of Contractor unclassified information systems and other repositories for the protection of FOUO/CUI.

Reference Item 12: The Prime Contractor shall forward all requests for public release authorization through the Contracting Officer or designated representative to the listed DLA program office. Per NISPOM section 5-511, the Contractor shall include all necessary information to assist with the decision of the DLA program office. Per NISPOM Chapter 7, Section 102c., the Prime Contractor shall act as the focal point for all Subcontractor requests for public release. A lack of response from the DLA program office does not constitute as public release authorization. The Prime Contractor shall not release information to the public prior to receiving written authorization from the DLA program office (this requirement includes any information system that provides public access).

Reference Item 13:

Security Classification Guides(SCGs): Lightweight Laser Designator Rangefinder, 19 Feb 2002;

Horizontal Technology Integration -2nd Generation FLIR, 8 May 2003: Force XXI Battle Command Brigade and Below (FBCB2) I Joint Battle Command-Platform (JBC-P), 31 Mar 2010, or the Operational Security Classification Guide, Force XXI Battle Command, Brigade and Below and Joint Battle Command - Platform, dated 4 Jan 2006.

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039

FOR OFFICIAL USE ONLY/CONTROLLED UNCLASSIFIED

INFORMATION SUPPLEMENT

1. Definitions.

a. Controlled Unclassified Information (CUI). Unclassified information which requires access and distribution limitations prior to appropriate coordination and an official determination by cognizant authority approving clearance of the information for release to one or more foreign governments or international organizations, or for official public release. Per DoD Manual 5200.01, Volume 4 it includes the following types of information: "For Official Use Only" (FOUO); “Sensitive But Unclassified” (State Department information); “DEA Sensitive Information” (Drug Enforcement Agency information); “DoD Unclassified Controlled Nuclear Information”; “Sensitive Information” as defined in the Computer Security Act of 1987; and information contained in technical documents (i.e., Technical Data) as discussed in DoD 5230.24, 5230.25, International Traffic in Arms Regulation (ITAR), and the Export Administration Regulations (EAR). Other sensitive information includes Personally Identifiable Information (PII), information covered by the Privacy Act of 1974, and company proprietary information. DoDM 5200.01, Volume 4, DoDD 5205.02, DoDD 5230.9, and DoDI 8550.01 provide additional guidance on the handling of information described in this paragraph.

b. Dual Citizenship. A dual citizen is a citizen of two nations. For the purposes of this document, an individual must have taken an action to obtain or retain dual citizenship.

Citizenship gained as a result of birth to non-U.S. parents or by birth in a foreign country to U.S.

parents thus entitling the individual to become a citizen of another nation does not meet the criteria of this document unless the individual has taken action to claim and to retain such citizenship.

c. For Official Use Only (FOUO). FOUO is a dissemination control applied by the DoD to unclassified information that may be withheld from public disclosure under one or more of the nine exemptions of the Freedom of Information Act (FOIA) (See DOD 5400.7-R). FOUO is not a form of classification to protect U.S. national security interests.

d. National of the United States.Title 8, U.S.C. Section 1101(a)(22), defines a National of the U.S. as:

(1) A citizen of the United States, or,

(2) A person who, but not a citizen of the U.S., owes permanent allegiance to the U.S.

NOTE: 8 U.S.C. Section 1401, paragraphs (a) through (g), lists categories of persons born in and outside the U.S. or its possessions that may qualify as Nationals and Citizens of the U.S. This subsection should be consulted when doubt exists as to whether or not a person can qualify as a National of the U.S.

e. U.S. Person. Any form of business enterprise or entity organized, chartered, or incorporated under the laws of the United States or its possessions and trust territories and any

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039 person who is a citizen or national (see National of the United States) of the United States, or permanent resident of the United States under the Immigration and Nationality Act.

