Attachment_3.doc

DOC document 55 KB Posted

Attached to
Coatings Application at CCAD, TX Federal contract opportunity
Solicitation number
W9132T-15-T-0044
Issued by
Department of the Army Corps of Engineers Engineer Research and Development Center

About this file

Attachment 3

View the file

Other files for this federal contract opportunity

Other files attached to Coatings Application at CCAD, TX, newest first.
File Type Posted
Questions_and_Answers.docx DOCX document
Attachment_1.pdf PDF
Attachment_5.pdf PDF
Attachment_3.doc DOC document
Attachment_2.pdf PDF
A22_RFQ.doc DOC document
Attachment_4.pdf PDF
Attachment_5.pdf PDF
A22_RFQ.doc DOC document
Attachment_1.pdf PDF
Attachment_4.pdf PDF
Attachment_2.pdf PDF
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CAO: March 2014

SECURITY REQUIREMENTS FOR ALL CONTRACTS

PERFORMED AT CORPUS CHRISTI ARMY DEPOT

Place these security requirements in all Statement of Works (SOW’s) and Performance Work Statements (PWS’s) for contracts performed at Corpus Christi Army Depot (CCAD).

This document is a brief overview of rules and regulations of Naval Air Station Corpus Christi (NASCC) and

Corpus Christi Army Depot (CCAD). It is not intended to be all-inclusive or cover all contingencies. Direct specific security requirements questions to the following numbers:

CCAD: (361) 961-3313

NASCC: (361) 961-2480

Regulations:

Army Directive 2014-05 (or its successor) Policy and Implementation Procedures for Common Access Card

Credentialing and Installation Access for Uncleared Contractors

AR 25–1, Army Knowledge Management and Information Technology

AR 25–2, Information Assurance

AR 25–55, The Department of the Army Freedom of Information Act

AR 70–31, Standards for Technical Reporting

AR 190-13, Department of the Army Physical Security Program

AR 360–1, The Army Public Affairs Program

AR 380–5, Department of the Army Information Security Program

AR 380-10, Foreign Disclosure and Contact with Foreign Representatives

AR 380-49, Industrial Security Program

AR 380-67, Personnel Security (PERSEC)

AR 530-1, Operations Security (OPSEC)

AR 530-1, AMC Supp Operations Security (OPSEC)

AR 530-1, CCAD Plan Operations Security (OPSEC)

AMC-R 525-13, AMC Force Protection Program

DoD 5220.22-M National Industrial Security Program Operating Manual

DOD Directives 5230.24, Distribution Statements on Technical Documents

DOD Directives 5230.25, Withholding of Unclassified Technical Data from Public Disclosure

DoD Regulation 5200.2-R Personnel Security Program

DoD 5400.11-R, Department of Defense Privacy Program

UFC 4-010-01 9 February 2012 Change 1, 1 October 2013 DoD MINIMUM ANTITERRORISM STANDARDS

FOR BUILDINGS UNIFIED FACILITIES CRITERIA (UFC)

1. Conduct and Behavior: IAW DoD Directive 5200.8, “Security of DoD Installations and Resources”, the NAS commander has broad authority to remove or exclude any person or persons from the military installation to protect personnel and property, to maintain good order and discipline, and to ensure the uninterrupted and successful performance of the installations mission. In the exercise of this authority, the commander may refuse to grant entry or may bar Contractor employees. Refusal of entry or barment of any employee does not relieve the Contractor of the responsibility to continue performance under this contract.

1.1. All personnel entering and working at CCAD are subject to all rules, regulations and applicable laws. All personnel and their effects are subject to search, to include vehicles and company belongings.

1.2. No person shall willfully fail or refuse to comply with lawful orders or direction of any civilian or military security police officer.

1.3. The Contractor shall not employ persons for work on this contract if such employees are identified to the

Contractor by the Government as a potential threat to the health, safety, security, general well being or operational mission of the installation and its population. Disrespectful behavior, failure to obey orders or regulations, fighting, horseplay, stealing, illegal use of drugs (using/transporting/selling), consuming or being under the influence of alcohol, or being in the possession of illegal weapons are prohibited and subject to appropriate penalties. This may include being detained, banned from entering the Government facility, or remanded to civilian authorities.

1.4. All Contractor personnel will limit their travel on the installation only to specific areas required for performance of the contract, specified break and meal areas, or in travel directly to and from these locations.

Employees found on the installation away from officially identified areas may be detained and/or debarred from the installation.

