DD254_Collateral_Addendum.pdf
PDF 54 KB Posted
- Attached to
- Administrative Support Services Federal contract opportunity
- Solicitation number
- W911QX-17-R-0003
About this file
This document contains a Collateral Addendum and DD Form 254 for a contract to provide Administrative Support Services to the Army Research Laboratory. The solicitation seeks to award multiple IDIQ contracts through the 8(a) program to support various directorates across multiple ARL sites. Required non-personal services include program management, administration, technical, security, financial management, logistics, technical publications, library support, and graphics/audiovisual services. Responses to the synopsis notice were due by November 11, 2016. The Army Research Laboratory is responsible for basic, exploratory, and advanced research to support the development of weapons technologies and systems.
DD254 Collateral Addendum
View the file
Other files for this federal contract opportunity
Show all 50
Administrative Support Services has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Template last updated 6/11/2015
COLLATERAL ADDENDUM
To
U.S. Army Research Laboratory
DD Form 254, Contractor Security Classification Specification
Date: 1 December 2016
Contract Number: W911QX-17-R-0003 / W911QX-16-R-0009
Contractor Name: TBD
_X_ Items marked with an X are applicable to this contract
Items Continued:
_X_ Item 8. List ALL locations where classified performance is required under the contract (i.e. contractor, subcontractor, and Government facilities).
(1) If the place of performance is the same as 6a (or 7a), either enter the facility’ name or enter “Same as Item 6a (or 7a) in block 8a. If the place of performance is different from 6a (or 7a), include the facility name, address and CAGE code.
(2) If there is more than one place of performance, enter “multiple locations – see
Item 13 (or Attachment xxx)” in item 8a, and identify each performance location accordingly.
(3) Performance of a contract in Government facilities should be explained in Item 13. The location will be placed in item 8a. (e.g. Pentagon).
__10a. Communications Security (COMSEC). COMSEC information includes accountable or non-accountable COMSEC information and controlled cryptographic items (CCI). If accountable COMSEC material is involved, the contractor must have a COMSEC account. Prior approval from the KO is required in order for a Prime Contractor to grant COMSEC access to a subcontractor. The Prime Contractor should also notify the NSA Central Office of Record (COR) before negotiating or awarding subcontracts. Classified COMSEC material is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. COMSEC access shall be IAW DoD 5220.22-M and AR 380-40. When access is required at Government facilities, contractor personnel will adhere to COMSEC rules and regulations as mandated by Command policy and procedures. Written concurrence of the KO is required prior to subcontracting.
__10b. Restricted Data Information is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level.
Written concurrence of the KO is required prior to subcontracting.
__ 10c. Critical Nuclear Weapon Design Information (CNWDI). KO approval is required prior to granting CNWDI access to a subcontractor. Special briefings and procedures are also required. Access to CNWDI requires a final U.S.
Government clearance at that appropriate level. 10c must be marked “YES” if item 10b is marked “YES.”
__10d. Formerly Restricted Data (FRD). The contractor is permitted access to Formerly Restricted Data (FRD) in the performance of this contract. Access to FRD requires a final U.S. Government clearance at the appropriate level. Written concurrence of the KO is required prior to subcontracting. NOTE: Access to FORMERLY RESTRICTED DATA requires a final U.S. Government Clearance at the appropriate level.
__10e (1). Intelligence Information: SCI Access required. No public release of information authorized, public disclosure or confirmation of any subject related to the support contract is not authorized without first obtaining written approval from the KO. . If the contract requires access to intelligence information, the KO is responsible for ensuring that the additional security requirements outlined in the DNI Directives are incorporated in the guidance provided to the contractor. If the contract requires Sensitive Compartmented Information (SCI) access, a SCI Addendum is required and MUST be coordinated with the Contractor Support Element (CSE). SCI is very expensive for the contractor to maintain. This block should not be marked unless there is a current SCI requirement. If access to SCI is required: Mark 10e (1) “YES” and mark Items 14 and 15 “YES.”
__10e (2). This contract requires access to non-SCI intelligence information.
Non-SCI Information is not releasable to contractor employees who have not received a clearance at the appropriate security level. Written concurrence of the KO is required prior to subcontracting. Access to Intelligence information required for performance. Request for non-SCI intelligence information should be submitted to the U.S. Army Research Laboratory, ATTN: RDRL-LOI-F, 2800 Powder Mill Road, Adelphi, MD 20783. If access to non-SCI is required mark 10e
(2) “YES” and mark Item 14 “YES”.
