Attachment_003_DD254_ADDENDUM.pdf
PDF 212 KB Posted
- Attached to
- Business Operation Support Services (BOSS) Federal contract opportunity
- Solicitation number
- W15QKN16R0050
About this file
Attachment 0003 (Part 2) - DD 254 Addendum
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| OPMG_Boss_Question_2.docx | DOCX document | |
| W15QKN16R0050_Amendment_0001.pdf | ||
| OPMG_BOSS_Questions.docx | DOCX document | |
| Attachment_001_PWS.docx | DOCX document | |
| Attachment_0003_DD254.pdf | ||
| Attachment_0002_QASP.docx | DOCX document | |
| W15QKN16R0050.pdf | ||
| Attachment_0004_-_Labor_Category_Matrix.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
OFFICE OF THE PROVOST MARSHAL GENERAL
DD254 ADDENDUM
Contract Number: W15QKN-16-R-0050 Solicitation:
Awarded to: TBD As of: 9 June 2016
Period of Performance on this contract is:
The Period of Performance reads as follows:
Base Period: DOA plus 8 months Option Period1: DOA plus 12 months Option Period2: DOA plus 12 months
Contracting Officer Representative (COR):
The undersigned has reviewed this Security Specification, understands the provisions and will ensure that it is complied with within the limits of his/her responsibility, and that any violations are brought to the attention of the Contracting Officer (KO) and the supporting Security Manager (see Block 16).
Date COR Name: Amanda Davis Office Symbol: DAPM-RMD Address: 251 18th Street, Arlington, VA 22022, Rm 244A Phone: (703) 571-0380 Email: amanda.d.davis.civ@mail.mil
ONLY THE CHECKED PROVISIONS ARE APPLICABLE TO THIS CONTRACT.
Reference Item 1a. Specified positions designated by the Contracting Officer’s Representative (COR) or Contract Monitor (CM) will require the following clearances:
TS/SCI: All (on-site/off-site) contractor personnel MUST possess a final Top Secret (TS) Clearance based on a Single Scope Background Investigation (SSBI), SBPR, or PPR completed within the last 5 years (in-scope) with Sensitive Compartmented Information (SCI) eligibility prior to reporting to any assignment within OPMG in order to meet contractual security requirements.
The clearance must be fully adjudicated at the SCI level and will have an indication of “determined eligibility of DCID 6/4” in JPAS. Personnel security clearances (PCLs) must be verifiable in the Joint Personnel Adjudication System (JPAS). Foreign National are prohibited from working on classified and unclassified portions of this contract.
TS: All (on-site/off-site) contractor personnel MUST possess a final Top Secret (TS) Clearance based on a Single Scope Background Investigation (SSBI) SBPR, or PPR prior to reporting to any assignment within OPMG in order to meet contractual security requirements completed within the last 5 years (in-scope). The clearance must be fully adjudicated at the Top Secret level and will have an indication of “determined eligibility of Top Secret” in JPAS. Personnel security clearances (PCLs) must be verifiable in the Joint Personnel Adjudication System (JPAS). Foreign National are prohibited from working on classified and unclassified portions of this contract.
Office of the Povost Marshal General DD254 Addendum
W15QKN-16-R-0050
X Secret: All off-site contractor personnel MUST possess a final Secret (S) Clearance based on a National Agency Check (NACLAC) completed within the last 10 years (in-scope). The clearance must be fully adjudicated at the Secret level and will have an indication of “determined eligibility of Secret” in JPAS. Personnel security clearances (PCLs) must be verifiable in the Joint Personnel Adjudication System (JPAS). Foreign National are prohibited from working on classified and unclassified portions of this contract.
Unclassified: All off-site contractor personnel do not require a clearance due to the work associated with this Task Order being Unclassified. All uncleared personnel shall be escorted at all times to and from meetings held at the Pentagon and other controlled facilities. Foreign National are prohibited from working on classified and unclassified portions of this contract.
ONSITE: All contractor personnel working onsite performing work under this contract shall possess at minimum a SECRET clearance, prior to reporting to any assignment within the Defense Forensics and Biometrics Agency in order to meet contractual security requirements. Foreign Nationals will not perform on any area of the contract (classified or unclassified).
Reference Item 7 (Subcontractor). Before a Prime Contractor can use a subcontractor or a consultant that requires access to classified information on this contract, approval must be obtained from the Contracting Officer (KO) or Contracting Officer Representative (COR). A subcontractor letter must be submitted to the OPMG Security Office from the COR before the DD254 can be modified. After selection of a subcontractor or a consultant requiring access to classified information in performance of this contract, the Prime Contractor will prepare and submit a DD Form 254 through the KO/COR to the OPMG Security Office.