1.5. Subcontracts; if the Contractor enters into a Subcontractor arrangement with another Contractor, the prime

Contractor is responsible for Subcontractor performance and compliance.

The prime Contractor must provide a copy of the security requirements to the subcontractor. The contracting officer must ensure any questions of adequacy of the Subcontractor are resolved to the mutual satisfaction of the prime

Contractor, Subcontractor, security, and CCAD commander.

1.6. All prospective government and contractor employees are subject to a check of their criminal history prior to being granted access to CCAD. Adverse or derogatory information revealed by these checks, or failure to provide full disclosure, may result in denial of access.

2. Support:

2.1. Security support provided by CCAD to the Contractor includes (if applicable) storage containers for classified information/material, use of base destruction facilities, classified reproduction facilities, use of base classified mail services, security badging, investigation of security incidents, base traffic regulations, use of security forms, and conducting inspections required by DoD 5220.22-R “Industrial Security Regulation”, Army Instruction 380-49

“Industrial Security Program”, AR 380-5 “Department of Army Information Security Program”, and AR 25-2

“Information Assurance” and others as required or deemed necessary by the Government.

2.2. Security support requiring joint Army and Contractor coordination includes packaging classified information, mailing and receiving classified materials, implementing emergency procedures for protection of classified information, security checks, and internal security controls for protection of classified material, sensitive material, and high value pilferable property.

3. Security Investigation Requirements: (As Applicable)

3.1. Contractors must maintain the same level investigation or higher as their civilian counterparts. In the absence of a civilian counterpart, CCAD Security will determine the level of investigation based on a position sensitivity review. Close coordination with the COR and company are required. All documentation required for access to

CCAD for classified contracts or IT Level I & II shall be processed through the CCAD Security Personnel Security

Office prior to entering CCAD facilities.

3.2. Classified Contracts: An interim clearance must be in place prior to entering CCAD facilities. All documentation (i.e. SF 86, etc.) required for security clearance shall be processed through the Contractor Facility

Security Office (FSO).

3.2.1 For all contracts involving employees who require a security clearance for performance of their duties or access to classified material, the Contractor must possess or obtain a facility security clearance prior to performing contract work. If the Contractor does not possess a facility clearance, the Government (Contracting Office) may request one from the Defense Security Service (DSS).

3.2.2. Contractor employees without a clearance level or background check properly indicated in the Joint

Personnel Adjudication System (JPAS) or its successor, will not be assigned to this task directly or indirectly.

Contractor employee(s) will not be authorized access, regardless of personal clearance, without the facility first being cleared to the appropriate level by Defense Security Service (DSS).

3.3.1. The Contractor shall request security clearances for personnel requiring access to classified information or IT

Level I or II within 15 days after receiving a facility clearance. If the Contractor is already cleared, they shall request security clearances for the personnel within 15 days after contract award. Due to costs involved with security investigations, requests for Contractor employee security clearances shall be kept to an absolute minimum necessary to perform contract requirements.

3.3.1.1 IT Level I positions; Contractor employees shall have one of the following prior to commencing work: A current, valid Single Scope Background Investigation (SSBI) or “Interim” Top Secret eligibility by Defense

Industrial Security Clearance Office (DISCO) indicated in JPAS.

3.3.1.2. IT Level II positions; Contractor employees shall have one of the following prior to commencing work: A favorably completed National Agency Check with Law and Credit (NACLC) background investigation or “Interim”

Secret eligibility by DISCO indicated in JPAS.

3.3.1.3. IT Level III positions: Contractor employees shall have one of the following prior to commencing work: A favorably completed National Agency Check with Law and Credit (NACLC) background or “Interim” Secret eligibility by DISCO indicated in JPAS.

3.4. Unclassified Contracts requiring IT access: All documentation (i.e. SF 85P, etc.) required for their initial security appointment for unclassified contracts to IT Level III shall be processed through the CCAD Security

Personnel Security Office prior to entering CCAD facilities.

3.4.1. IT Level III positions; Contractor employees requiring access to CCAD Local Area Network (LAN) shall have background investigation processed through CCAD Personnel Security Office. If the Contractor employee does not possess the proper investigation, the Government (Contracting Officer Representative) will request one.

The Government assumes costs and initiates the investigation by submitting the appropriate Personnel Security

Investigation request to the Army Center of Excellence. Minimum requirements for CAC issuance and access to the

LAN is an initiated investigation with favorable FBI fingerprint check. Due to costs and the inherent delays involved with security investigations, requests for Contractor LAN access shall be kept to an absolute minimum necessary to perform contract requirements.