2. Access.

a. No person may have access to information designated as CUI unless that person has been determined to have a valid need for such access in connection with the accomplishment of a lawful and authorized Government purpose. The final responsibility for determining whether an individual has a valid need for access to information designated as CUI rests with the individual who has authorized possession, knowledge, or control of the information, not with the prospective recipient.

b. e. When CUI is to be provided to or generated by DoD contractors, the controls and protective measures to be applied shall be described in the pertinent contract documents (e.g., contract clause; statement of work; or DD Form 254, “Department of Defense Contract Security Classification Specification”). Solicitations and contracts shall use a non-disclosure of information clause that prohibits release of unclassified information to the public without approval of the contracting activity (e.g., clause 252.204-7000 of the Defense Federal Acquisition Regulation Supplement). The clause shall also be made applicable to subcontractors.

c. ALL DoD unclassified information MUST BE REVIEWED AND APPROVED FOR

RELEASE through standard DoD Component processes before it is provided to the public (including via posting to publicly accessible websites) in accordance with DoDD 5230.09, Clearance of DoD Information for Public Release, and other applicable regulations. Unclassified information previously approved for release to the public may be shared with any foreign government or organization.

d. Release or disclosure of CUI to foreign governments or international organizations shall be in accordance with DoDD 5230.20, Visits and Assignments of Foreign Nationals, and other policy and procedures that may be established by the USD(P) and the Defense Logistics Agency.

e. Some CUI is export-controlled information which may additionally be protected by law, Executive order, regulation, or contract. DoD officials must pay particular attention to export control regulations and to access restrictions on each type of CUI to ensure compliance with export requirements, especially when non-U.S. citizens are assigned to or visit their organizations.

f. Release or disclosure of CUI to non-U.S. citizens employed by the Department of Defense is permitted, provided access is within the scope of their assigned duties; access would further the execution of a lawful and authorized DoD mission or purpose and would not be detrimental to the interests of the Department of Defense or the U.S. Government; there are no contract restrictions prohibiting access; and the access complies with the requirements of export control regulations, as applicable. In such cases, the non-U.S. citizen shall execute a nondisclosure agreement approved by appropriate DoD Component authorities.

g. CUI may be identified in security classification guides to ensure the information receives appropriate protection. If the security classification guide is subsequently cancelled, a separate memorandum or other guidance document may be issued to identify the declassified information, if any, that qualifies as CUI as well as any CUI previously cited in the guide.

h. For unauthorized disclosures of CUI, no formal security inquiry or investigation is required.

However, appropriate management action shall be taken to fix responsibility for unauthorized disclosure of CUI whenever feasible or required by other guidance, and appropriate disciplinary action shall be taken against those responsible.

i. Non-Sensitive Positions (ADP/IT-III positions). Non-sensitive positions associated with FOUO/CUI are found at Contractor facilities processing such information on their (Contractor's) unclassified computer systems. All unclassified computer systems will be protected in accordance with DFARS 252.204-7012, Safeguarding of Covered Defense Information and Cyber Incident Reporting and NIST SP 800-171, with access to CUI/FOUO conducted in accordance with applicable policy. Personnel nominated to occupy ADP/IT-III designated positions must have at least a National Agency Check with Inquiries (NACI). The Contractor shall contact DLA Office of Personnel Security at DIPersonnelSecurity(PERSEC)Operations@dla.mil, and provide the requested information.

DLA Office of Personnel Security will assist the Contractor complete the SF85, Position of Trust Questionnaire, and fingerprints.

3. Identification Markings. FOUO/CUI shall be marked in accordance with DoDM 5200.01, Volume 4, Enclosure 3, Section 2.c.

4. Handling. Storage of FOUO/CUI outside of Contractor facilities (i.e. residence, telework facility, hotel, etc.) shall be in a locked room, drawer, filing cabinet, briefcase, or other storage device, so that access to the material by unauthorized individuals. Continuous storage of FOUO/CUI outside of a Contractor facility shall not exceed 30 days unless government approval is granted.