(Reference: DoD 5200.22M, Chapter 7) x
Reference Item 8 (Actual Performance). Performance of this contract will be at the contractor’s facility and one or more of the following U.S. Government sites/spaces:
Office of the Provost Marshal General/Defense Forensics And Biometrics Agency 251 South 18th Street, Suite 244A, Arlington, VA 22202
Biometrics Identity Management Activity 347 West Main Street, Clarksburg, WV 26301
Reference Item 10a, 11h (COMSEC).
a. The contractor may require and is authorized to have/receive accountable Government furnished COMSEC information and equipment.
b. Access to COMSEC information requires special briefings at the contractor’s facility. Access to COMSEC material/information is restricted to U.S. citizens holding a final U.S. Government clearance at the appropriate level. Such information is not releasable to personnel holding only reciprocal clearances. Further disclosure of COMSEC information by a contractor, to include subcontracting, requires prior approval of the KO/COR. If the contractor does not have access to COMSEC information and/or equipment and it is required, contact the DSS/OL CSO for that area;
and they will brief the contractor in COMSEC safeguarding requirements.
c. The NSA Central Office or Record has primary responsibility for the auditing of all COMSEC material governed by NSA policy. Refer to National Security Agency/Central Security Service (NSA/CSS) Policy Manual 3-16, Control of Communications Security Material, (Aug 2005) page E-4 for guidance in control and protection of COMSEC material/information. The cognizant DSS/OL security office is responsible for inspecting for compliance with the NISPOM. COMSEC material/information may not be released to DoD contractors without NSA approval.
d. The COMSEC equipment will need to be authorized up to _____________ (Indicated in Block 1b) level. COMSEC Support will be provided (internally/by the government agency). COMSEC Account # ________________ . Only if support is provided by government agency:
Contractor must forward request for COMSEC material/information to the COMSEC custodian [through the OPMG Security Office]. Non-accountable COMSEC information, though not tracked in the COMSEC material control system, may still require a level or control within a document control system. Work with COMSEC equipment and material will be by direction of the government agent.
(DoD 5220.22M, Chapter 9)
Reference Item 10b and 10d (Restricted Data and Formerly Restricted Data).
a. Access
(1) Contractor will require access to Restricted Data (RD) and Formerly Restricted Data (FRD). The minimal investigation requirements for access to RD and FRD requires a final Favorable Single Scope Background Investigation (SSBI) for Top Secret/RD, Top Secret/Secret/FRD, Secret/RD and a Favorable National Agency Check with Local Agency Checks and Credit Check (NACLC) for access to Secret/FRD, Confidential/RD, or Confidential/FRD. Contractor personnel must be briefed for CNWDI prior to access.
(2) Requests for access to RD and FRD will be submitted by the contractor to the servicing security office, through the Contracting Officer’s Representative (COR), for approval.
Contractor will be briefed and have the Department of Energy Form 5631.20, U.S. Department of Energy Request for Visit or Access Approval, performed at OPMG spaces or off-site OPMG sites approved for briefing RD Programs.
b. Implementation Guidance. Implementing procedures for the RD and FRD programs are contained in DoD Directive 5210.2, Access to Dissemination of Restricted Data, DoD 5200.1-R, Information Security Regulation, and DoD 5220.22M, National Industrial Security Program Operating Manual (NISPOM). These publications will be used for dissemination, access, marking, management of information, and briefings.
c. Waivers. Requests for waivers to any requirements in the above publications or other requirements involving Restricted Data will be address through the OPMG Security Office for coordination and approval. Requests shall contain sufficient information to permit a complete and thorough analysis of the impact on the RD and FRD programs.
Reference Item 10c (Critical Nuclear Weapons Design Information).
a. Access. Due to the sensitivity of Critical Nuclear Weapons Design Information (CNWDI), access shall be granted to the absolute minimum number of personnel who required access for the accomplishment of assigned responsibilities on a contract (classified or unclassified). The Contracting Officer’s Representative will ensure access is granted to the minimum number of employees required on the strictest need-to-know basis. Due to the importance of such information, special requirements have been established for the control and access.
(1) Contractor will require access to Critical Nuclear Weapons Design Information (CNWDI). The minimal investigation requirements for access to CNWDI requires a final Favorable Single Scope Background Investigation (SSBI) for Top Secret/Restricted Data (CNWDI), Secret/ Restricted Data (CNWDI) and a Favorable National Agency Check with Local Agency Checks and Credit Check (NACLC) for access to Confidential/Restricted Data (CNWDI). Contractor personnel must be briefed for CNWDI prior to access.
(2) Requests for access to CNWDI will be submitted by the contractor to the servicing security office, through the Contracting Officer’s Representative (COR), for approval. Contractor will be briefed and have the Department of Energy Form 5631.20, U.S. Department of Energy Request for Visit or Access Approval, performed at OPMG spaces or off-site OPMG sites approved for briefing RD Programs. If the subcontractor does not have access to CNWDI, contact the Cognizant Security Agency (CSA). The CSA will brief the subcontractor in safeguarding requirements for CNWDI. User Agency approval is required prior to granting CNWDI access on a subcontract.
b. Implementation Guidance. Implementing procedures for the CNWDI programs are contained in DoD Directive 5210.2, Access to Dissemination of Restricted Data, DoD 5200.1-R, Information Security Regulation, and DoD 5220.22M, National Industrial Security Program Operating Manual (NISPOM). These publications will be used for dissemination, access, marking, management of information, and briefings. All CNWDI will be accounted for and disposed of in accordance with the NISPOM. (NISPOM Chapter 9, Section 2, Paragraph 9-20)
c. Waivers. Requests for waivers to any requirements in the above publications or other requirements involving Restricted Data will be address through the OPMG Security Office for coordination and approval. Requests shall contain sufficient information to permit a complete and thorough analysis of the impact on the RD and FRD programs.