NOTE: If access to SCI and non-SCI is required mark 10e(1) and 10e(2) “YES” , mark Item 14 “YES” and mark Item 15 as appropriate. Prior approval by the KO is required before a subcontract involving access to Intelligence Information can be issued. Access to Intelligence information requires a U.S. Government clearance at the appropriate level.
__ 10f. Special Access Information: Special Access Programs (SAP) imposes security requirements on the contractor that exceed the NISPOM. When SAP information is involved, the cognizant SAP security office is responsible for providing the contractor with the additional security requirements needed to ensure adequate protection of SAP information. Contractor will comply with Program Security Procedures Guide to include Security Classification Guides (list in block 11c below) and AR 380-381, Special Access Programs provided by the KO at the performance location. If SAP requirements are imposed on the contractor mark 10f “YES” and mark Item 14 “YES.”
If a SAP subcontract is awarded, the prime contractor is responsible to incorporate the additional security requirements in the subcontract. The Program Manager must grant authorization for release of SAP information to the subcontractor prior to issuance of any SAP subcontract. A SAP Addendum is required for all contracts that require SAP access. Additional clarification should be addressed in either Item 13 or the SAP Addendum and are as follows:
• What information makes the hardware/services classified?
• Will hardware/data being generated require classification? At what stage in the production will it become classified?
Be sure to:
• Identify the specific information to be classified
• Provide appropriate downgrading or declassification instructions, and
• Provide any special instructions, explanations, comments or statements necessary to clarify other items identified in the DD Form 254.
__10g. Personnel not assigned to a NATO staff position, but requiring access to NATO classified information, NATO COSMIC, NATO Secret or access to the NATO accredited SIPRNET terminals, must possess the equivalent FINAL or Interim U.S. Security Clearance based upon the appropriate personnel security investigation required. Personnel with access to NATO ATOMAL information must have the appropriate level FINAL U.S. Security Clearance. The government program/project manager is the designated representative that will ensure the contractor security manager and concerned employees are NATO briefed prior to access being granted. The contractor will maintain strict compliance in regards to NATO information IAW NISPOM Ch 10, Section 7. Prior approval from the KO is required for subcontracting. Note: If the contractor does not require access to NATO information, requires access to the SIPRNET, mark 10g “No” but mark 10k “Yes” (SIPRNET access) and add the statement below in item 13 that the contractor requires access to the SIPRNET and NATO awareness brief is required.
The SIPRNET contains NATO information and a NATO awareness briefing is required for everyone who needs access to the SIPRNET. The purpose of providing a NATO awareness briefing is to inform personnel how to protect NATO information in the event they come across it while on the SIPRNET. The Prime contractor must receive approval from the KO to grant NATO access to a subcontractor.
__ 10h. Foreign Government Information (FGI): This is classified information that is provided to the U.S. Government by a foreign government(s); an international organization, or any element thereof. This does not include NATO information.
Mark “YES” if applicable. The prime contractor must receive approval from the KO to grant access to a subcontractor. Foreign Government Information (FGI) is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. Written concurrence of the KO is required prior to subcontracting.
__ 10i. Limited Dissemination Information (LDI). This is no longer a valid program and you should not have any new documents or contracts reflecting this caveat.
_X_ Item 10j. “For Official Use Only” (FOUO): The "For Official Use Only" (FOUO) marking is assigned to information at the time of its creation in a DoD User Agency. It is not authorized as a substitute for a security classification marking but is used on official government information that may be withheld from the public under exemptions 2 through 9 of the Freedom of Information Act
(FOIA).
Other non-security markings, such as "Limited Official Use" and "Official Use Only" are used by non-DoD User Agencies for the same type of information and should be safeguarded and handled in accordance with instruction received from such agencies.
Use of the above markings does not mean that the information cannot be released to the public under FOIA, only that the Government must review the information prior to its release to determine whether a significant and legitimate government purpose is served by withholding the information or portions thereof.
MARKINGS: An unclassified document containing FOUO information will be marked "For Official Use Only" at the bottom of the front cover (if any), on the first page, on each page containing FOUO information, on the back page, and on the outside of the back cover (if any).
Within a classified document, an individual page that contains both FOUO and classified information will be marked at the top and bottom with the highest security classification of information appearing on the page. If an individual portion contains FOUO information but no classified information, the portion will be marked, "FOUO."
Any "'For Official Use Only" information released to a contractor by a DoD User Agency is required to be marked with the following statement prior to transfer.
“This document contains information EXEMPT FROM MANDATORY DISCLOSURE UNDER THE FOIA. Exemptions apply.”