5. Transmission/Dissemination/Reproduction.

a. Subject to compliance with official distribution statements, FOUO markings (e.g., Export Control, Proprietary Data) and/or Non-Disclosure Agreements which may apply to individual items in question; authorized Contractors, consultants and grantees may transmit/disseminate FOUO/CUI information to each other, other DoD Contractors and DoD officials who have a legitimate need to know in connection with any DoD authorized contract, solicitation, program or activity. The government Procuring Contracting Officer (PCO) will confirm with the Contracting Officer's Representative or Task Order Monitor "legitimate need to know" when required. Contractors shall employ Public Key Infrastructure (PKI) and Public Key (PK) enabling technologies for the electronic transmission of FOUO/CUI. The following general guidelines apply:

(1) In accordance with DoD Manual 5200.01, Volume 4, “Controlled Unclassified Information (CUI),” Enclosure 3, external electronic data transmissions of CUI/FOUO shall be only over secure communications means approved for transmission of such information.

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039

(2) Encryption of e-mail to satisfy this requirement shall be in accordance with DoD

Instruction 8582.01, “Security of Unclassified DoD Information on Non-DoD Information Systems,” June 6, 2012, being accomplished by use of DoD approved Public Key Infrastructure Certification or by the company’s participation in the “Federal Bridge.”

b. Failure of the Contractor to encrypt FOUO/CUI introduces significant risks to the DLA mission. It is essential for the Contractor to understand that mitigation options that are available.

The Contractor must understand that failure to encrypt FOUO/CUI carries with it certain risks to the mission. These risks can be mitigated with the thoughtful application of processes, procedures, and technology. Some of the available mitigation tools include:

(1) Approved DoD PKI/CAC hardware token certificates or DoD trusted software certificates for encrypting data in transport.

(2) Industry best practice of Virtual Private Network (VPN) Internet Protocol

Security (IPSEC) for intra-organization transport.

(3) Industry best practice of Secure Sockets Layer Portal Web Services for document sharing and storage.

(4) Approved DoD standard solutions for encrypting data at rest.

(5) Approved DoD E-Collaboration services via DLA Portal or Defense Information

Systems Agency (DISA) Network Centric Enterprise Services (NCES).

(6) Any FIPS 140-2 validated encryption [e.g., IPSEC, Secure Socket Layer/Transport

Layer Security (SSL/TLS), Secure/Multipurpose Internet Mail Extensions (S/MIME)].

(7) Procure and employ Secure Telephone Equipment (STE).

(8) Procure and employ secure facsimile (FAX) capability.

(9) Utilize secure VTC capabilities.

(10) Hand-carry FOUO/CUI.

(11) Utilize mailing through U.S. Postal Service.

(12) Utilize overnight express mail services.

c. FOUO/CUI shall be processed and stored internally on Automated Information Systems (AIS) or networks 1) when distribution is to an authorized recipient and 2) if the receiving system is protected by either physical isolation or a password protection system. Holders shall not use general, broadcast, or universal e-mail addresses to distribute FOUO/CUI. Discretionary access control measures may be used to preclude access to FOUO/CUI files by users who are authorized system users, but who are not authorized access to FOUO/CUI. External transmission of FOUO/CUI shall be secured using NIST-validated encryption. FOUO/CUI cannot be placed on any publically-accessible medium.

d. Reproduction of FOUO/CUI may be accomplished on unclassified copiers within designated government or Contractor reproduction areas.

6. Storage. During working hours, reasonable steps shall be taken to minimize the risk of access by unauthorized personnel (e.g., not reading, discussing, or leaving FOUO/CUI information unattended where unauthorized personnel are present). After working hours, FOUO/CUI information may be stored in unlocked containers, desks, or cabinets if contract building security

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039 is provided. If such building security is not provided or is deemed inadequate, the information shall be stored in locked desks, file cabinets, bookcases, locked rooms, etc.

7. Disposition.

a. When no longer required, FOUO/CUI shall be returned to the DLA office that provided the information or destroyed by any of the following means:

a. Burning (Use of burn bags and an authorized burn facility)

b. Cross-cut shredding (Shredders must be listed on the NSA Evaluated Products

List)

c. Any method approved for the destruction of classified material.

b. Removal of the FOUO/CUI status can only be accomplished by the government originator. The DLA COR shall review and/or coordinate with proper authority the removal of FOUO/CUI status for information in support of contract activity.