Reference Item 10e(1) (Intelligence Information) (1) SCI & (2) Non-SCI.
a. The OPMG is required to abide by several security directives. The following definitions are from these directives.
1. Intelligence Community: U.S. Government agencies and organizations identified in Section 3 of the National Security Act of 1947, as amended. DIA is a designated member of the intelligence community.
2. Intelligence Information: Intelligence information and related material include the following information, whether written or in any other medium, classified pursuant to E.O.
13526 or any predecessor or successor Executive Order:
(a) Foreign intelligence and counter intelligence defined in the National Security Act of 1947, as amended, and in Executive Order 12333.
(b) Information describing U.S. foreign intelligence and counterintelligence activities, sources methods, equipment, or methodology used for the acquisition, processing or exploitation of such intelligence; foreign military hardware obtained through intelligence activities for exploitation and the results of the exploitation;
and any other data resulting from U.S. intelligence collection efforts; and
(c) Information on intelligence community protective security programs, e.g.
personnel, physical, technical, and information security.
b. Strict adherence to the need-to-know principle for intelligence information applies. Access to intelligence information requires a FINAL U.S. Government clearance at the appropriate level. SCI access by contractor personnel must be approved in writing by the KO/COR via justification letter.
The COR will ensure access is granted to the minimum number of employees required on the strictest need-to-know basis.
c. Violations of the foregoing restrictions that result in unauthorized disclosure of intelligence information shall be immediately reported to the OPMG Security Office.
d. DIA has security responsibility for SCI released to the contractor or developed under this contract, with one exception. Public release of SCI information is not authorized.
e. Contractor generated or Government furnished material may not be provided to the Defense Technical Information Center (DTIC). Contractor generated technical reports will bear the statement ‘Not Releasable to the Defense Technical Information Center per DoD Instruction 5230.24.’
f. All contract personnel requiring access to SCI information must:
(1) Be U.S. citizen,
(2) Have been granted a final TOP SECRET security clearance by the U.S. Government,
(3) Have been approved as meeting ICD 704 criteria by a Government Cognizant Security Agency
(4) Have been indoctrinated for the applicable compartments of SCI access PRIOR to being given an access to such information released or generated under this contract.
(5) Immigrant aliens, foreign nationals, or personnel cleared on an interim basis are not eligible for access to classified information released or generated under this contract.
g. Prior to being granted access to Top Secret (TS), Special Access Program (SAP), or Sensitive Compartmented Information (SCI), all DoD Contractor employees must orally attest that they will conform to the conditions and responsibilities imposed by law or regulation on those granted access. They shall attest to understanding fully their responsibilities to protect national security information and to adhere to the provisions stated on Standard Form 312, “Classified Information Nondisclosure Agreement” and/or the “SCI/SAP Indoctrination Form”, after reading the entire Nondisclosure Agreement.
h. SCI information/material received by the contractor under this contract may not be released to subcontractors without permission of the KO/COR.
i. Upon expiration of this contract, the contractor shall request disposition instructions for all project material, both classified and unclassified. The contractor may be directed to destroy or return the material. If project material is to be retained by the contractor, every effort should be taken to transfer it to a follow-on contract or similar effort, if applicable. Unless in receipt of written authorization by the KO/COR to retain specific material for a specific period of time, the material shall be returned or destroyed as instructed. Any exception to security policy shall be referred to the OPMG Security Office for coordination with the appropriate agencies and the contracting officer.
j. All contractor SCI work and access will be at an appropriate Department of Defense (DoD) accredited SCI Facility (SCIF) or a SCIF accredited by another U.S. Government Agency and properly covered by a Co-Utilization Agreement (CUA). Prior to processing (receiving, creating, discussing, or storing) SCI information in a non-DIA accredited SCIF, the contractor will ensure a Co-Utilization Agreement has been established.
k. The COR will furnish complete classification guidance for the service to be performed.
l. SCI furnished in support of this contract remains the property of the DoD department, agency, or command that releases it. Upon completion or cancellation of the contract, all SCI furnished will be returned to the direct custody if the responsible security officer designated above. See DoD 5105.21-M-1 for complete guidance of handling SCI.
m. The contractor and COR will revalidate all SCI requirements under this contract with the OPMG Security Office annually or when a revised DD Form 254 issued, whichever is sooner.
n. All SCI visit requests by contractors shall be forwarded to the COR for approval and need-to-know certification before being sent through the SSO to the facility to be visited.
Use paragraph below if SCI will only be accessed at non-government location(s).
o. STU-III or STE terminals installed at the contractor's facilities shall be supported by a COMSEC account. STU-IIIs in SCI Facilities (SCIFs) require Class VI Cryptographic Ignition Key (CIK).
(DoD 5105.21-M-1, Chapter 3 & Chapter 5)
X Reference Item 10e(2) (Non SCI Intelligence).
a. The OPMG is required to abide by several security directives, one of which is Director of Central Intelligence Directive 6/6 (DCID 6/6), Security Controls on the Dissemination of Intelligence Information. The following are definitions from that directive.
1. Intelligence Community: U.S. Government agencies and organizations identified in Section 3 of the National Security Act of 1947, as amended. DIA is a designated member of the intelligence community.