Removal of the "For Official Use Only" marking can only be accomplished by the originator or other competent authority. When the "For Official Use Only" status is terminated, all known holders will be notified to the extent practical.
DISSEMINATION: Contractors may disseminate "For Official Use Only" information to their employees and subcontractors who have a need for the information in connection with a classified contract. Contractors must ensure employees and subcontractors are aware of the special handling instructions detailed below.
STORAGE: During working hours, "For Official Use Only" information shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During nonworking hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during nonworking hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after- hours protection or the material can be stored in locked receptacles such as file cabinets, desks, or bookcases.
TRANSMISSION: "For Official Use Only" information may be sent via first-class mail or parcel post. Bulky shipments may be sent by fourth-class mail. DoD components, officials of DoD components, and authorized DoD contractors, consultants, and grantees send FOUO information to each other to conduct official DoD business. Tell recipients the status of such information, and send the material in a way that prevents unauthorized public disclosure. Make sure documents that transmit FOUO material call attention to any FOUO attachments.
Normally, you may send FOUO records over facsimile equipment. To prevent unauthorized disclosure, consider attaching special cover sheets, the location of sending and receiving machines, and whether authorized personnel are around to receive FOUO information. FOUO information may be passed to officials in other departments and agencies of the executive and judicial branches to fulfill a government function. Mark the records "For Official Use Only" and tell the recipient the information is exempt from public disclosure under the FOIA and requires special handling.
DISPOSITION: When no longer needed, FOUO information must be shredded.
UNAUTHORIZED DISCLOSURE: Unauthorized disclosure of "For Official Use Only" information does not constitute a security violation but the releasing agency should be informed of any unauthorized disclosure. The unauthorized disclosure of FOUO information protected by the Privacy Act may result in criminal sanctions and disciplinary action may be taken against those responsible
_X_ 10k. Other:
__ Other:__________________________________________
_X_ Secret Internet Protocol Network (SIPRNET) access required. The contractor shall not access, download or further disseminate any special access data (i.e. intelligence, NATO, COMSEC, etc.) outside the execution of the defined contract requirements and without the guidance and written permission of the KO. In the event that any special access is required, the KO must modify the requirements for the DD Form 254. Note: Once the KO has modified the requirements for the DD Form 254, the Contractor must complete the SIPRNET Access Request Form, along with the modified DD Form 254, and forward to the KO prior to receiving access. A NATO awareness brief will also be required for all Contractors prior to access to the SIPRNET. Notify the Security office (RDRL- LOI-S) Industrial Security when contractors assigned to/and working at ARL once approval has been requested/granted.
_X_ 11a. Have access to classified information only at another contractor’s facility or at a government activity. “ONLY” is the key word. Mark “YES” when access or storage of classified information is not required at the contractor’s facility. If marked “YES” , Item 1b should be marked “N/A” or “None.” When this item is marked YES, block 8a must identify the actual work location and if applicable block 8b and 8c must also be completed.
If 11a is “YES”, then 11b, 11c and, 11d, 11h and 11k will be “NO” – they are mutually exclusive. This question is about the safeguarding capability at the contractor facility. If no work is done at the contractor facility then they will not be receiving, generating, or fabricating anything classified at that location.
Contractor performance is restricted to (enter name and address of contractor facility or government activity). Government agency or activity will provide security classification guidance for performance of this contract. Submit visit request to the KO and/or Security Management Office for need-to-know verification.
__ 11b. Receive classified documents only: The contractor will receive classified documents, (instead of classification guides), to perform on the contract, but is not expected to generate classified information. The classification markings shown on the documents received will provide the classification guidance necessary. If the volume or configuration of the documents is such that specialized storage requirements are necessary, contact DSS to verify storage capacity at the contracting facility. If this item is marked “YES”, items 11a, 11c and 11d must be marked “NO”. If material is received and or stored at the contractor site for reference purposes only but the work is done on a government site or other cleared facility site, mark “YES”. This item applies if there is no generation of classified materials (i.e. derivative classification). Contractor will receive classified documents for reference only; however, if any classified information is generated in performance of this contract, it shall be derivatively classified and marked consistent with the source material.