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039

DD254, Block 13 Continuation

10a/11h- COMSEC information/material will be processed IAW DoD 5220.22-M, NSA/CSS Policy Manual 3- 16, AR 380-40 (Policy for Safeguarding and Controlling Communications Security), and additional security guidelines (Appendix A). When access is required at Government facilities, contractor personnel will adhere to COMSEC rules and regulations as mandated by Command policy and procedures. Contractor personnel requiring COMSEC access and/or authorized a COMSEC account must be U.S. Citizens and possess a final clearance at the appropriate level. All contractors shall be briefed before access to COMSEC is granted.

Subcontracts requiring classified COMSEC information shall be awarded only upon the approval of the Contracting Officer. Concurrence of the KO is required prior to subcontractors working on the program. Copies of the subcontract DD Form 254 will be forwarded to the KO for the Contract file and to CECOM G2 for DD Form 254 tracker information. Per AR 380-40, Chapter 4: Contractor personnel are subject to the Department of Army Cryptographic Access Program (DACAP).

10e (2). Non-SCI Intelligence Materials access required for performance by contractor. Non-SCI Information is not releasable to contractor employees who have not received a clearance at the appropriate security level. Written concurrence of the KO is required prior to subcontracting, Appendix C.

10j. Safeguarding "For Official Use Only” (FOUO) information, Appendix D. FOUO Information generated and/o provided under this contract shall be safeguarded and marked as specified in AR 25-55 and DoD 5200.1 M (Marking is in Volume 2).

10k. SIPRNET ACCESS: All contractors requiring access to the SIPRNET MUST HAVE A FINAL SECRET CLEARANCE OR Interim Top Secret clearance. All contractors with SIPRNET access MUST receive COMSEC and NATO Awareness briefings from their FSO prior to being granted access. COMSEC and NATO Awareness Briefing dates must be recorded on all visit requests. The NATO Awareness Briefing is required to inform personnel how to protect NATO information in the event they come across it while accessing SIPRNET. The contractor shall not access, download or further disseminate any special access date (i.e., intelligence, NATO, COMSEC, etc.) outside the execution of the defined contract requirements. All contractors will read the NATO Central Registry awareness briefing located at: https://secureweb.hqda.pentagon.mil/cusr/forms.aspx prior to being issued a SIPRNet account. This briefing does not authorize NATO access, and is solely for the purpose of awareness.

11c/d- The contractor will receive and generate classified material, and fabricate, modify, or store classified hardware. The contractor requires access to classified source data up to and including SECRET in support work on this effort. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents. Use of “Multiple Sources” on the “Derived From” line necessitates compliance with the NISPOM, paragraph 4-208a, and the use of a bibliography.

11g. The contractor is authorized the use of the Defense Technical Information Center (DTIC) or other secondary distribution center. The contractor will prepare DD Forms 1540 and 2345 for authorized access to DTIC. Completed forms will be provided to the KO for processing.

11i. Access to SIPRNet, if authorized at contractor facilities, requires sponsorship through CECOM G2 for determination of TEMPEST from the Army TPM, 902nd MI Group. TEMPEST requirements are reviewed and determined IAW AR 380-27, Control of Compromising Emanations (FOUO), 19 May 2010, Chapter 4, TEMPEST Countermeasures Review. TEMPEST Information is not releasable to contractor employees who have not received a FINAL Clearance at the appropriate security level. Written concurrence of the KO is required prior to subcontracting. See Appendix E.

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039

11k. Contractor is authorized to use Defense Courier Service (DCS). The KO must obtain written approval from the Commander, Defense Courier Service, Attn: Operations Division, Fort George G. Meade, MD. 20755-5370. Only certain classified information qualifies for shipment by DCS. Prior approval of the KO is required before a prime contractor can authorize a subcontractor to use the services of DCS.