2. Intelligence Information: Intelligence information and related material include the following information, whether written or in any other medium, classified pursuant to E.O.
13526 or any predecessor or successor Executive Order:
(a) Foreign intelligence and counter intelligence defined in the National Security Act of 1947, as amended, and in Executive Order 12333.
(b) Information describing U.S. foreign intelligence and counterintelligence activities, sources methods, equipment, or methodology used for the acquisition, processing or exploitation of such intelligence; foreign military hardware obtained through intelligence activities for exploitation and the results of the exploitation;
and any other data resulting from U.S. intelligence collection efforts; and
(c) Information on intelligence community protective security programs, e.g.
personnel, physical, technical, and information security.
b. Strict adherence to the need-to-know principle for intelligence information applies. Access to intelligence information requires a FINAL U.S. Government clearance at the appropriate level. SCI access by contractor personnel must be approved in writing by the KO/COR via justification letter.
The COR will ensure access is granted to the minimum number of employees required on the strictest need-to-know basis.
c. Violations of the foregoing restrictions that result in unauthorized disclosure of intelligence information shall be immediately reported to the OPMG Security Office.
e. Contractor generated or Government furnished material may not be provided to the Defense Technical Information Center (DTIC). Contractor generated technical reports will bear the statement ‘Not Releasable to the Defense Technical Information Center per DoD Instruction 5230.24.’
e. Classified material received or generated under this contract is not releasable to foreign nationals. Public release of classified information is not authorized.
k. The COR will furnish complete classification guidance for the service to be performed.
(DoD 5220.22M, Chapter 5)
Reference Item 10f (SAP).
a. To execute this contract, additional security requirements in addition to DoD 5220.22-M will be required. The contractor shall comply with the security provisions of these programs. Marking and/or classification guidance for material originated or generated under this contract will be provided through the Special Access Program, Program Manager, under separate cover. Any material generated by the contractor (including correspondence, drawings, models, mockups, photographs, schematics, progress, special and inspection reports, engineering notes, computations and training aids) shall be classified according to content.
b. This contract will be performed in a facility approved through the SAP Cognizant Security Authority (CSA) in accordance with applicable SAP security requirements.
c. All personnel requiring access to SAP information:
(1) Must be U.S. citizen,
(2) Have been granted a final TOP SECRET U.S. Government security clearance,
(3) Have been approved as meeting ICD 704 criteria by a Government cognizant authority, and
(4) Have been indoctrinated for the applicable SAP prior to being given access to any information generated or received under this contract.
(5) Immigrant aliens, foreign nationals, or personnel cleared on an interim basis are not eligible for access to classified information released or generated under this contract.
(6) Contractor generated or Government furnished property may not be provided to the Defense Technical Information Center (DTIC).
d. The Contractor Special Security Officers shall coordinate with the OPMG Security Office prior to subcontracting any portion of this contract.
IAW DoD 5220.22-M-SUP-1
a. Contractor employees associated with this contract shall sign appropriate Government non-disclosure statements prior to beginning work.
b. All SAP classified material pursuant to this contract shall be protected in accordance with the NISPOM, NISPOM supplement, DoD Overprint to the NISPOM Supplement, DOD 5200.1-R, CJCSI 5250.01 Series, and the appropriate SAP Program Security Plan (PSP) and Security Classification Guide (SCG).
c. Any material generated by the contractor (including correspondence, drawings, models, mockups, photographs, schematics, progress, special and inspection reports, engineering notes, computations and training aids) shall be classified according to content. Contractor generated or Government furnished material may not be provided to the Defense Technical Information Center.
Contractor generated reports will bear the statement: “Not Releasable to the Defense Technical Information Center” per DoD Instruction 5230.24.
d. Guidance for classification shall be derived from the applicable Security Classification Guides, documents, or special instructions. Such material shall not contain contractor logos or similar identifiers which identify the specific contractor or team members. Marking and/or classification guidance for material originated or generated under this contract will be provided through the OPMG Security Office under separate cover.
e. All SAP material remains the property of the releasing Government Cognizant Agency. Upon completion or cancellation of this contract, SAP material previously furnished will be returned to the direct custody of the OPMG Security Office or other SAPCO as determined by the Director, OPMG.
f. All work with SAP material/computer systems will normally be conducted in government SAP Facilities approved by the Director, OPMG. Any SAP activities conducted at other facilities will require specific, case-by-case approval of Director, OPMG. Access to government furnished computer systems requires compliance with all applicable DoD and Army directives and completion of annual Information Assurance training.
g. All SAP access requests in support of this contract will be made through the OPMG Security Office. Personnel will meet access eligibility requirements specified in CJCSI 5250.01 Series. No access will be granted for SAP information until completion of applicable PAR and PIA in accordance with DoDD 5205.07 and DoDI 5205.11. Personnel desiring access to SAP information must also consent to random Counter-intelligence polygraphs.
h. Upon expiration of this contract, the contractor is required to have a close-out inspection by the OPMG Security Office to ensure proper disposition of SAP material and equipment. The contractor may be directed to properly destroy the material or return it. No SAP project material is to be retained by the contractor – if applicable; every effort should be taken to transfer it to a follow-on contract or similar effort. This must be done, however, with the contracting officer’s (KO) approval.