__ 11c. Receive and generate classified information: Mark “YES” when the contractor is expected to receive and generate classified material at the contractors’ facility (documents and/or hardware) and will require detailed security classification guidance in order to perform on the contract. If this item is marked “YES,” detailed security classification guidance must be provided. The contractor will be required to have safeguarding capability at its facility and the level of safeguarding required must be identified in item 1b. the contractor requires access to classified source data up to and including (Top Secret, Secret, Confidential – insert one) in support of the work effort. Any extracts or use of such data requires the contractor to apply derivative classifications and markings consistent with the source documents. Use of “Multiple Sources” on the “Derived From” line necessitates compliance with the NISPOM, paragraph 4- 208a, and the use of a bibliography. Information generated in the performance of this contract action will be classified in accordance with:
__ The following security classification guides (SCG): (Title, Date)
__ Security Classification Guidance provided at performance location.
__ Source documents/materials
__ 11d. Fabricate, modify, or store classified hardware: Mark “YES” if the contractor is expected to generate or utilize hardware which is classified due to its existence, uniqueness, appearance, application, capability, or product produced. Include as much information as possible (additional information can be added in Item 13) to describe the nature and extent of the storage that will be required.
Will Restricted or Closed Areas be required? Yes/No Is hardware involved? Yes/No. How much ____________. How large is the hardware and can it be stored or will Open Storage be required?
If item 11d is “YES”, items 11a, 11b and 11e must be marked “NO”. If more than 2 cubic feet of storage is required, contact DSS to verify storage capacity at the contracting facility. Contractor must provide adequate storage at their facility for classified hardware to the level of (enter one: Top Secret, Secret, or Confidential).
__ 11e. Contractor is performing a service only and is not expected to produce a deliverable item. Explain the services provided and appropriate security guidance in block 13.
__ 11f. Have access to U.S. classified information outside the U.S., Puerto Rico, U.S. Possessions and Trust Territories: U.S. activity where the overseas performance will occur. City_____________/Country____________. If additional security requirements will be imposed on the contract, Item 14 must also be marked “YES” and completed as appropriate depending upon the programs involved.
__11g. Contractor will register with the Defense Technical Information Center (DTIC) using DD Form 1540, Registration of Scientific and Technical Information and DD Form 2345, Militarily Critical Technical Data Agreement if access to unclassified, militarily critical data from other DoD sources is required. The sponsoring KO must submit DD Form 1540 “Registration for Scientific and Technical Information Services” to DTIC on behalf of the contractor. For subcontractors, the prime contractor submits the DD Form 1540 with the KO verifying the need-to-know.
__ 11h. Mark this item “YES” if the contractor is to be held accountable for COMSEC information. If non-accountable COMSEC information is involved, mark this item “NO.”
1.__ COMSEC material on hand, but account not required (complete block 2)
__STE __Facsimile __ Other
2. __ COMSEC support provided by:_______________________
3. __ Secure telephone or facsimile will be used for all classified communications.
4. __ Secure telephone, facsimile, encrypted e-mail or U.S. Postal Service is required and will be used for all controlled unclassified information (CUI) (FOUO), Export Controlled, Critical Program Information (CPI) transmissions.
__11i. Mark “YES” if the contractor is required to impose TEMPEST countermeasures for information processing equipment after vulnerability assessments are completed. TEMPEST requirements are additional to the requirements of the NISPOM. The prime contractors may not impose TEMPEST requirements on their subcontractors without the KO approval. If marked “YES,” Item 14 must also be marked “YES” and pertinent contract clauses identified or added to Item 13. If requested by the KO, TEMPEST Countermeasure Assessment Requests may be included as an attachment to the DD Form 254.
TEMPEST - Electronic and electromechanical telecommunications and automated information processing equipment can produce unintentional, intelligence-bearing emanations, commonly known as TEMPEST. If intercepted and analyzed, these emanations may disclose information transmitted, received, handled or otherwise processed by the equipment. TEMPEST Information is not releasable to contractor employees who have not received a FINAL Clearance at the appropriate security level. Written concurrence of the KO is required prior to subcontracting.
_X_ 11j. Operations Security (OPSEC) Requirements: Mark “YES” if the contractor must impose certain countermeasures directed to protect intelligence indicators. OPSEC requirements are additional to the requirements of the NISPOM. The prime contractors may not impose OPSEC requirements on their subcontractors unless the KO approves the OPSEC requirements. If marked “YES,” Item 14 must also be marked “YES” and pertinent contract clauses identified or added to Item 13.
Mark the applicable block below.
__ Contractor will comply with/implement OPSEC policies and procedures provided at the contract performance location.
_X_ Contractor will comply with ARL OPSEC Plan, policies and procedures to be provided by the COR.