11j. Contractor shall develop an OPSEC Plan IAW AR 530-1, Chapter 6 as listed in section 2.0, and CDRL # D001 of the Technical Requirements document. The OPSEC Plan/SOP will be for use for work at contractor facilities. When contractor is performing their work at Government facilities, the contractors shall adhere to the OPSEC requirements IAW the following Program OPSEC Plan/SOP: (Title and Date of the OPSEC Plan/SOP) Level I OPSEC training is available at the following website: http://cdse.edu/catalog/elearning/GS130.html (Duration: 45 minutes).

11l. IT Sensitive Duties Required (See Block 13, Item 13a).

13a. Contractor personnel performing IT sensitive duties are subject to investigative and assignment requirements IAW AR 25-2, AR 380-67, DoD 8570.0 and affiliated regulations. Army regulation available at http://www.apd.army.mil.

13b.Foreign subcontractors, foreign vendors and/or visitors that are not cleared US Companies, participating in Army foreign disclosure issues will be handled in accordance with AR 380-10, Foreign Disclosure and Contacts with Foreign Representatives, dated 4 DEC 2013.

All disclosures (i.e., oral, visual, briefing, documents) to foreign nationals require prior approval by the foreign disclosure officer.

All requests for non-US cleared foreign subcontractor and/or Foreign own companies to perform on this contract must be requested from the Prime Contract to the KO through Program Office and approved by Foreign Disclosure Officer.

13c. Classified information will be protected IAW the NISPOM, Chapter 5. All security incidents involving classified information will be reported to the CECOM G2 Industrial Security Office, and DSS Industrial Security Representative. Information will be forwarded to KO and the PM for a program damage assessment to be conducted

IAW AR 380-49.

13d. All subcontractor DD254s and subcontractor tier DD254s will be sent to the KO. Any Contractors/subcontractors owned by Foreign Companies and that have a clearance issued by the Defense Security Service under a Special Security Agreement need to have a National Interest Determination (NID) approved if access is required to: Top Secret; COMSEC; Restricted Data; SCI and/or SAP. NID requirements and justification must be sent through CECOM G2 to be forwarded to the approving agencies. Only after a NID approval is received will a FOCI contracting firm be authorized to work on the program.

13e. Security Training and Briefing: IAW AR 380-49 Chapter 3, the FSO will provide Threat Awareness and Reporting Program (TARP) training in addition to initial and refresher security training IAW AR 381-12, paragraph 1-14 and Chapter 2 for contractors working in contractor facilities. Contractors may be exempt from such security training if they can provide documentation they have had similar training from their FSO.

The FSO will forward Certificates and/or a signed Letter of Certification for Training to the COR for verification of required training to be included in the contract folder. Integrated/embedded contractors will receive security training from the assigned CECOM Security Manager/Representative. Some Security training provided to integrated/embedded contractors will include:

--TARP Training: Live training provided by 902d – Annual training requirement

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039

--Initial Security Orientation: Online training available on the Army Learning Management System (ALMS) site, reference ALARACT 207-2103 – Initial training --Annual Security Orientation: Online training available on the Army Learning Management System (ALMS) site, reference ALARACT 207-2103 – Annual training requirement Derivative Classification Training, reference DoD 5200.01-V3-Biennial training requirement --Operations Security Training, reference AR 530-1- Annual training requirement --Foreign travel training, AR 525-13 – Required when traveling abroad The previous listing includes some training requirements that are provided. Any training requirements that the installation or tenant facilities require of the contractors must be added to the DD 254 and the security section of the contract document.

13f. If contractor must submit the subcontracts DD Form 254’s to the KO for the contract file and forward to CECOM G2 for review to ensure Army requirements flow down to the sub-contractor.

