SPRDL1-16-R-0093_Periscope_Housing_DD254.pdf

PDF 1011 KB Posted

Attached to
Periscope Hoursing Federal contract opportunity
Solicitation number
SPRDL116R0093
Issued by
Department of the Army Materiel Command TACOM Life Cycle Management Command

About this file

DOD Contract Security Classification Specification (DD Form 254)

View the file

Other files for this federal contract opportunity

Other files attached to Periscope Hoursing, newest first.
File Type Posted
SPRDL116R0093-0007.pdf PDF
SPRDL116R0093-0006.pdf PDF
SBCT_OPSEC_with_PEO_Plan_2013.pdf PDF
SPRDL116R0093-0005.pdf PDF
SPRDL116R0093-0004.pdf PDF
SPRDL116R0093-0003.pdf PDF
SPRDL116R0093-0002.pdf PDF
SPRDL116R0093-0001.pdf PDF
SPRDL116R0093.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SPRDL1-16-R-0093 FOR PLANNING PURPOSES ONLY Page 1 of 3

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the DoD National Industrial Security Program

Operating Manual apply to all security aspects of this effort.)

1. CLEARANCE AND SAFEGUARDING

a. FACILITY CLEARANCE REQUIRED

Secret

b. LEVEL OF SAFEGUARDING REQUIRED

Secret

2. THIS SPECIFICATION IS FOR: (X and complete as applicable) 3. THIS SPECIFICATION IS: (X and complete as applicable)

a. PRIME CONTRACT NUMBER

X a. ORIGINAL (Complete date in all cases)

DATE (YYYYMMDD)

20160713

b. SUBCONTRACT NUMBER

b. REVISED (Supersedes all previous specs)

Revision No.

X

c. SOLICITATION OR OTHER NUMBER

SPRDL1-16-R-0093

DUE DATE (YYYYMMDD)

20160815 c. FINAL (Complete item 5 in all cases)

4. IS THIS A FOLLOW-ON CONTRACT? ______ YES ___X___ NO. If yes, complete the following:

Classified material received or generated under Preceding Contract Number) is transferred to this follow-on contract.

5. IS THIS A FINAL DD 254? ______ YES ___X___ NO. If yes, complete the following:

In response to the contractor’s request dated , retention of the identified classified material is authorized for the period of

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE

TBD

b. CAGE CODE

TBD

c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

TBD

7. SUBCONTRACTOR

a. NAME, ADDRESS, AND ZIP CODE

b. CAGE CODE

c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

8. ACTUAL PERFORMANCE

a. NAME, ADDRESS, AND ZIP CODE

TBD

b. CAGE CODE

TBD

c. COGNIZANT SECURITY OFFICE (Name, Address, and Zip Code)

TBD

9. GENERAL IDENTIFICATION OF THIS PROCUREMENT

Produce Periscope Housing

10. THIS CONTRACT WILL REQUIRE ACCESS TO: YES NO 11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: YES NO

a. COMMUNICATION SECURITY (COMSEC) INFORMATION X a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT ANOTHER CONTRACTOR’S FACILITY

OR A GOVERNMENT ACTIVITY X

b. RESTRICTED DATA X b. RECEIVE CLASSIFIED DOCUMENTS ONLY X

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION X c. RECEIVE AND GENERATE CLASSIFIED MATERIAL X

d. FORMERLY RESTRICTED DATA X d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE X

e. INTELLIGENCE INFORMATION: e. PERFORM SERVICES ONLY X

(1) Sensitive Compartmented Information (SCI) X f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE THE U.S., PUERTO RICO, U.S.

POSSESSIONS AND TRUST TERRITORIES X

(2) Non-SCI X g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE TECHNICAL INFORMATION CENTER

(DTIC) OR OTHER SECONDARY DISTRIBUTION CENTER X

f. SPECIAL ACCESS INFORMATION X h. REQUIRE A COMSEC ACCOUNT X

g. NATO INFORMATION X i. HAVE TEMPEST REQUIREMENTS X

h. FOREIGN GOVERNMENT INFORMATION X j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS X

i. LIMITED DISSEMINATION INFORMATION X k. BE AUTHORIZED TO USE THE DEFENSE COURIER SERVICE X

j. FOR OFFICIAL USE ONLY INFORMATION X

l. OTHER (Specify) Follow and implement (See Block 13)

(1) Threat Awareness and Reporting Requirements

X k. OTHER (Specify)

(1) Controlled Unclassified Information

(2) Security Classification Guidance

X

DD Form 254, DEC 99 Previous editions are obsolete.

initiator:Nancy.a.chaplin.civ@mail.mil;wfState:distributed;wfType:email;workflowId:c6835a39c2b2a844853e87c9757cf8ec

SPRDL1-16-R-0093 FOR PLANNING PURPOSES ONLY Page 2 of 3

12. PUBLIC RELEASE. Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual or unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for approval prior to release

Direct Through (specify):

The PCO to the PM SBCT, ATTN: SFAE-GCS-S, M/S 325 (Security Manager), 6501 E. 11 Mile Road, Warren, MI 48397, who will obtain public release approval through the prescribed channels to include the PCO and PAO.

to the Directorate for Freedom of Information and Security Review, Office of the Assistant Secretary of Defense (Public Affairs)* for review.