__ 11k. The KO must obtain written approval from the Commander, Defense Courier Service, Attn: Operations Division, Fort George G. Meade, MD. 20755- 5370. Only certain classified information qualifies for shipment by DCS. Prior approval of the KO is required before a prime contractor can authorize a subcontractor to use the services of DCS. If the contractor is receiving materials through DCS then 1b should be marked “YES” to the appropriate safeguarding level (TS, S, or C). If this is marked “NO” then using DCS is not an option for the contractor.
__ 11l. Other. Use of Automated Information Systems (AIS) as approved by the Defense Security Service.
__ 12. The contractor is responsible for obtaining the approval of the contracting activity prior to release of any information received or generated under the contract, except for certain types of information authorized by the NISPOM.
13. Use this block to expand or explain information marked “Yes” in blocks 10 and 11 of the DD Form 254. If the information does not fit into Block 13, annotate “See Attached Addendum” and provide all additional information accordingly
13. US Army Research Laboratory (ARL), in conjunction with the program sponsor shall exercise final authority concerning classification matters not directed or resolved in DD Forms 254 and/or referenced.
Unclassified limited documents (e.g. FOUO, Distribution statement controlled) are not authorized for public release; therefore, they cannot be posted on a publicly accessible web server or transmitted over the internet unless appropriately encrypted. Request for public release cannot be transmitted via the internet until the contractor receives final approval from ARL, OPSEC Plans must comply with OPSEC instructions of the sponsoring activity.
Individual tasks placed under this contract may require access to prescribed information (e.g., intelligence), specific classification guidance and security requirements for these tasks will be indentified on a separate DD Form 254 at the time tasks are awarded through delivery orders.
_X_13. The name, telephone number, email address and mailing address of the COR is:Tracy Talsma, PHONE (410) 278-0705, E-MAIL tracy.l.talsma.civ@mail.mil. The FSO (prime contractor) is TBD, PHONE TBD E-MAIL TBD. Contract End Date: TBD
Is the FSO fully trained? TBD.
Is there a Technology Control Plan available? _TBD.
The FSO is responsible for initial and refresher security briefings and debriefings.
_X_13. Suspicious Contacts. Contractors shall report efforts by any individual, regardless of nationality, to obtain illegal or unauthorized access to classified information or to compromise a cleared employee.
__13. Training. All employees working on-site will attend/complete annual counterintelligence, OPSEC, and security awareness refresher training provided by the ARL Security/Counterintelligence Office, Adelphi, MD.
_X_ 13. A copy of DD Form 254 for all subcontracts shall be provided to ARL, ATTN: RDRL-LOI-S (Industrial Security) 2800 Powder Mill Road, Adelphi, MD 20783.
__ 13. Foreign National Access. Foreign nationals will not be assigned to work on or otherwise given access to contract information.
__ 13. Foreign National Access. Foreign national participation/access to contract information is limited to public release information. Foreign nationals will not be assigned to work on nor given access to contract information without the written concurrence of the U.S. Army Research Laboratory Foreign Disclosure Officer (FDO) Forward request for access to the Army Research Laboratory, ATTN:
RDRL-LOI-F (FDO), 2800 Powder Mill Road, Adelphi, MD 20783-1138 so as to arrive not later than 10 working days prior to date access is required. The request will contain the following information:
Subject’s name:
Citizenship:
Type of visa:
Visa Expiration date:
Individual’s field of expertise:
What they will contribute to the contact work:
__ 13. Subcontractor foreign national participation. Subcontractor requests for foreign national participation will be submitted through the prime contractor to the ARL Foreign Disclosure Officer as stated in item 14 below.
__ 13. Foreign Government/Contractor Participation. The participation of foreign governments/contractors as either prime or subcontractor is not authorized.
__ 13. Foreign national security briefings. Prior to being given access to contract information foreign nationals will be briefed on the security policies and procedures with which they will comply. These briefings will be made a matter of record and retained for two years.
__13. Foreign travel. Prior to foreign travel in the performance of this contact, contractor employees will be briefed on the intelligence, industrial and technical threat. Travelers will receive counterintelligence debriefing upon their return.
The contractor FSO, 902d Military Intelligence Group, ARL Security and Counterintelligence Office or other competent authority, may conduct briefings/debriefings. A record of these briefings will be made a matter of record, which will be maintained for a period of 2 years.
__14. Additional Security Requirements:
__ 15. Information should be provided regarding the specific areas from which the CSO is excluded and the agency that will assume the responsibility.
16. Certification and Signature.
__17f.
_X_ Army Research Laboratory
ATTN: RDL-LOI-S
2800 Powder Mill Road, Adelphi, MD 20783-1138
File details come from the government source that posted it. Updated .