3.5. Fitness Issues:

3.5.1. The Contracting Officer Representative (COR) and CCAD Security will be notified when discovery of adverse information indicates potentially actionable issues which may disqualify the Contractor employee from access.

3.5.2. OPM Memorandum, Final Credentialing Standards for Issuing Personal Identity Verification Cards under

HSPD-12 provides government-wide credentialing standards to be used by all Federal departments and agencies in determining whether to issue or revoke personal identity verification (PIV) cards to employees and contractor personnel.

3.5.3. Whether or not to grant access is the sole discretion of the Government. The decision not to grant access will not be grounds for contract modification and shall not constitute an excuse for Contractor performance failure.

3.6. System Authorization Access Request (SAAR): Prior to system access, a SAAR, DD Form 2875, System

Authorization Action Requirement, shall be completed by the Contractor employee The Contractor employee shall complete Part I, the COR shall complete Part II, and CCAD Personnel Security shall complete Part III.

Unclassified Contracts NOT requiring IT access: Contracts not requiring access to CCAD LAN shall be subject to installation access requirements that include Rapid Gate and/or guest sponsorship. The COR shall provide the appropriate details and contact information.

4. IT/IA Requirements:

4. 1. All contract employees with access to the CCAD network must be registered in the Army Training

Certification Tracking System (ATCTS) at commencement of services. Contractors and associated subcontractor employees must also complete DoD IA Awareness Training before they can be granted access to the CCAD network and complete the training annually thereafter.

4.2. All contractors working IA/IT functions must comply with DoD and Army training requirements in DoDD

8570.01, DoD 8570.01-M, and AR 25-2 within 6 months of employment.

4.3. Per DoD 8570.01-M, DFARS 252.239.7001, and AR 25-2, the contractor employees’ supporting IA/IT functions shall be appropriately certified upon contract award. The baseline certification, as stipulated in DoD

8570.01-M, must be completed upon contract award.

5. Foreign Nationals:

5.1. Official Visits: All official foreign visits (visits sponsored by a foreign government) must be based on a legitimate need , be sanctioned by the appropriate foreign attaché or embassy, and approved through Department of

Army channels. Access will be coordinated through the CCAD Foreign Disclosure Officer (FDO), COR, and respective NASCC/CCAD security offices.

5.2. Unofficial Visits: These are visits by foreign nationals that are not endorsed by a foreign government. The

Contractor will submit a request for employee access, based on a legitimate need, to the appropriate COR. The

COR will in turn notify the FDO of the request. Due to security considerations, requests for these types of visits should be kept to a minimum. Foreign nationals will require a government escort at all times while on CCAD property. The COR will ensure the foreign contractor employee provides a copy of their passport to NASCC and

CCAD security offices, to ensure the appropriate background checks are completed. NOTE: Properly validated permanent resident alien registration card holders are exempt from this requirement.

6. Notifications: The following information will be submitted to the COR and the CCAD Security Manager on company letterhead, signed by the Contractor Facility Security Officer (FSO) within 15 days of awarding the contract. An updated listing shall be provided quarterly or when the company or an employee’s status or information changes. Electronic equivalents are acceptable. The notification shall include:

a. Name, address, and telephone number of company representatives.

b. Employee's name, last four of social security number, shift

c. The contract number and contracting agency.

d. The highest level of classified information to which Contractor employees require access.

e. The location(s) of contract performance.

f. The date contract performance begins and terminates.

7. Security Point of Contact: At no cost to the Government, the Contractor shall appoint a senior Contractor employee to serve as an on-site point of contact for any security concerns at the CCAD location. This may be a full time position or an additional duty position.

8. Security Training:

8.1. All contractor employees, including subcontractor employees, requiring access to Army installations, facilities, or controlled access areas shall complete AT Level I awareness training within 30 calendar days after contract start date or effective date of incorporation of this requirement into the contract, whichever applies. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee to the COR (or to the contracting officer, if a COR is not assigned) within 30 calendar days after completion of training by all employees and subcontractor personnel. AT Level I awareness training is available at https://atlevel1.dtic.mil/at.

8.2. US-based contractor and subcontractor employees who are required to travel overseas in performance of their duties must receive government provided AT awareness training that is specific to the area of responsibility (AOR), as directed by AR 525-13. Specific AOR training content will be directed by the combatant commander and the unit

ATO will ensure an applicable AT foreign travel briefing is provided to the contractor.