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039

APPENDIX A

ADDITIONAL SECURITY GUIDELINES FOR

COMSEC

Provided by the CECOM LCMC Director of Intelligence & Security/G2 (Updated: 14 July 2008)

Contractor Generated Communications Security (COMSEC) Material: Any material generated by the contractor (including, but not limited to:

correspondence, drawings, models, mockups, photographs, schematics, status programs and special inspection reports, engineering notes, computation and training aids) will be classified according to its own content. Classification guidance will be taken from other elements of this Contract Security Classification Specification, DD Form 254, Government furnished equipment or data, or special instructions issued by the Contracting Officer, or his duly appointed representative.

REQUIREMENTS:

1. The requirements of DoD 5220.22-M and NSA/CSS Policy Manual 3-16 are applicable to this effort.

2. All contractor personnel to be granted access to classified COMSEC information must be U.S. citizens granted FINAL clearance by the government prior to being given access. Immigrant aliens, interim cleared personnel, or personnel holding a contractor granted CONFIDENTIAL clearance are n eligible for access to classified COMSEC information released or generated under this contract without the express permission of the Director, NSA.

3. Contractor employees or cleared commercial carriers shall not carry classified COMSEC material on commercial passenger aircraft anywhere in world without the approval of the procuring contracting officer.

4. No contractor generated COMSEC or government furnished material may be provided to the Defense Technical Information Center (DTIC). Contractor generated technical reports will bear the statement "Not Releasable to the Defense Technical Information Center per DoD Directive 5100 38."

5. Classified paper COMSEC material may be destroyed by burning, disintegration, chopping or high security crosscut shredding.

Cryptographic k tapes must be “terminally” destroyed (destroyed to the point where it cannot be reconstructed) utilizing devices listed on the Evaluated Products List (EPL) for Punched Tape Destruction Devices or the EPL for High-Security Disintegrators. A listing of EPLs can be found at http://www.nsa.gov/ia/government/mdg.cfm. When a method other than burning is used, all residue must be reduced to pieces 5mm or smaller in an dimension. When classified COMSEC material other than paper is to be destroyed, specific guidance must be obtained from the User Agency.

6. Unclassified COMSEC information released or generated under this contract shall be restricted in its dissemination to personnel involved in the contract. Release in open literature or exhibition of such information without the express written permission of the Director, NSA, is strictly prohibit

7. Recipients of COMSEC information under this contract may not release information to subcontractors without permission of the User Agency.

8. Additional notices to be affixed to the cover and title or first page of contractor generated COMSEC documents:

a. "COMSEC MATERIAL - ACCESS BY CONTRACTOR PERSONNEL RESTRICTED TO U.S. CITIZENS HOLDING

FINAL GOVERNMENT CLEARANCE."

b. "THIS PUBLICATION OR INFORMATION IT CONTAINS MAY NOT BE RELEASED TO FOREIGN NATIONALS WITHOUT PRIO SPECIFIC APPROVAL FROM THE DIRECTOR, NSA. ALL APPROVALS WILL IDENTIFY THE SPECIFIC INFORMATION AND COPIES THIS PUBLICATION AUTHORIZED FOR RELEASE TO SPECIFIC FOREIGN HOLDERS. ALL REQUESTS FOR

ADDITIONAL ISSUANC MUST RECEIVE PRIOR SPECIFIC APPROVAL FROM THE DIRECTOR, NSA."

9. Point of contact is:

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039

APPENDIX D

SAFEGUARDING “FOR OFFICIAL USE ONLY” (FOUO) INFORMATION

Provided by the CECOM Director of Intelligence & Security/G2

(Updated: 14 July 2008)

Reference: AR 25-55, Chapter IV

1. The “FOR OFFICIAL USE ONLY” marking is assigned to information at the time of its creation in a DOD User Agency. It is not authorized as a substitute for a security classification marking but it is used on official Government Information that may be withheld from the public under exemptions 2 through 9 of the Freedom of Information Act.

2. Other non-security markings such as “Limited Official Use” and “Official Use Only” are used by non-DOD User Agencies for the same type of information and should be safeguarded and handled in accordance with instructions received from such agencies.