Reference Item 10g (NATO).
Access up to and including ____________ material will be required for reference at _______.
All ______________ may require access to North Atlantic Treaty Organization (NATO) Top Secret information for reference only. Access to NATO information will be authorized at the Government location specified in Item 8a. This also means information belonging to, and circulated by, NATO. Special briefings are required for access to NATO. Prior approval of the contracting activity is required for subcontracting. Access to classified NATO information requires a final U.S. Government clearance at the appropriate level and special briefings. Contractor shall be briefed into and debriefed by Facility Security Officer prior to arrival and departure from this contracting effort.
If contractor is read into ATOMAL or COSMIC, an annual re-brief is required.
Personnel not assigned to a NATO staff position, but requiring access to NATO classified information, NATO Secret or access to the NATO accredited SIPRNET terminals, must possess the equivalent FINAL or Interim U.S. Security Clearance based upon the appropriate personnel security investigation required. Personnel with access to NATO ATOMAL information must have the appropriate level FINAL U.S. Security Clearance. The government program/project manager is the designated representative that will ensure the contractor security manager and concerned employees are NATO briefed prior to access being granted. The contractor will maintain strict compliance in regards to NATO information IAW NISPOM Ch 10, Section 7. Prior approval from the KO is required for subcontracting.
Off-site contractors or subcontractors will not have access to NATO at their facility.
(DoD 5220.22M, Chapter 10)
Reference Item 10h (Foreign Government Information).
a. Access to this information, classified or unclassified, is restricted to U.S. citizens. This information includes any Foreign Government Information except NATO. Prior approval of the KO/COR is required before subcontracting. Access to classified foreign government information requires a final U.S. Government clearance at the appropriate level. Access will be granted on a case-by-case basis at the government locations specified in item 8a.
b. Foreign Government Information will be stored and access controlled in the same manner as U.S. Government material of the same classification.
(DoD 5220.22M, Chapter 10 and DoD 5105.21-M-1, Chapter 3)
Reference Item 10i (Limited Dissemination Information):
“LIMDIS” is handled under FOUO.
x Reference Item 10j (For Official Use Only).
a. The Contractor is authorized and may have access to UNCLASSIFIED information/material identified as "FOR OFFICIAL USE ONLY" (FOUO). Contractor will have access to unclassified sensitive information normally identified as FOUO, Privacy Act Information, Sensitive but Unclassified and Law Enforcement Sensitive The contractor is prohibited from further disclosure/dissemination of this information without the expressed written authorization of the OPMG. Material identified as FOUO shall be safeguarded IAW the guidance contained in DoD 5200.1-R, Appendix 3, Information Security Program. In addition, contractors or subcontractors must obtain approval from the KO/COR or Public Affairs Office prior to posting any unclassified information that was provided to them by the OPMG on any Web site or the Internet.
b. IAW OPSEC and Security Planning for Base Realignment and Closure (BRAC) 2005 Implementation, BRAC information shall be stored and processed on information systems approved for “For Official Use Only” data that provide password or PKI protection. Web sites shall implement secure connections (i.e., https/SSL) and require user identification for access (i.e., password/ID or PKI).
(DoD Regulation 5400.7, DoD Freedom of Information Act Program)
Reference 10k Other Secret Internet Protocol Network (SIPRNET) access required.
The contractor shall not access, download or further disseminate any special access data (i.e.
intelligence, NATO, COMSEC, etc.) outside the execution of the defined contract requirements and without the guidance and written permission of the KO. In the event that any special access is required, the KO must modify the requirements for the DD Form 254. Note: Once the KO has modified the requirements for the DD Form 254, the Contractor must complete the SIPRNET Access Request Form, along with the modified DD Form 254, and forward to the KO prior to receiving access. A NATO awareness brief will also be required for all Contractors prior to access to the SIPRNET.
X
Performance in Government Facilities.
This contract requires personnel to perform work as a member of, or in direct support of, the OPMG and will require individuals to work within Government controlled facilities.
A. In and Out Processing. This contract requires personnel to perform work as a member of, or in direct support of, the OPMG and will require individuals to obtain and maintain government issued building access cards to enable performance within Government controlled facilities. As such, all contractor personnel are required to in-process with the OPMG or location POCs prior to reporting for work. As a condition of this contract, all personnel issued government access cards are required to ensure the card is returned to the OPMG Security Office upon removal from the contract or termination of employment under this contract. Applies in all cases were performance in a government facility is applicable.
B. Escape Mask Program. This contract requires personnel to perform work as a member of, or in direct support of, the OPMG and will require individuals to obtain and maintain government furnished escape masks to enable performance within Government controlled facilities. As such, all contractor personnel are required to contact OPMG Sustainment Division for mask training (within 24 hours) of reporting for work. As a condition of this contract, all personnel issued government escape masks are required to ensure the mask is returned to OPMG/OPMG upon removal from the contract or termination of employment under this contract. Applies in all cases were performance in a government facility is applicable.
C. Common Access Cards (CAC). This contract requires personnel to obtain the Government issued Common Access Card (CAC) in order to access government computer systems. As such, all contractor personnel are required have an approved Form 8 or exception to policy letter before a CAC Request will be approved in the Contractor Verification System (CVS) by a Trusted Agent (TA). The COR will submit the request for approval. As a condition of this contract, all personnel issued Government CACs are required to ensure the card is returned to the OPMG Security Office upon removal from the contract or termination of employment under this contract.