8.3. The contractor and all associated subcontractors shall brief all employees on the local iWATCH program. This is a locally developed training is provided by CCAD security and will be used to inform employees of the types of suspicious behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 30 calendar days of contract award and within 30 calendar days of new employees’ commencing performance, with the results reported to the COR no later than 30 days after training completion.

8.4. Those contractors who require a CAC Card and access to the CCAD network, they contractor must develop an

OPSEC Standard Operating Procedure (SOP)/Plan within 90 days of contract award, which will be reviewed by the

CCAD OPSEC Officer for approval IAW AR 530-1, Operations Security. The SOP/Plan must identify CCAD’s critical information, why it needs to be protected, where it is located, who’s responsible for it, and how to protect it.

8.5. IAW AR 530-1, new contractor and associated subcontractor employees who require a CAC Card and access to the CCAD network must complete Level I OPSEC training within 30 calendar days of reporting for duty. In addition, all contractor and associated subcontractors must complete annual OPSEC awareness training.

9. Pass and Identification Items: The Contractor shall obtain the pass and identification items for employees and

Contractor owned vehicles required for contract performance.

10. Retrieving Identification Media: The Contractor shall retrieve all identification media, including vehicle passes from employees who depart for any reason before the contract expires; e.g. terminated for cause, retirement, etc. and surrender to security or the COR as appropriate.

11. Weapons, Firearms, and Ammunition: Contractor employees are prohibited from possessing weapons, firearms, or ammunition, on themselves or within their Contractor-owned vehicle or privately-owned vehicle while on CCAD.

12. Safeguarding Classified or Sensitive Information: Any material marked as Top Secret, Secret, Confidential, For Official Use Only (FOUO) Freedom of Information Act (FOIA), Privacy Act Information, or any other restrictively marked material discovered by the Contractor or Contractor employees will be surrendered at the earliest opportunity to any military or DoD employee of the installation. Under no circumstances will the

Contractor retain such material. The Contractor and all Contractor employees will execute a SF 312, Classified

Information Non-Disclosure Agreement or equivalent CCAD Non-Disclosure Agreement as directed or required.

12.1. Classified: Visitor Groups will safeguard classified information IAW DoD 5200.1-R, DoD Information

Security Program, AR 380-5, Department of the Army Information Security Program, AR 380-49, Industrial

Security Program, and other directives deemed necessary by the Servicing Security Activity (SSA)

12.2. Information Systems (IS): All Contractor personnel will protect and restrict access to all documentation (i.e.

maps, test and evaluation results, vulnerability assessments, audits, results, or findings) describing operational IS architectures, designs, configurations, vulnerabilities, address listings, or user information.

12.3. FOR OFFICIAL USE ONLY (FOUO): The Contractor shall comply with DoD 5400.7-R, Chapter 4, DoD

Freedom of Information Act (FOIA) Program requirements and AR 25-55, Chapter III and Chapter IV, The

Department of the Army Freedom of Information Act Program. These regulations set forth policy and procedures for the disclosure of records to the public and for marking, handling, transmitting, and safeguarding FOUO material.

12.4. Privacy Act: All data associated with this task is covered by the Privacy Act of 1974, Title 5 of the U.S.

Code, Section 552a and applicable CCAD rules and regulations. Violation of the Act may involve the imposition of criminal penalties. Therefore, all Contractor personnel assigned shall take appropriate actions to prevent unauthorized disclosure of Privacy Act information.

12.5. Operation Security (OPSEC): Contractor personnel must protect information that has been designated as critical to the CCAD mission from disclosure. Critical information will only be disseminated on a “need-to-know” basis and not be discussed in public areas such as hallways, bathrooms, eateries, smoke shacks, or any off-base gathering locations. Contractor employees will not pass critical information over unsecured telephones, facsimiles, and/or e-mail outside of the CCAD firewall. Contractor employees will not post critical information on the web, personal “blogs,” or where it is visible to visitors or the public.

12.6. Proprietary Information: Information and materials developed at CCAD are considered business sensitive and must be protected from unauthorized disclosure. This information is the sole property of CCAD and must not be revealed or used except in contract performance. Distribution is limited to authorized US Government agencies and identified Contractors. Contractor personnel must receive prior authorization from the CCAD Public Affairs

Officer (PAO) to disseminate CCAD information.