3. Use of the above markings does not mean that the information cannot be released to the public, only that it must be reviewed by the Government prior to its release, to determine whether a significant and legitimate Government purpose is served by withholding the information or portions of it.

4. IDENTIFICATIONMARKINGS:

a. An unclassified document containing FOUO information shall be marked “For Official Use Only” in bold letters at least 3/16 of an inch high at the bottom of the front cover (if any), on each page containing FOUO information, and on the outside of the back cover (if any). No portion marking will be shown.

b. Within a classified document, an individual page that contains both FOUO and classified information will be marked at the top and bottom with the highest security classification appearing on the page. If an individual portion contains FOUO information but no classified information, the portion will be marked ‘FOUO.’

c. Any “FOR OFFICIAL USE ONLY” information released to a contractor by a DOD User Agency is required to be marked with the following statement prior to transfer:

THIS DOCUMENT CONTAINS INFORMATION EXEMPT FROM MANDATORY DISCLOSURE UNDER THE

FOIA. EXEMPTIONS APPLY.

d. Removal of the “FOR OFFICIAL USE ONLY” marking can only be accomplished by the originator or other competent authority. When “FOR OFFICIAL USE ONLY” status is terminated, all known holders will be notified to the extent possible.

5. DISSEMINATION: Contractors may disseminate “FOR OFFICIAL USE ONLY” information to their employees and subcontractors who have a need for the information in connection with a classified contract.

6. STORAGE: During normal working hours “FOR OFFICIAL USE ONLY” information shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During non-working hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks is adequate when internal building security is provided during non-working hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after hours protection or the material can be stored in locked receptacles such as file cabinets, desks or bookcases.

7. TRANSMISSION: “FOR OFFICIAL USE ONLY” information may be sent via first-class mail or parcel post. Bulky shipments may be sent fourth-class mail.

8. DISPOSITION: When no longer needed, FOUO information may be disposed of by tearing each copy into pieces to preclude reconstructing, and placing it in a trash container or as directed by the User Agency.

9. UNAUTHORIZED DISCLOSURE: Unauthorized disclosure of “FOR OFFICIAL USE ONLY” information does not constitute a security violation but the releasing agency should be informed of any unauthorized disclosure. The unauthorized disclosure of FOUO information protected by the Privacy Act may result in criminal sanctions.

10. Point of contact is:

Printed: 31 January 2018 Contract #TBD / Solicitation #SPRBL1-18-R-0039

APPENDIX E:

CONTROL OF COMPROMISING EMANATIONS (TEMPEST)

Provided by CECOM G2 (Updated:22 August 2012)

1. Reference:

a. DOD 5220.22-M, National Industrial Security Program Operating Manual, 28 February 2006.

b. AR 380-27, Control of Compromising Emanations (FOUO), 19 May 2010, Chapter 4, TEMPEST Countermeasures Review.

c. (C) Regulation AR 381-14, Technical Counterintelligence (TCI), 30 September 2002 (U).

2. Prior to the implementation of any TEMPEST countermeasures or expenditure of funds contractor facilities electronically processing classified information are required to submit through the KO to CECOM G2 and the contract Program Manager following information for sponsorship of a TEMPEST assessment, within 30 days of award TEMPEST assessments will be marked at a minimum of FOUO, classify according to content. The Army TEMPEST staff will review the information provided and determine if a formal TEMPEST Countermeasures Review (TCR) is required. Notification will be provided by the government security manager to the point of contact identified in the submission.

a. Facility location – include the exact address, building number, room number, and so forth. An area map showing the facility location in relation to other buildings, installation perimeter, and so forth, if available.

b. Point of Contact – include the email addresses phone numbers (commercial and cell).

c. Level of processing-include the classification level of the information that the facility will process (Secret, Top Secret, sensitive compartmented information (SCI), Special Access Program (SAP), and so forth) and frequency of processing

d. Transmitters – include information on any transmitters (cell phones, two-way pagers, radios, transceivers (including alarm systems), wireless systems, portable electronic…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.