D. NIPRNET access required. This contract requires the contractor to access and use the unclassified government computer system known as the NIPRNET at locations identified by the government customer. All provisions of the DoD Information Assurance Certification and Accreditation Process (DIACAP) apply. This system is Unclassified only, and inappropriate or improper use of the system will result in a reportable incident to Defense Security Service (DSS).
E. SIPRNET access required. This contract requires the contractor to access and use the classified government system known as the SIPRNET at locations identified by the government.
All provisions of the DoD Information Assurance Certification and Accreditation Process (DIACAP) apply. This system is authorized for use to but not exceeding the SECRET level only, and inappropriate or improper use of the system will result in a reportable incident to Defense Security Service (DSS).
F. JWICS access required. This contract requires the contractor to access and use the classified government system known as JWICS at locations identified by the government customer. This system is authorized for use to but not exceeding the TS-SCI level only, and inappropriate or improper use of the system will result in a reportable incident to Defense Intelligence Agency
(DIA)
G. TRAINING REQUIREMENTS:
a. OPSEC TRAINING: Contractor shall abide by OPSEC policies and procedures, as detailed in CJSCI 3213.01C and as directed by the OPSEC Manager or an OPSEC representative. Contractor shall accomplish their initial OPSEC training within 90 days of in-processing and complete annual OPSEC training. Contractor shall notify their OPSEC Coordinator or an OPSEC representative of recommendations for the OPSEC program or potential OPSEC concerns.
b. IA TRAINING: Contractor shall abide by IA policies and procedures, as detailed in Army regulations and as directed by the Information Assurance Manager (IAM) or an IA representative.
Reference Item 11a. (Have Access to Classified Information Only at another Contractor's Facility or Government Activity):
Performance of the classified portion of this contract is restricted to OPMG facilities and/or the locations cited in Block 8a, above. The KO/COR will provide security classification guidance for performance of this contract. SCI and collateral classified information may be processed, displayed, discussed or stored at OPMG facilities and the contractor's facility, provided the activity takes place in an appropriate area accredited and/or approved by an U.S. Government agency.
Reference Item 11b Receive Classified Documents Only.
REQUIRED FOR OFFSITE ONLY
Any classified information generated in performance of this contract shall be classified according to the markings on the source material. All classified information received is the property of the U.S. Government/Army/OPMG. The KO/COR will be contacted at the expiration or termination of this contract for proper disposition instructions.
Reference Item 11c. Receive and Generate Classified Material.
REQUIRED FOR OFFSITE ONLY
a. The Contractor may receive and generate classified information material up to and including
b. If the contractor/subcontractor is required to process classified information on an Automated Information System/Network (AIS/N) at the contractor/subcontractor’s facility, the information must be processed on an AIS/N accredited by a U.S. Government agency, and the contractor/subcontractor will be required to maintain/store the AIS/N in a U.S. Government accredited area, as appropriate.
c. OPMG contractors processing collateral classified information on contractor AIS equipment/networks within facilities accredited by the Defense Security Services will be accredited in accordance with DoD 5220.22-M. Contractor AIS equipment/networks used to process SCI information will be accredited in accordance with ICD 503, regardless of location.
Prior to processing SCI information on a Contractor AIS System/Network, the AIS System/Network must be accredited by DIA. (Contractors must contact the OPMG Security Office to initiate the SCI accreditation process for an AIS System/Network or a SCIF.)
Note that if 11c is marked then 1b must have a level of storage at contractor’s facility.
Reference Item 11d. Fabricate, Modify, or Store Classified Hardware.
REQUIRED FOR OFFSITE ONLY
a. The Contractor may fabricate, modify or store classified hardware up to and including ____________ using DIA-approved safes, vaults or security containers.
b. Equipment used to fabricate or modify classified information must be secured IAW DoD 5220.22M & DoD 5105.21-M-1.
c. Unless directed in writing otherwise, all classified information and/or material received or generated by the Contractor (including classified waste material) must be returned to the OPMG, unless retention is requested for a specific period of time and authorized in writing by the KO/COR. At the termination or expiration of this contract, the KO/COR will be contacted for proper disposition instructions.
d. SCI material/hardware will ONLY be stored in a SCIF, with a current SCI accreditation.
(DoD 5220.22-M, Chapter 5 & DoD 5105.21-M-1, Chapter 3)
Reference Item 11e. Perform Services Only. Contractor is performing a service only and is not expected to produce a deliverable item.
Reference Item 11f. Have Access to U.S. Classified Information Outside the US, Puerto Rico, US Possessions and Trust Territories. The contractor may require access to classified information at one or more Foreign Government Sites and/or U.S. Government facilities OCONUS (Outside the Continental United States). The government program manager will provide travel orders and direction prior to departure.
Contract performance will occur at the following U.S. activities:
Where____________________
Contractors when performing or traveling outside the United States under this contract will:
a. All personnel will obtain an AOR specific foreign travel brief within 90 days of travel and will provide proof of training to the COR.
b. All personnel will receive the Antiterrorism Level I Awareness training within one year prior to travel.
c. The contractor may only have access to U.S. classified information outside the U.S. if they are traveling under government orders.