*In the case of non-DoD User Agencies, requests for disclosure shall be submitted to that agency

13. SECURITY GUIDANCE. The security classification guidance needed for this classified effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract; and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classified assigned or recommended. (Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. Add additional pages as needed to provide complete guidance.)

Estimated Completion Date: 31 May 2018

Collateral classified information provided in support of this contract shall be protected in accordance with the National Industrial Security Program Operating Manual (NISPOM) DoD 5220.22-M, and this DD Form 254. Unclassified information shall be protected IAW the OPSEC Plan, and Attachment A.

All classified material shall be transmitted IAW the NISPOM (Registered US Mail, cleared commercial carrier (Monday thru Thursday), Same Day Delivery, or secure fax).

Access to technical data by foreign interests is prohibited unless authorized by a valid export authorization.

The following attachments are made part of this DD Form 254:

Attachment A – Guidelines for the Controlled Unclassified Information (Item 10.k., includes Item 10.j (1))

CUI and OPSEC requirements shall be flowed down to all U.S. subcontractors (including unclassified U.S. subcontractors) as an integral part of their respective contracts.

See Continuation of Block 13

“The COR has reviewed this Security Specification and certifies the requirements are complete and adequate for performance of the contract. The COR understands the provisions and will ensure that it is complied with within the limits of his/her responsibility, and that any violations are brought to the attention of the KO and supporting Security Manager."

Eduardo Larosa Government Technical Lead

14. ADDITIONAL SECURITY REQUIREMENTS. Requirements, in addition to NISPOM requirements, are established for this contract. (if, Yes, identify the pertinent contractual clauses in the YES NO contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the cognizant security office.

Use Item 13 if additional space is needed.)

Also see Block 13 for additional requirements.

15. INSPECTIONS. Elements of this contract are outside the inspection responsibility of the cognizant security office. (If Yes, explain and identify specific areas or elements carved out YES NO and the activity responsible for inspections. Use item13 if additional space is needed.)

16. CERTIFICATION AND SIGNATURE. Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this contract effort. All questions shall be referred to the official named below.

a. TYPED NAME OF CERTIFYING OFFICIAL

Nancy Chaplin

b. TITLE

Activity Security Manager

c. TELEPHONE (Include Area Code)

586-282-9648

d. ADDRESS (Include Zip Code)

PEO GCS

ATTN: SFAE-GCS-CIO/MS 505

6501 East 11 Mile Road Warren, MI 48397-5000

17. REQUIRED DISTRIBUTION

a. CONTRACTOR

b. SUBCONTRACTOR

c. COGNIZANT SECURITY OFFICE FOR PRIME AND SUBCONTRACTOR

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY ADMINISTRATION

e. ADMINSTRATIVE CONTRACTING OFFICER

f. OTHERS AS NECESSARY

e. SIGNATURE

DD Form 254 Reverse, DEC 99

CONTINUATION OF BLOCK 13 OF THE DD FORM 254

SPRDL1-16-R-0093 FOR PLANNING PURPOSES ONLY Page 3 of 3

Item 10.j – FOR OFFICIAL USE ONLY (FOUO): FOUO Information generated and/or provided under this contract shall be safeguarded and marked as specified in additional Guidelines for Controlled Unclassified Information (CUI) (Attachment A).

Item 10.k.(1) – CONTROLLED UNCLASSIFIED INFORMATION (CUI) generated and/or provided under this contract shall be safeguarded and marked as specified in additional Guidelines for Controlled Unclassified Information (CUI) (Attachment A).

Item 10.k.(2) – SECURITY CLASSIFICATION GUIDANCE: Security Classification Guide for Laser Protection Material, Dated 18 Sep 2013. All hardware is unclassified under this contract. Test and evaluation data must be classified per the original classification authority and the Security Classification Guide.

Item 11.c – RECEIVE AND GENERATE CLASSIFIED INFORMATION: The contractor requires access to classified source data up to and including Secret in support of the work effort. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents. Use of “Multiple Sources” on the “Derived From” line necessitates compliance with the NISPOM, paragraph 4-208a, and the use of a bibliography.

