A01 - Attachment 0004 - Contract Security Classification Specification_12J....pdf

PDF 992 KB Posted

Attached to
FORMAL SOLICITATION - Distributed Common Ground System - Army Capability Drop 2 Data Fabric and Analytics Federal contract opportunity
Solicitation number
W56KGY-19-R-0007
Issued by
Department of the Army Materiel Command Army Contracting Command Aberdeen Proving Ground

About this file

This solicitation seeks proposals for a multiple award indefinite delivery/indefinite quantity contract to provide a commercial software solution and related services for the Distributed Common Ground System - Army Capability Drop 2 Data Fabric and Analytics program. Offerors must propose solutions that dynamically ingest data from multiple sources with common/open interfaces to enable data discovery, refinement, management, storage, and access across echelons. The minimum contract value is $3,500 and the maximum is $823,263,105.82 over a potential seven-year ordering period. Proposals are due by 12:00 PM Eastern on August 2, 2019 and the Army intends to award multiple contracts on a firm-fixed-price basis. Relevant past performance must include at least one year of experience on projects similar in scope within the last three years. Questions regarding this solicitation must be submitted to the Army in writing by the specified due date.

Solicitation Section J Attachments/Exhibits

View the file

Other files for this federal contract opportunity

Other files attached to FORMAL SOLICITATION - Distributed Common Ground System - Army Capability Drop 2 Data Fabric and Analytics, newest first.
File Type Posted
DCGS-A_Capability_Drop_2__Questions_Answers_8-09-2019.pdf PDF
DCGS-A_Capability_Drop_2__Questions_Answers_8-06-2019.pdf PDF
A01_-_Attachment_0006_-_Total_Evaluated_Price_Worksheet_DCGS-A_CD_2_30JUl2019.XLSX XLSX spreadsheet
A07_-_Solicitation_W56KGY-19-R-0007_Amendment_0001_01AUG2019.pdf PDF
DCGS-A_Capability_Drop_2__Questions_Answers_7-26-2019.pdf PDF
A01 - Attachment 0006 - Total Evaluated Price Worksheet_DCGS-A CD 2_26JU....xlsx XLSX spreadsheet
A01 - Attachment 0008 - Solicitation Tables_DCGS-A CD 2_26JUN2019.pdf PDF
A01 - Exhibit A_ CDRL_IPSC.PDF PDF
A01 - Exhibit C_ CDRL_MISC.PDF PDF
A01 - Attachment 0002 - Statement of Work Appendix A_DCGS-A CD 2_25JUN20....pdf PDF
A01 - Exhibit E_ CDRL_ADMN.PDF PDF
A01 - Attachment 0009 - Past Performance Assessment Request_DCGS-A CD 2_....pdf PDF
A01 - Exhibit B_ CDRL_MGMT.PDF PDF
A01 - Attachment 0005 - Quality Assurance Surveillance Plan_DCGS-A CD 2_....pdf PDF
A07_-_Solicitation_W56KGY-19-R-0007_18JUL2019.pdf PDF
A01 - Exhibit D_ CDRL_SESS.PDF PDF
A01 - Exhibit F_ CDRL_ILSS.PDF PDF
A01 - Attachment 0001 - Statement of Work_DCGS-A CD2_17JUL2019.pdf PDF
Show all 18

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CLASSIFICATION (When filled in): Unclassified

PREVIOUS EDITION IS OBSOLETE. Page 1 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 1 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

October 31, 2020

The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED (See Instructions)

Top Secret

b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/

MATERIAL REQUIRED AT CONTRACTOR FACILITY

Top Secret

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

a. PRIME CONTRACT NUMBER (See instructions.)

b. SUBCONTRACT NUMBER

c. SOLICITATION OR OTHER NUMBER

W56KGY19R0007

DUE DATE (YYYYMMDD)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

DATE (YYYYMMDD)

b. REVISED (Supersedes all previous specifications.)

REVISION NO. DATE (YYYYMMDD)

c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)

4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:

Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.

5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:

In response to the contractor's request dated , retention of the classified material is authorized for the period of:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE

TBD

b. CAGE CODE

TBD

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

a. NAME, ADDRESS, AND ZIP CODE

b. CAGE CODE

TBD

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

8. ACTUAL PERFORMANCE (Click button to add more locations.)

a. LOCATION(S) (For actual performance, see instructions.)

See continuation page, item 13

b. CAGE CODE

(If applicable, see Instructions.)

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT

The contractor shall provide a commercial item that is a software only solution to meet the interoperability, security, training, usability, and data management capabilities of the Project Manager (PM) Distributed Common Ground System – Army (DCGS-A) Capability Drop (CD) 2, Data Fabric and Analytics. The Contractor shall also provide support, services, and deliverables.

PREVIOUS EDITION IS OBSOLETE. Page 2 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 2 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION

b. RESTRICTED DATA

g. NORTH ATLANTIC TREATY ORGANIZATION

(NATO) INFORMATION

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.)

h. FOREIGN GOVERMENT INFORMATION

d. FORMERLY RESTRICTED DATA

i. ALTERNATIVE COMPENSATORY CONTROL MEASURES

(ACCM) INFORMATION

e. NATIONAL INTELLIGENCE INFORMATION:

(1) Sensitive Compartmented Information (SCI)

(2) Non-SCI

j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)

k. OTHER (Specify) (See instructions.)

SIPRNet, JWICS, and SCGs

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT

ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT

ACTIVITY

(Applicable only if there is no access or storage required at contractor facility.

See instructions.)

b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY

c. RECEIVE, STORE, AND GENERATE CLASSIFIED

INFORMATION OR MATERIAL

d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

e. PERFORM SERVICES ONLY

f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE

THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST

TERRITORIES

g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE

TECHNICAL INFORMATION CENTER (DTIC) OR OTHER

SECONDARY DISTRIBUTION CENTER

h. REQUIRE A COMSEC ACCOUNT

i. HAVE A TEMPEST REQUIREMENT

j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE

l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED

INFORMATION (CUI).

(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)

m. OTHER (Specify) (See instructions.)

IT Sensitive Duties

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.

Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

DIRECT THROUGH (Specify below)

See continuation page, item 13

Public Release Authority:

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;

and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

See continuation page, item 13

List of Attachments (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)

PREVIOUS EDITION IS OBSOLETE. Page 3 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 3 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018

NAME & TITLE OF REVIEWING OFFICIAL SIGNATURE

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

No Yes If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.

(See instructions for additional guidance or use of the fillable PDF.)

See SOW Appendix A

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

No Yes If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item

13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.

(See instructions for additional guidance or use of the fillable PDF.)

The SSO is responsible for inspections and oversight of SCIF at government facilities.

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

a. GCA NAME

Army Contracting Command-APG

b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See Instructions)

W56KGY

c. ADDRESS (Include ZIP Code)

6565 Surveillance Loop, BLDG 6001 Aberdeen Proving Ground, MD 21005-1846

d. POC NAME

Matthew C. Ebner

e. POC TELEPHONE (Include Area Code)

+1 (443) 861-5390

f. EMAIL ADDRESS (See Instructions) matthew.c.ebner.civ@mail.mil

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See Instructions)

Howard, Brian K.

b. TITLE

Industrial Security Specialist

c. ADDRESS (Include ZIP Code)

Building 6002, Room D2101 6585 Surveillance Loop Aberdeen Proving Ground, MD 21005

d. AAC OF THE CONTRACTING OFFICE (See Instructions)

W1J103

e. CAGE CODE OF THE PRIME CONTRACTOR (See Instructions.)

f. TELEPHONE (Include Area Code)

+1 (443) 861-6999

g. EMAIL ADDRESS (See Instructions) brian.k.howard8.civ@mail.mil

h. SIGNATURE

i. DATE SIGNED (See Instructions)

20190612

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

a. CONTRACTOR

b. SUBCONTRACTOR

c. COGNIZANT SECURITY OFFICE FOR PRIME AND

SUBCONTRACTOR

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY

ADMINISTRATION

e. ADMINISTRATIVE CONTRACTING OFFICER

f. OTHER AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)

HOWAR

D.BRIAN.

KEITH.10

44428373

Digitally signed by

HOWARD.BRI

AN.KEITH.104

4428373 Date: 2019.06.12 15:21:11 -04'00'

DD Form 254 - Item 13 Continuation

Solicitation Number: W56KGY19R0007

Contract Number:

ALL ITEMS CHECKED YES, APPLY TO THIS EFFORT. ITEMS CHECKED NO ARE NOT APPLICABLE TO THIS EFFORT

AND REQUIREMENTS WILL NOT BE LEVIED AGAINST THE CONTRACTOR.

Q @ 4. Follow-on contract - The classified portion of work has been completed on the contract cited in this item. The processing of classified will no longer be done under this contract. All classified material/information associated

YES NO

with this contract is authorized to be transferred to the contract number cited in Item 2a.

Remarks:

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

CONTRACTOR.

® 0 8. Actual Places of Performance: REFERENCE ITEM 8 OF DD FORM 254 FOR ACTUAL PLACES OF

PERFORMANCE. SPECIFIC REMARKS REGARDING THOSE LOCATIONS ARE FOUND BELOW AND/OR PLACES OF

YES NO

PERFORMANCE ARE DUPLICATED BELOW.

YES

Remarks:

CONUS: PEO IEW&S/PM DCGS-A (BLDG 6002/6006) and 12WD (BLDG 6003) at C41SR, Aberdeen Proving Ground (APG), Q 10a. COMSEC - Access to COMSEC material is required in the performance of this contract. The contractor may be authorized to receive government furnished cryptographic equipment, if a COMSEC account is required and NO if Item llh of this DD Form 254 is checked. Contractor personnel are subject to The Department of Army

Cryptographic Access Program (DACAP), IAW AR 380-40. The contractor shall comply with NSA/CSA Manual 3-

16, AR 380-40, and the Committee of National Security Systems Instructions (CNSSI) 4001, "Control of

Communications Security Material," or other guidance provided by the central office of record. If access to

COMSEC information is required at Government facilities, contractor shall adhere to the government/program

COMSEC plan or guidance. Approval by the KO/COR is required prior to transporting or carrying classified

COMSEC material on a cleared commercial carrier or passenger aircraft. The government program/project manager shall designate the number of personnel requiring cryptographic (CRYPTO) access. Approval by the KO is required prior to the flow down of COMSEC requirements to any subcontractor.

Remarks:

No additional remarks.

Q @ 10b. Restricted Data - Contractor requires access to Restricted Data per the PWS. Refer to 10 CFR 1045 "Nuclear

Classification and Declassification" and Atomic Energy Act of 1954, as amended, for further information.

YES NO Approval by the KO is required prior to the flow down of Restricted Data requirements to any subcontractor.

Remarks:

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

CONTRACTOR.

Contract Number:

0 @ 10c. Critical Nuclear Weapon Design Information - Contractor requires access to Critical Nuclear Weapon

Design Information (CNWDI). Special briefings and procedures are required. Approval by the KO is required prior YES NO to the flow down of CNWDI requirements to any subcontractor.

Remarks:

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

CONTRACTOR.

Q @ 10d. Formerly Restricted Data - Contractor requires access to Formerly Restricted Data (FRD) per the PWS, SOW, or SOO.

YES NO

Remarks:

YES

YES

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

CONTRACTOR.

Q 10e(1). Sensitive Compartmented Information (SCI) -Access to Intelligence information that is Sensitive

Compartmented Information (SCI) may be required in the performance of this contract. Refer to the SCI

NO

Addendum for additional guidance. Contractors are required to complete SCI training requirements through

COR approved appropriate training systems/databases (e.g., Total Employee Development (TED), Security

Training, Education and Professionalization (STEPP)). Only those personnel that require access to SCI information to complete their job duties will be provided SCI access. Approval by the KO is required prior to the flow down of SCI requirements to any subcontractor.

Remarks:

SSO is to approve all indoctrinations and contractor shall immediately notify the SSO of any loss of accesses.

Q 10e(2). Non-Sensitive Compartmented Information (Non-SCI) -Access to Intelligence information that is Non

Sensitive Compartmented Information (Non-SCI) may be required in the performance of this contract. Approval

NO

by the KO is required prior to the flow down of Non-SCI requirements to any subcontractor.

Remarks:

No additional remarks.

Contract Number:

O® lOf. Special Access Programs - Contractor requires access to Special Access Program (SAP) Information per the

PWS, SOW, or SOO. Contractor will comply with DoDM 5205.07 (Volumes 1-4), AR 380-381, and requirements NO and directions provided by the Program Security Officer (PSO), name and contact information found below, orYES successor. Approval by the KO is required prior to the flow down of SAP requirements to any subcontractor.

Requiring Activity's (RA) PSO is required to provide the SAP Security Plan to contractors for adherence.

PSO Name (must be completed if l0f is checked YES):

NOT APPLICABLE

PSO Contact Information (Phone and DISA Email):

NOT APPLICABLE

Remarks:

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

CONTRACTOR.

@ Q 10g. North Atlantic Treaty Organization - Contractor requires access to North Atlantic Treaty Organization

(NATO) Information per the PWS. Approval by the KO is required prior to the flow down of NATO requirements YES NO to any subcontractor. Refer to item 13g for NATO training guidance in Item 13.

Remarks:

No additional remarks.

Q @ 10h. Foreign Government Information - Contractor requires access to Foreign Government Information (FGI) per the PWS, SOW, or SOO.

YES NO Remarks:

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

CONTRACTOR.

Q @ 10i. Alternative Compensatory Control Measures - Contractor requires access to Alternative Compensatory

Control Measures (ACCM) Information.

YES NO

Remarks:

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

Contract Number:

®O 10j. Controlled Unclassified Information (CUI) - Access to Controlled Unclassified Information (CUI) is required in the performance of this contract. Information designated as CUI, e.g., For Official Use Only (FOUO), generated or provided under this contract shall be controlled, handled, stored, marked, safeguarded, transmitted, and destroyed IAW DoDM 5200.01 Vol 4, DoDM 5400.0, AR 380-5, AR 25-55, AR 25-2, and the following guidance:

YES NO

• Electronically transmitted CUI shall be sent via:

o Emailing FOUO between the Government and a Contractor: Digitally encrypted email can be accessed via DOD CAC or if the Contractor's company has the proper DOD-approved assurance certificates installed. For more details on DOD-approved assurance certificates visit https://iase.disa.mil/pki/eca/Pages/index.aspx.

o Government SharePoint: Contractor must have a DOD CAC and access is based on the

Government's approval.

o U.S. Army Research Laboratory Secure Access File Exchange (ARL SAFE) Service https://safe.arl.army.mil/ o lntelDocs - https://inteldocs.intelink.gov/inteldocs o CD/DVD: Save CUI-marked files to a CD/DVD and properly mail to recipient.

o Fax: Send CUI-marked documents via facsimile machine to recipient.

o An accredited information system with proper security controls.

• The contractor may disseminate FOUO information to their employees and subcontractors that have a need-to-know.

• The contractor shall report the unauthorized disclosure of CUI to the COR.

Remarks:

No additional remarks.

® Q 10k. SCGS - SCGs associated with this effort are listed below by title, date, and office of primary responsibility per AR 380-49. Contractor will require access to all SCGs listed below:

Remarks: (ENTER ALL SCGs ASSOCIATED WITH THIS EFFORT BY TITLE, DATE, AND FUNCTIONAL OFFICE OF

PRIMARY RESPONSIBILITY)

1. ARCYBER SCG FOR CYBERSPACE OPERATIONS AND SECURITY, DATED 19 MAY 2016, U.S. ARMY CYBER

COMMAND AND SECOND ARMY, or most current SCG.

2. DCSG-A Security Classification Guide 20150528 PEO IEW&S

Contract Number:

®O 10k. SIPRNet - Secured Internet Protocol Network (SI PR Net) access is required for the performance of the contract. Requests for access will be submitted to COR to facilitate the local vetting and approval process.

Contractor must follow appropriate processes for obtaining login credentials to SIPRNet. Contractor personnel must be cleared at the NATO SECRET level in order to obtain access to SIPRNet. If SIPRNet is required at contractor facility, contractor shall coordinate with appropriate DSS representatives. The contractor requires access to the Defense Information Systems Network (DISN) Secret Internet Protocol Routing Network (SIPRNet) dated 01 June 2013, or most current.

YES NO

YES

Remarks:

No additional remarks.

Q 10k. JWICS - JWICS access is required for the execution of the contract. Requests for access will be submitted to

COR to facilitate the vetting and approval process. Contractor must follow appropriate processes for obtaining NO login credentials to JWICS. Contractor personnel must be cleared at the NATO SECRET level in to obtain access to JWICS. If JWICS is required at contractor facilities, the contractor shall coordinate with the appropriate

Special Security Officer (SSO) and/or Contractor Special Security Officer (CSSO). The Contractor requires access to the JWICS SCG, Defense Intelligence Agency, dated 29 September 2017, or most current.

No additional remarks.

Q @ 10k. NSANet - NSANet access is required for the execution of the contract. Requests for access will be submitted to COR to facilitate the vetting and approval process. Contractor must follow appropriate processes

YES NO

for obtaining login credentials to NSANet.

Remarks:

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

Contract Number:

Q @ 10k. Other classified IS- (Add tailored verbiage provision for using other classified IS)

YES NO Remarks:

YES

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

CONTRACTOR.

@ 11a. Have access to classified information only at another contractor's facility or at a government activity -

The contractor shall have access to classified information only at another contractor's facility or at a NO government activity. If this item is checked, than safeguarding of classified is NONE and items llb, llc, lld, llh, or llk do not apply to this effort.

Remarks:

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

CONTRACTOR.

Q @ 11b. Receive and store classified documents only - Contractor is authorized to receive classified documents only for purposes named in the remarks below. There will be no generation or derivative classification of YES NO material at the contractor facility. Special storage requirements are listed in remarks below.

Remarks:

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

Contract Number:

0 llc. Receive, store, and generate classified information or material - Contractor is authorized to receive, store, and generate classified material at the contractor's facility. Contractor will reference the appropriate security NO classification guidance when generating or deriving classified material or hardware, reference item 10k. AllYES classified information received or generated will be properly stored and handled according to the markings on the material. All classified information received or generated is the property of the U.S. Government. At the termination or expiration of this contract, the U.S. Government will be contacted for proper disposition instructions.

Remarks:

No additional remarks.

@ Q lld. Fabricate, modify, or store classified hardware - Contractor will fabricate, modify, or store classified hardware at their facility. A description of the area required to store such material and details regarding

YES NO what the contractor will require, can be found in the remarks below.

Remarks:

No additional remarks.

0 fe'i lle. Perform services only - Contractor will perform services only as described in the remarks below:

\:I Remarks:

YES NO

NOT APPLICABLE TO THIS EFFORT. REQUIREMENT WILL NOT BE LEVIED ON THE

YES

YES

DD Form 254 - Item 13 Continuation

Solicitation Number: W56KGY19R0007

Contract Number:

0 llf. Have access to U.S. classified information outside the U.S., Puerto Rico, U.S. Possessions, and Trust

Territories - The contractor will have access to classified information at OCON US locations. Refer to item 8a for NO a listing of OCON US locations. RA is responsible for identifying security oversight for the OCON US locations and ensuring compliance with Foreign Clearance Guide (https://www.fcg.pentagon.mil/fcg.cfm).

Remarks:

No additional remarks.

llg. Be authorized to use the services of Defense Technical Information Center (DTIC) or other secondary distribution center - The contractor will prepare DD Form 1540, Registration for Scientific and Technical

NO Information Services and DD Form 2345, Militarily Critical Technical Data Agreement, for authorized access to

Defense Technical Information Center DTIC. Completed forms will be provided to the KO/COR for processing and submission to DTIC.

Remarks:

No additional remarks.

@ Q 11h. Require a COMSEC account - Contractor requires a COMSEC account. If this item is checked, then item 10a will be checked.

YES NO Remarks:

Contract Number:

@ Q lli. Have a TEMPEST requirement - Contractor shall follow TEMPEST requirements IAW AR 380-27.

YES NO

Remarks:

No additional remarks.

® 0 11j. Have Operations Security (OPSEC) Requirements - (ALWAYS REQUIRED)

(REQUIRED WHEN THE PLACE OF PERFORMANCE IS AT GOVERNMENT INSTALLATIONS/FACILITIES) While YES NO performing work at Government facilities, the contractors shall adhere to the OPSEC requirements IAW the

OPSEC Plan/SOP listed by name and date, in the REMARKS BELOW, or its most current version. The OPSEC plan will be provided to the contractor after contract has been awarded.

YES

and/or

(REQUIRED WHEN THE PLACE OF PERFORMANCE IS AT THE CONTRACTOR'S FACILITY) If performing on contractor site, the contractor shall have an identified certified Level II OPSEC coordinator per AR 530-1. The contractor shall develop an OPSEC Plan IAW AR 530-1 as listed in the PWS, SOW, and, SOO CORL NUMBER

BELOW. RA is responsible for providing to the contractor a current and valid program/command OPSEC Plan.

The contractor will use the program/command OPSEC Plan to ensure the contractor developed OPSEC Plan includes the same Critical Information List (CIL) and OPSEC measures.

Remarks: (ENTER OPSEC PLAN[S] ASSOCIATED WITH THIS EFFORT BY TITLE AND DATE)

CORL DI-MGMT-80934C, A003

PM DCGS-A OPSEC Plan V1.5 20140721 PM DCDS-A

Q llk. Be authorized to use Defense Courier Service (DCS) - Contractor is authorized to use Defense Courier

Service (DCS). The KO/COR will obtain written approval from the United States Transportation Command's NO (USTRANSCOM) Defense Courier Division (TCJ3-C), Scott AFB, IL 62225-5357. Only certain classified information qualifies for shipment by DCS. If applicable, COMSEC material will be transported via DCS as described in remarks below.

Remarks:

DD Form 254 - Item 13 Continuation Solicitation Number: W56KGY19R0007 Contract Number:

0 111. Receive, store, or generate CUI - Contractor is authorized to receive, store, or generate CUI in the performance of this contract. Information designated as CUI, e.g., FOUO generated under this contract shall be

NO controlled, handled, stored, marked, safeguarded, transmitted and destroyed IAW DoDM 5200.01, DoDM 5400.07, AR 380-5, AR 25-2, AR 25-55, and the following guidance:

• Electronically transmitted CUI shall be sent via:

o Emailing FOUO between the Government and a Contractor: Digitally encrypted email can be accessed via DOD CAC or if the Contractor's company has the proper DOD-approved assurance certificates installed. For more details on DOD-approved assurance certificates visit https://iase.disa.mil/pki/eca/Pages/index.aspx.

o Government SharePoint: Contractor must have a DOD CAC and access is based on the Government's approval.

o U.S. Army Research Laboratory Secure Access File Exchange (ARL SAFE) Service https://safe.arl.army.mil/ o lntelDocs - https://inteldocs.intelink.gov/inteldocs o CD/DVD: Save CUI-marked files to a CD/DVD and properly mail to recipient.

o Fax: Send CUI-marked documents via facsimile machine to recipient.

o An accredited information system with proper security controls.

• The contractor may disseminate FOUO information to their employees and subcontractors that have a need-to-know.

• The contractor shall report the unauthorized disclosure of CUI to the COR.

Remarks:

No additional remarks.

� Q llm. Other/IT sensitive duties required - Refer to Item 13 for IT requirements.

� Remarks:

YES NO

Contract Number:

12. Public Release - All requests for public release shall be submitted by the government COR utilizing the

CECOM Public Release Approval System (PRAS) at: https://medinah.sed.apg.army.mil/PRAS/ and/or through

OPSEC Officer and Public Affairs Office (PAO) identified below:

OPSEC Officer and Contact PM DCGS-A OPSEC Officer, Wai Wong, Information (include phone, email, and mailing address):

wai.l.wong6.civ@mail.mil / 443-861-2405, PM DCGS-A, Aberdeen Proving Ground, MD 21005

PAO (include phone, email, and PEO IEW&S Public Affairs Officer mailing address):

brandon.j.pollachek.ctr@mail.mil / 443.861.7820, APG, MD 21005

@ Q 13a. IT Levels - The RA shall determine the appropriate IT Level for each individual contractor personnel in accordance with DoD 8570.01-M (Ch4), AR 380-67, and AR 25-2. The appropriate level of access for each IS will YES NO be documented via System Access Requests.

Q 13b. IS Accreditation - Contractors must use appropriately accredited IS email when sending official government correspondence. Using a masked domain is not acceptable.

YES NO

@ Q 13c. OCONUS Places of Performance - Contractors traveling to OCON US locations for either official or unofficial

YES NO

travel may require a defensive counterintelligence briefing prior to their departure. Requirement for defensive

YES

YES

travel brief will be based on threat and will remain at the discretion of the G2 and/or organization's security manager.

0 13d. Spillages - Classified information will be protected IAW the NISPOM and DFARS 252.204-7012. All security incidents involving classified information, e.g., spillage, shall be immediately reported to the RA Security NO Specialist and to their DSS Industrial Security Representative. Information will be forwarded to KO/COR and the

Program Manager for a program damage assessment to be conducted IAW AR 380-49. A spillage occurs whenever classified information or CUI is transferred onto an information system not authorized for the appropriate security level or not having the required CUI protection or access controls. Contractors responsible for a willful or negligent spillage of information shall pay enterprise service providers for the associated cleanup costs across the enterprise to restore the affected network or networks to a normal operating configuration.

0 13e. Security Trainings/Briefings - Security Training and Briefing: IAW AR 380-49 Chapter 3, the FSO will provide

Threat Awareness and Reporting Program (TARP) training in addition to initial and refresher security training NO IAW AR 381-12, paragraph 1-14 and Chapter 2 for contractors working in contractor facilities. Contractors may be exempt from such security training if they can provide documentation they have had similar training from their FSO. The FSO will forward Certificates and/or a signed Letter of Certification for Training to the COR for verification of required training to be included in the contract folder.

Integrated/embedded contractors will receive security training from the assigned Security

Manager/Representative. Training is tailored to the organization's requirements as well as local policy. Some examples of Security training provided to integrated/embedded contractors may include, but is not limited to, the following:

• TARP Training: Live training provided by 902d Ml Group - Annual training requirement

YES

YES

DD Form 254 - Item 13 Continuation

Solicitation Number: W56KGY19R0007

Contract Number:

• Initial Security Orientation: Online training available on the Army Learning Management System (ALMS) site, reference ALARACT 207-2103 - Initial training

• Annual Security Orientation: Online training available on the Army Learning Management System

(ALMS) site, reference ALARACT 207-2103 - Annual training requirement

• Derivative Classification Training, reference DoD 5200.01-V3-Biennial training requirement

• Operations Security Training, reference AR 530-1- Annual training requirement:

http://cdse.edu/catalog/elearning/GS130.html

• Foreign travel training, AR 525-13 - Required when traveling abroad

Q 13f. NATO Awareness Briefing - All cleared contractor personnel shall obtain a NATO Security Awareness

Briefing from their FSO and/or from their program security specialist. NATO Awareness Briefing can be found at

N the following CAC enabled link http://www.cusr.army.mil/.

0 13g. Security Classification Guides - Per AR 380-49, the RA is required to identify by title, functional office of primary responsibility, and approval date, the SCGs applicable to the contract on the DD Form 254 within item NO 13. The requirement for SCG(s) must also be annotated on DD Form 254, block 10k. Due to the mission and its reimbursable nature, it is impossible to proactively identify all SCGs associated with contract efforts. However, upon identification, the RA shall immediately provide SCGs related to the classified information associated with the execution of this contract.

Q 13h. PWS, SOW, or SOO - The PWS, SOW, or SOO shall be provided to the contractor's FSO and/or CSSO along with the DD Form 254 and associated Continuation Pages. This is to ensure that the FSO and/or CSSO are aware

NO

of all contractual requirements relating to security within the effort.

@ Q 13i. Generation of classified material - The generation of classified material includes derivatively classified information.

YES NO

@ Q 13j. Individual Courier Card - Requirements for Individual Courier Cards must be approved by the COR.

YES NO

13k. Additional Remarks not already addressed in items la -13k of this Security Appendix.

Q @ Remarks:

YES NO No additional remarks.

File details come from the government source that posted it. Updated .