(DoD 5220.22M, Chapter 10)
Reference Item 11g. Be Authorized to Use the Services of the Defense Technical Information Center (DTIC) or Other Secondary Distribution Center.
Contractor generated or Government furnished material may not be provided to the Defense Technical Information Center (DTIC). The contractor must prepare and forward DD Forms 1540 to the KO/COR for authorization BEFORE the services may be requested. Technical information on file at the Defense Technical Information Center (DTIC) will be made available to the contractor if the contractor requires such information. The KO/COR will certify the field of interest relating to the contract. The KO/COR will submit on behalf of the contractor. For subcontractors, the prime contractor submits the DD 1540 with the KO/COR verifying need to know. The contract may also submit DD Form 2345 “Military Critical Technical Data Agreement” (after registration with DTIC) to the Defense Logistic Services for access to unclassified, military critical technical data from other DoD sources. The KO/COR must certify the need-to-know-to DTIC. Special access information will not be sent to the National Defense Technical Information Center or the U.S. Department of Energy of Scientific and Technical Information.
(DoD 5220.22M, Chapter 11)
Reference Item 11h. Require a COMSEC Account.
a. The contractor is authorized to receive Government furnished cryptographic equipment/material. Access to classified COMSEC information requires a final U.S. Government clearance at the appropriate level and a briefing detailing proper safeguarding of COMSEC material/information. Further disclosure of COMSEC information by a contractor, to include subcontracting, requires prior approval of the contracting activity. Contractor must forward request for COMSEC material/information through government program manager to COMSEC Custodian.
Contractor is responsible for accountable COMSEC information and must provide a complete inventory as required by COMSEC account manager.
b. STU-III terminals installed at the contractor's facilities shall be supported by a COMSEC account through the CSO. STU-IIIs in the SCI Facilities (SCIFs) require Class VI Cryptographic Ignition Key (CIK).
c. Public release of COMSEC information/material is not authorized.
(DoD 5220.22M, Chapter 9)
Reference Item 11i. Have TEMPEST Requirements (aka Emissions Security).
REQUIRED FOR OFFSITE ONLY
For Collateral level classified processing: To determine possible TEMPEST countermeasures the contractor will assist in the vulnerability evaluation. The OPMG requires the contractor to provide a list and layout of equipment, the estimated percentage of classified information processed, cable/conduit runs, a floor plan layout that depicts placement of equipment in relation to other rooms, equipment distances from walls or uncontrolled areas, and physical security being afforded the equipment both during processing and after hours. Drawings/maps showing location of facility in relation to surrounding buildings/structures and any other information necessary to determine the tempest countermeasure requirements are needed.
(DoD 5220.22M, Chapter 11)
Reference Item 11j. Have Operations Security (OPSEC) Requirements.
a. The contractor will comply with Operations Security (OPSEC) requirements contained in the contract, addendum thereto, or identified herein.
b. The contractor will take the necessary precautions to ensure employees who require access are instructed on OPSEC and the protection of sensitive, unclassified information as well as Critical Unclassified Information (CUI).
c. The contractor will need to be familiar with OPSEC and be required to take mandatory OPSEC training.
d. The contractor will take the necessary precautions to ensure employees with access to the sensitive and critical information are instructed not to disclose or disseminate any information relating to the conduct and performance of the contract to any individual not authorized to perform on this contract.
e. The Contractor will ensure all UNCLASSIFIED, SENSITIVE AND CRITICAL information is returned to the OPMG and not destroyed.
f. Further OPSEC guidance may be obtained by contacting the OPMG Organizational Operations.
g. OPSEC and other security guidance issued to the prime contractor will also apply to subcontractors working on this effort.
(AR 530-1 and NISPOM)
Reference Item 11k. Authorized to use Defense Courier Service.
This contract may require the use of the Defense Courier Service (DCS) for shipment of classified information/material. The prime contractor must obtain written approval from KO/COR and provide the approval to the Commander, Defense Courier Service, ATTN: Operations Division, Fort George G. Meade, MD 20755-5370. Only certain classified information qualifies for shipment by DCS. The Contractor must obtain guidance concerning shipment of classified information/material from the DCS. Prior approval of NGA KO/COR is required before a prime contractor can authorize their subcontractor to use the services of DCS.
Off-Site: Contracting activity will request DCS Services from the Commander, Defense Courier Service, ATTN: Operations Division, Bldg 9-830, Fort George G. Meade, MD 20755-5370.
On-Site: Route all requests through Government Activity Office via Top Secret Control Officer (TSCO). Route all requests for SCI access through OPMG/OPMG SSO.
Prior approval of the contracting activity is required before granting subcontractor use of DCS services.
Reference 11l. Other.
When portions of this work under this contract occur at OPMG facilities, all OPMG policy and contractor personnel shall adhere to procedures that relate to security management. In the event that the development of information or material is not clearly covered by the contract or OPMG security policy and procedures, the contractor is required to seek OPMG guidance regarding its handling. Any questions the contractor or contractor personnel may have on the applicability of these security requirements shall be addressed to the KO/COR and/or the OPMG Security Office.