Item 11.i – HAVE TEMPEST REQUIREMENTS: Prior to the implementation of any TEMPEST countermeasures or expenditure of funds, a TEMPEST assessment will be conducted at all contractor facilities electronically processing classified information. TEMPEST assessments will be marked at a minimum of FOUO or classify according to content. The Army TEMPEST staff will review the information provided and determine if a formal TEMPEST Countermeasures Review (TCR) is required. Notification will be provided by the Government Security Manager to the point of contact identified in the submission. This requirement shall be flowed down to all U.S. subcontractors that use Information Systems to process classified material. Refer to scope of work and the CDRL that addresses the submission of this requirement.

Item 11.j – OPERATIONS SECURITY (OPSEC) REQUIREMENTS: The contractor shall follow the Stryker OPSEC Plan, as well as annexes and updates. The contractor is not required to develop their own OPSEC Plan. All U.S. contractors shall provide annual program specific Stryker OPSEC training for all program personnel. The contractor shall provide Stryker OPSEC Plan specific training to all new contractor personnel within 30 days of program assignment. Annually, contractors shall complete OPSEC training and submit a report, validating 100% completion to the Government Security Office by 30 September.

Refer to scope of work and the CDRL that address the submission of this requirement. These requirements, OPSEC Plan and training, shall be flowed down to all U.S. subcontractors with access to CUI and/or classified material.

Item 11.l.(1) – THREAT AWARENESS AND REPORTING REQUIREMENTS: ICW NISPOM 1-301, the contractor shall report threat-related incidents, behavioral indicators, and other matters of counterintelligence (CI) interest specified in AR 381-12, Chapter 3, through the facility security officer to the government security officer, the nearest military CI office, the Federal Bureau of Investigation, and the Defense Security Service. Annually, train personnel who handle classified information IAW AR 381-12, Chapter 2. This requirement shall be flowed down to all U.S. subcontractors that have access to classified information/material.

Item 12 – PUBLIC RELEASE: An electronic copy of the request with full text and graphics must be provided through the Government Contracting Officer at least forty-five (45) working days prior to the requested release date. If all or part of the information was generated by another organization, their written release authorization must accompany the request.

Notification of loss or compromise of collateral classified information shall be provided to the Government Program Security Office within 72 hours of the incident, in addition to the reporting requirements outlined in the NISPOM.

Solicitation/Contract Number:

Revised: Mar 1, 2016 Page A1 of 2

ATTACHMENT A

ADDITIONAL GUIDELINES FOR CONTROLLED UNCLASSIFIED INFORMATION

General: There are types of information that are not classified but that require application of access and distribution controls and protective measures for a variety of reasons. This information is known as “controlled unclassified information (CUI).” The types of information considered CUI for the program are information marked “For Official Use Only” by the U.S. Government and technical data. When handling CUI material, all personnel are to comply with these requirements and follow their company policy and/or applicable Proprietary Information Agreements (PIA) concerning the protection of proprietary information in situations not clearly stated herein.

Technical Data Description: Any recorded information related to experimental, developmental, or engineering works that can be used to define an engineering or manufacturing process, or can be used to design, procure, produce, support, maintain, operate, repair, or overhaul program material. The data may be graphic or pictorial delineations in media (e.g., computer software, drawings, or photographs), text in specifications, related performance or design documents, or computer printouts. Examples of technical data include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, catalog-item identifications, and related information, and computer software documentation.

For Official Use Only (FOUO) Information Description: “For Official Use Only (FOUO)” is a Government designation applied to unclassified information that may be exempt from mandatory release to the public under the Freedom of Information Act (FOIA). FOUO information includes information identified as such in the Security Classification Guide or information from a government document marked FOUO.

CUI Markings

Marking of FOUO documents will be in accordance with Army Regulation (AR) 25-55. Information extracted from an FOUO document will carry the FOUO marking until formally reviewed by the government.

AR 25-55 can be found at http://www.apd.army.mil/pdffiles/r25_55.pdf.

Marking of Technical Data will include the statement provided in the Security Classification Guide. If the contents of the technical document require more than one Distribution Statement, apply the most restrictive statement. This does not preclude additional mandated markings as may be required by the contract.

Protection of CUI Information

Access: CUI may be released only to an individual who has a valid need for such access in connection with the accomplishment of a lawful and authorized Government purpose. Information in any media format may only be disseminated on a need-to-know basis. The need-to-know restricts the use or dissemination of CUI data to those individuals or organizations with direct affiliation with the given program or project. Further dissemination of such information will be at the discretion of the Government Security Manager. Personnel no longer requiring access to CUI must dispose (see “Disposal” below) or surrender any in their possession and terminate future access to it.

Storing/Handling: During working hours, take reasonable steps to minimize risk of access to CUI by unauthorized personnel. After working hours, when not in physical possession of the owner, all CUI (whether hardcopy or optical media (e.g., DVDs, CDs) that contain CUI) must be afforded a reasonable degree of physical protection to prevent theft of program information (e.g., store CUI information in locked desks or file cabinets, locked rooms, cable lock laptops, storing in a trunk, storing out of site or similar means). Do not display CUI in public places (e.g., airports, airplanes, restaurants). Electronic storing and processing of CUI shall be in accordance with DFARS 252.204-7012 Safeguarding Controlled Defense Information and Cyber Incident Reporting. Do not process CUI on public computers (e.g., those available for use by the general public in kiosks, hotel business centers), public wireless networks or computers that do not have access control. Personally owned computers and personally owned devices are not authorized to process CUI. Portable electronic devices (e.g., smartphones, laptop computers, tablets), non-portable computers, and removable media (e.g., external hard drives, flash drives, USB drives; not including optical media) must be physically and electronically protected as described in this instruction and the DFARS 252.204- 7012.

Dissemination: CUI printed documents and material may be transmitted through mail channels, commercial carrier or hand-carried without formal courier orders. FOUO information may be disseminated to DoD personnel and DoD contractors to conduct official business for the program. If dissemination is required outside of DoD personnel or DoD contractors, contact the Government Security Manager for approval. Technical data will follow the release instructions identified in the Distribution Statement. Use secure communications whenever possible; however, land-line telephones are more secure than cellular telephones and should be used whenever available for discussions

Solicitation/Contract Number:

Revised: Mar 1, 2016 Page A2 of 2 involving CUI. Transmit voice and facsimile transmissions only when you have a reasonable assurance that only authorized recipients will have access to the transmission. Digital transmission shall comply with the below:

• All transmission and/or dissemination of CUI (i.e., email and file transfers) must use NIST/NIAP-approved cryptographic products/algorithms, e.g., DoD-approved Public Key Infrastructure Certification or AMRDEC Safe Exchange at https://safe.amrdec.army.mil/safe. These are available at http://iase.disa.mil/pki/eca or http://csrc.nist.gov/cryptval/. This encryption requirement includes communications that contain passcodes to teleconferences or web conferences where there is a reasonable expectation that CUI may be discussed. When encryption is not available, a government collaborative suite (aka Integrated Digital Environment [IDE]) must be used to transmit CUI.

• Contractor-hosted collaborative suites may be used for digital transmission and/or dissemination of CUI by personnel not located on a government backbone (e.g., NIPRNET), provided the following conditions apply:

� Use only NIST/NIAP-approved cryptographic products/algorithms. The latest validation lists may be obtained at http://iase.disa.mil/pki/eca or http://csrc.nist.gov/cryptval/.

� Use an internally hosted service that does not use a third-party collaborative suite service provider.

• Do not post CUI to web pages that are publicly available or have access limited only by domain/IP restrictions.

As permitted by other contract provisions, CUI may be posted to web pages that control access through the use of a DoD approved Public Key Infrastructure Certification and that provide protection via use of secure sockets, or other equivalent technologies. These are available at http://iase.disa.mil/pki/eca.

• As new technologies become available in the electronics arena, care should be given to providing a reasonable degree of protection from known vulnerabilities.

• The Internet is “Public Access”. CUI must be reviewed and officially approved by the PEO GCS Public Affairs Officer for public release before placing on the Internet. This is not applicable when the Internet is used for e-mail transmissions and encryption is used as noted above.

Disposal: Destroy CUI documents by any means approved for the destruction of classified information, i.e. cross-cut shredding or other means that would make it difficult to recognize or reconstruct the information. Clear, purge, or destroy CUI on removable media IAW BBP 03-PE-O-0003 Army Information Assurance Sanitization of Media to AR 25-2. This is available at https://informationassurance.us.army.mil.

Report of Loss of CUI: Report any loss of CUI to the Government Security Manager. Initial reports shall be made as expeditiously as possible in all cases within 72 hours of discovery. If additional information is required after submission and review of the initial report, guidance will be provided at that time. Mark any reports For Official Use Only, exemptions 2 and 5 apply. Initial report content shall include the following information as available.

• Applicable dates, including dates of compromise and dates of discovery

• Threat methodology, including all known resources used (e.g. IP addresses, domain names, software tools)

• Account of what actions the threat(s) may have taken on victim system/network

• What information may have been compromised or lost, and its potential impact on government programs

CONTRACT SECURITY CLASSIFICATION SPECIFICATION
Item 11.j – OPERATIONS SECURITY (OPSEC) REQUIREMENTS: The contractor shall follow the Stryker OPSEC Plan, as well as annexes and updates. The contractor is not required to develop their own OPSEC Plan. All U.S. contractors shall provide annual prog...
Text1: SPRDL1-16-R-0093
2016-07-18T09:20:41-0400
LAROSA.EDUARDO.1228868910
2016-07-18T13:09:45-0400
CHAPLIN.NANCY.A.1230490259

SubmitButton1:

File details come from the government source that posted it. Updated .