13. Reporting Requirements: Contractor personnel shall report to an appropriate authority any information or circumstances of which they are aware may pose a threat to the security of personnel, resources, and classified or unclassified defense information. Contractor employees shall be briefed by their immediate supervisor upon initial on-base assignment.

14. Physical Security: The Contractor shall be responsible for safeguarding all Government property and controlled forms provided for Contractor use. At the end of each work period, all Government facilities, equipment, and materials shall be secured.

15. Key Control: The Contractor shall establish and implement methods of making sure all keys issued to the

Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. The Contractor shall not duplicate any keys issued by the Government.

15.1. The Contractor shall immediately report to security, the Quality Assurance Evaluator (QAE), and Program

Manager any occurrences of lost or duplicated keys.

15.2"In the event keys, other than master keys, are lost or duplicated, the Contractor may be required, upon written direction of the Government, to pay for total cost of service to replace the affected lock or locks or perform rekeying by deducting the cost of such assistance conducted by the Government, from payment due to the Contractor.

In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the

Government and the total cost deducted from payment due the Contractor."

15.3. The Contractor shall prohibit the use of keys, issued by the Government, by any persons other than the

Contractor’s employees and the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in performance of contract work requirements in those areas.

16. Lock Combinations: The Contractor shall control access to all Government provided lock combinations to preclude unauthorized entry. The Contractor is not authorized to change lock combinations without written approval by the Government Program Manager. Records with written combinations to authorized secure storage containers, secure storage rooms, or certified vaults, shall be marked and safeguarded at the highest classification level as the classified or sensitive material maintained inside the approved containers or room.

17. Other Responsibilities:

17.1. Traffic Rules and Regulations: All personnel will abide by all traffic and parking rules and regulations.

Failure to abide may result in issuance of Government citations.

17.1.2. Permission to park company support vehicles within the perimeters of the job must be approved in advance by the COR and Security. Company support vehicles must have company identification.

17.2. Identification: CCAD requires Contractor personnel wear a Government issued identification badge provided by CCAD, NAS, or their representatives . Safety restrictions may require the pass to be removed while working, but it must be worn in plain view, above the waist, when away from the job site. Failure to do so is a violation of security regulations and may result in disciplinary action.

17.3. Visitors: Contractor personnel must clear all visitors in advance through the COR. This includes Contractor personnel and personal guests. All foreign national visitors will be identified to the appropriate authorities, be based on a legitimate need, and are only allowed at the discretion of the installation commander.

17.4. Photography: All photographic or video equipment must be cleared in advance through the COR and personnel must be issued a Camera Pass from PAO.

17.4.1. Photographs, video, drawings, blueprints, or any other type of rendering or measurements unrelated to contract performance of sensitive areas, such as critical resources, controlled or restricted areas, or other areas deemed sensitive by the Government is strictly prohibited. The Government reserves the right to seize equipment used for unauthorized purposes and the employee and/or Contractor may be debarred from the base, detained, reported and/or remanded to civilian authorities, or have other sanctions placed against them.

17.4.2. Transfer of digitized or electronic photographs, video, drawings, blueprints, or any other type of rendering or measurements must be coordinated/requested through the CCAD information assurance office.

17.5. Weekends /After Duty Hours: Notice of weekend/after duty hours scheduled work must be submitted to

Security through the COR. Personnel working weekend or after duty hours must check in and out with Security

Building access support to job sites must be arranged with the COR. Keys to areas are obtained by the COR.

Requesting areas to be unlocked by personnel other than contract representatives is not authorized.

17.6. Barricades/Construction Areas:

17.6.1. Designating construction areas is Contractor’s responsibility and must be coordinated in advance through the COR, Safety, CCAD Fire Marshall, and CCAD Security. Work (construction) areas will be secured at the end of each day. All doors and windows must be closed and locked, and lights and electrical equipment turned off.

17.6.2. All Contractor property locks and keys must be properly secured. The Government is not responsible for personal property left unattended or unsecured.

17.6.3. CCAD Security is to be notified of all emergencies, accidents, disturbances, etc. (as soon after the event as is reasonably possible) or requests for Security related assistance. CCAD Security will make the appropriate calls for proper authorities.

17.6.4. All personnel will abide by all applicable safety procedures and responsibilities. Smoking in areas other than authorized areas located throughout the Depot is prohibited.

17.6.5. Opening or blocking doors, entering non-job related areas without permission or clearance, or removing tools or other Government equipment without proper permission is not permitted. Government buildings and property will not be left unattended and unsecured.

File details come from the government source that posted it. Updated .