Contractors shall provide all cleared employees with security training and briefings commensurate with their involvement with classified information. The contractor shall provide all cleared employees with some form of security education and training at least annually. Refresher training shall reinforce the information provided during the initial security briefing and shall keep cleared employees informed of appropriate changes in security regulations. Contractors shall maintain records about the programs offered and employee participation in them. Contractors may obtain defensive security, threat awareness, and other education and training information and material from their CSA or other sources.
Only contractor/subcontractor/consultant personnel properly nominated by the contractor and approved by the KO/COR are authorized to perform on this contract and have access to classified information/material.
Prior to performance on any OPMG contract in which the contractor will have access to a U.S.
Government AIS System/Network, the contractor must have received the briefing/training required.
The contractor shall safeguard information IAW DTM 08-027, Security of Unclassified DoD Information on Non-DOD Information Systems. Do not post unclassified FOUO DoD information that has not been cleared for public release to website pages that are publicly available. Access controls must be restricted by user identification or password, user certificates, or other technical means and provide protection via use of TLS/SSL 6.0.
The contractor will ensure all Government computer accounts, assigned to contractor personnel during the performance of this contract, are deleted/disabled within 24 hours of completion, termination, removal, reassignment or other departure from the contract. (NOTE: Either the contractor, contractor’s supervisor, or the KO/COR, may disable the contractor’s AIS system/network account(s) by submitting a written request with the contractor’s name, date of the contractor’s departure, and identity of any AIS system/network accounts in which the contractor had access) through the OPMG Security Office or Organizational Operations. In either instance (i.e., cessation of contract or cessation of contractor personnel with this contract), the contractor shall notify the KO/COR in writing of all government computer accounts assigned to contractor personnel during the performance of this contract are deleted in accordance with this provision.
In performance of this contract, contractor/subcontractor /consultant will ensure any software to be provided or returned, under this contract, will be free from computer virus’ which could damage, destroy, or maliciously alter software, firmware, or hardware, or which could reveal to unauthorized persons any data or other information accessed through or processed by the software.
The contract requires AIS system capable of processing information up to _____________.
The KO/COR will notify the OPMG Security Office of all contractors who have departed or are no longer performing on the contract, and the date they were debriefed and by whom.
The contractor will report any adverse information coming to their attention to the OPMG Security Office. (The subsequent termination of employment of an employee does not obviate the requirement to submit the report.)
In performance of this contract, the contractor may be required and is authorized to hand carry or courier classified information up to an including ________ material within the following geographic area(s):
As such, contractor personnel are required to contact the OPMG Security Manager to obtain courier cards. Instructions for obtaining the courier card must be provided by COR and must be adhered to in order to obtain a courier card. The contractor/subcontractor will comply with the appropriate DIA/DOD/Army guidance for hand carry/courier of classified information.
In performance of this contract, the contractor will take the necessary precautions to ensure contractor/subcontractor employees out-process with the OPMG Security Office or the local site SSO upon termination/completion of this contract; The contractor will ensure contractor/subcontractor return any property/equipment (i.e., badge, common access cards (CAC), alternate tokens, vehicle hang tag, courier authorization, keys, etc.) issued by the OPMG.
In addition, when a contractor employee is reassigned, transferred, terminated or is no longer required to perform on this contract, the contractor FSO/CSSO will immediately notify the KO/COR, in writing, to cancel that employee's visit authorization.
The contractor is not authorized to destroy classified materials.
The FBI requires an SSBI investigation for unescorted access to their facilities. Much of the work on this task order requires independent actions of the contractor within the FBI facilities.
All visit access requests (VARs) by contractors, who will not sit in on-site OPMG spaces, shall be sent via the Joint Personnel Adjudication System (JPAS) to OPMG (Collateral SMO: W4GV137) or appropriate SMO for the effort by the contractor’s Facility Security Officer (FSO). The COR must approve the VAR prior to sending the request to the facility being visited.
In addition, in performance of this contract, the contractor/subcontractor will comply with security guidance provided by the KO/COR and/or contained in the following directives. NOTE: The Unclassified directives listed below can be downloaded via the Web site www.dtic.mil/whs/directives. Other directives, classification and marking guides should be obtained through the KO/COR:
• DoD 5200.1-R, Information Security Program, 17 Jan 97
• DoD 5200.2-R, Personnel Security Program, Jan 87
• DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), Feb
• DoD 5220.22-M-SUP-1, NISPOM Supplement, Revision 1 DoD Overprint, 1 Apr 04
• DoD 5105.21-M-1, Sensitive Compartmented Information Administrative Security Manual, Aug 98
• DoD C-5230.23, Intelligence Disclosure Policy, 18 Nov 83
• DoD 5200.28M, Security Requirements for AIS Systems, 21 Mar 88
• DCID 6/1, Security Policy Manual for Sensitive Compartmented Information, 1 Mar 95
• DCID 6/3, Protecting SCI Within Information Systems, 5 Jun 99
• DCID 6/6, Security Controls on the Dissemination of Intelligence Information, 6 June 03
• DCID 6/7, Intelligence Disclosure Policy, 20 Apr 01
• DCID 6/9, Physical Security Standards for SCIF, 18 Nov 02
• ICD 503, Information Technology Systems Security Risk Management,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .