ATTACHMENT 5 - DD254 Attachment One and Two - Amendment 0001.pdf
PDF 64 KB Posted
- Attached to
- Aberdeen Test Center- Scientific and Engineering Support Federal contract opportunity
- Solicitation number
- W91CRB-20-R-0019
About this file
This document package includes a DD254 security classification specification and details of a federal contract opportunity for scientific and engineering support services. The resulting single-award IDIQ contract will have a five-year ordering period and include both CPFF and FFP line items. Services will involve mechanical, electrical, software, systems engineering, and testing facilities support. The small business set-aside opportunity is issued by Army Contracting Command - Aberdeen Proving Ground on behalf of Aberdeen Test Center. Proposals are due by 4PM EST on May 29, 2020 and shall be emailed to the address provided. The scope of work involves development, fabrication, configuration and production of instrumentation systems across various areas such as mechanical equipment, electrical systems, software, and testing facilities.
View the file
Other files for this federal contract opportunity
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT ONE (Continuation of Block 13 of the DD Form 254 for Contract To Be Determined)
13. Security Guidance.
Item 11a. Contractor performance is primarily restricted to Aberdeen Proving Ground, Maryland, 21005. However, contractor performance may require travel to sites other than APG for training or work related duties at another government facility. The contractor shall have personnel available and ready to travel on the required date. The contractor shall use the personnel that are already supporting ATC’s mission at APG. There will not be access to classified information at the contractor’s facility. Therefore, the contractor will not be required to have any safeguarding capability at their facility. All access to classified information will be at a Government Activity or another contractor’s facility should a contract employee need to accompany a government employee away from APG.
Item 11j. The contract requires planning for and application of OPSEC in accordance with Army Regulation 530-1, Operations Security (OPSEC) and the contract clauses and statement of work. The ATC Security Manager shall advise the contractor of ATC’s Critical Information (CI), why it needs to be protected, where it is located, who is responsible for it and how to protect it. OPSEC guidance will also be provided as applicable for each project or program affected by this support.
ATTACHMENT TWO (Continuation of Block 14 of the DD Form 254 for Contract To Be Determined)
14. Additional Security Requirements.
Facility Clearance. The contractor shall possess a SECRET facility clearance at the time this contract is awarded. Verification by the ATC S2 shall be made to the Defense Security Service (DSS) using the National Industrial Security Program (NISP) Central Access Information Security System (NCAISS).
Personnel Security Clearances. All contract employees working under this contract shall possess a final SECRET clearance at the time this contract is awarded. Every cleared contract employee will receive a security indoctrination briefing. The briefing will be conducted within 30 days of issuance of a security clearance. The briefing will at a minimum include the following topics: general security education, OPSEC awareness, Information Systems Security, Force Protection, and training on the Threat Awareness Reporting Program (TARP). The training will also provide any additional security training that may be job specific. The contractor will notify the government in writing when this initial security training has been completed. A visit request must be submitted via Joint Personnel Adjudications Systems (JPAS) to the ATC SMO code of W4QUAA by the Facility Security Officer (FSO) or Alternate FSO.
At the conclusion of this contract, the FSO or Alternate FSO, will submit a termination letter to the ATC Visitor Desk and a copy sent to the ATC Industrial Security Specialist. Contract personnel whose security clearances are suspended shall not be permitted to work under this contract until their security clearance is reinstated.
Reports of Adverse Information.
If a contract employee becomes involved in any type of adverse information while supporting this contract, the ATC Security Manager will be notified immediately so that a decision can be made whether the employee will continue to have unescorted access into the Restricted Area and whether they will continue to have access to a government owned computer system. Contract personnel whose security clearances are suspended shall not be permitted to work under this contract until their security clearance is reinstated. The contractor shall report to the ATC Security Manager all adverse information on contractor personnel such as security violations, arrests, bankruptcy, wage garnishments and denial, suspension, or revocation of security clearances. The ATC Security Manager may deny employees’ access into APG restricted areas based upon the adverse information.
Information Systems (IS) Access. The contractor shall designate Information Technology (IT) positions for all personnel requiring access to IS in accordance with Army Regulation 25-2, Army Cybersecurity, Army Regulation 25-1, Army Knowledge Management and Information Technology Management, Army Regulation 380-67, Department of the Army Personnel Security Program and Army Regulation 380-5, Department of the Army Information Security Program.
All positions on this contract are designated IT 3. The contractor shall request the appropriate personnel security investigation based upon the IT position designation. The investigation must be favorably completed prior to employees being permitted access to IS and being placed in an
IT position. The contractor shall prepare a list identifying the IT position designations and submit to the ATC Information Systems Security Manager (ISSM) and ATC Security Manager.
In accordance with Army Regulation 25-1, all employees requesting access to an IS shall be required to sign an Acceptable Use Policy (AUP) and adhere to the policies outlined in the document regarding acceptable use of Government-owned computer systems and networks.
This document will be reviewed and signed annually thereafter. Also, prior to gaining access to a government computer system, all employees must take initial Cyber Awareness Training and annually thereafter. This is mandatory on line training which will be completed by scheduling an appointment with the ATC Cybersecurity Office. All Army IS will be used for OFFICIAL business only. Using Army IS to retransmit jokes, access pornographic, chain letters, game, militia or similar sites is strictly prohibited, Access to chat rooms (except AKO chat), use of commercial email addresses to send or receive DoD information, and use of Army IS to download shareware is also strictly prohibited. The contractor shall ensure that all IS used by contractor personnel are protected and accredited in accordance with Army Regulation 25-2 and related supporting directives and AUP guidance published by ATC. The contractor shall temporarily revert to manual mode when the required automation information systems are not available. Upon availability of the system or equipment, the contractor shall commence on-line input. Any DoD information processed on either Government furnished or contractor furnished computers belongs to the Government. During the Phase-In period, the Contractor shall complete a Request for Access (DD Form 2875 System Authorization Access Request) and Non- Disclosure Statement to ATC Computer Systems for the designated employees. This form shall be returned to the Government designee after completion.
Usage of Privately Owned Personal Electronic Devices (PEDs) Within the Restricted Area (RA). A privately owned personal electronic device (PED) is defined as a civilian multifunction cell phone, personal digital assistant, tablet, blackberry, personal wireless fitness devices (PWFD), digital inventory devices and electronic recording/storage devices. Contractor personnel shall not use the PED’s photographic/recording capability within the ATC Restricted Area (RA). The contractor shall not install or connect a privately owned PED to any government-owned computer or network system. Also, a PED that has the capability to store data cannot be connected to a government computer for purposes of charging the device’s battery. Contractor employees must use the appropriate wall adapter to charge a privately owned PED. Under no circumstances are contract employees permitted to take photographs with their personal cell phones or any type of recording device in the ATC Restricted Area. All PEDs (government or personal) are prohibited in any area that contains a Secure Internet Protocol Router Network (SIPRNET) connection; in any area or briefing room where classified material is being discussed; and in any area designated as a Special Access Program (SAP) area. PEDs are authorized for private, non-work related matters. Under no circumstances will a privately owned PED be used to transmit sensitive government information.
Installation Access. All contractor personnel will comply with the requirements of APG Regulation 190-4, Movement Control Within the Installation, for entry, exit and internal control of personnel, material and vehicles on APG. All vehicles and personnel are subject to search and seizure of contraband and/or unauthorized Government property in accordance with AR 190-13 (The Army Physical Security Program). To gain access to APG, DA Form 1602, Civilian Identification Card, shall be issued to contractors who do not require computer access or do not travel on official Government business upon written approval from the COR. Those contractors requiring access to government computers will be issued a Common Access Card (CAC).
Access into Restricted Areas. Most areas of ATC are within the restricted areas of APG.
Unescorted access will be permitted into the APG restricted area provided the contractor employee was issued a final SECRET clearance. If a contractor employee had a previously favorable Tier 3 security investigation or a final SECRET clearance with no more than 24 months of a break in service and there is no known adverse information, the contractor employee can have unescorted access.
Restricted Area (RA) Security Identification Credential.
Contractor personnel will be granted unescorted access provided the security clearance requirement stated above has been met. Once a written request (Credential Request Form and Access Credential Agreement) from the COR has been received and the investigation or security clearance has been verified by the visit request submitted via JPAS, the contractor employee will have their Department of Defense Common Access Card (CAC) programmed for unescorted access into the RA. At the same time the contract employee’s CAC is programmed, they will be issued an organizational credential to be used while in the RA. This credential identifies that the employee has an official need to be in the RA. If a contractor requires camera pass authority, their government point of contact must send an email to ATC Security justifying why the individual needs camera authorization in the RA. Once approved by ATC Security, a camera pass icon will be placed on the organizational credential upon completion of a Photographic Briefing and signature of the ATC Camera Pass Agreement. This icon authorizes the use of a government owned camera to capture for official use only images in the Restricted Area. All images will be reviewed by the ATC Operations Security (OPSEC) Officer prior to dissemination outside of ATC. At no time will a contractor be permitted to take any type of photographs, video or recording with their personal cellular or Smartphone while in the Restricted Area (RA). Contractor personnel shall wear their security credential above the waist at all times when in the restricted areas of APG with the following exceptions: (a) when photography is ongoing and the employee is likely to be in the photograph, and (b) when the employee is actually working with a piece of equipment that could catch the security credential and endanger the safety of the employee.
Photographic and Recording Permits. The Contractor shall obtain applicable permits to use government issued only photographic and recording equipment within APG restricted areas.
Contractor employees who must take photographs in the course of their official duties shall ensure that they have the camera icon on their security area picture badge. At no time will a contractor be permitted to take any type of photographs, video or recording with their personal cellular or Smartphone. All images/video captured in the restricted area are for official purposes only and must be OPSEC reviewed/approved prior to distribution. In order to take recording
ATTACHMENT TWO (Continuation of Block 14 of the DD Form 254 forContract To Be Determined) devices (other than personal cellular or Smartphone) into the restricted areas, the contractor employee must get written permission from the ATC Security Manager.
Common Access Card. All contractor employees who require computer access or travel on official Government business shall be issued a Department of Defense Common Access Card (CAC) through the Defense Enrollment Eligibility Reporting System (DEERS). CACs are processed in accordance with the guidelines for the Trusted Associate Sponsorship System (TASS). The contractor organization security manager gets the upcoming applicant vetted per requirements and forwards that information to the COR who is the Trusted Agent (TA) identified in the TASS. Once the TA receives the required information, it is entered into the TASS. The system generates an ID and new applicant password. The ID and password is forwarded to the applicant who will enter this information into TASS. The system will receive this information and it will notify the applicant with an approval email. Once the TA approves issuance of a CAC to the applicant through the TASS, the applicant can go to the nearest RAPIDS center with the proper identification and will be processed for a CAC which will be issued to them on the spot.
Foreign Nationals/Immigrant Aliens. Foreign nationals/immigrant aliens cannot be granted unescorted access to the restricted area, and shall not be scheduled to perform work under this contract. However, when foreign nationals/immigrant aliens visit ATC, the contractor shall comply with AR 380-10, Foreign Disclosure and Contacts with Foreign Representatives.
Safeguarding Government Information and Property. The contractor shall be responsible for Safeguarding all Government information and property provided for contractor use. The contractor shall safeguard information and material designated as classified, unclassified sensitive, Controlled Unclassified Information (CUI), Operations Security (OPSEC) sensitive, and Personally Identifiable Information (PII) in accordance with applicable directives stated in Item 13 (Security Guidance). The contractor will not release any work related information to the public without prior authorization. In addition, the contractor will not post any personal comments associating them with working for the federal government or any type of work related information on social media platforms. This includes discussion forums, blogging, etc.
Government-furnished property will be secured in accordance with AR 190-51, Security of Unclassified Army Property (Sensitive and Nonsensitive).
Loss or Possible Compromise of Classified Information. The contractor shall immediately report the loss or possible compromise of classified information or material to the ATC Security Manager or his designee in accordance with ATC Regulation 380-5, Information Security Program. In the event that there is a data spillage, the contractor will immediately notify their government supervisor, ATC Security Manager or his designee and the ATC ISSM.
Key Control. The contractor shall have access as needed to all Government-furnished facilities in accordance with Army Regulation 190-11, Physical Security of Arms, Ammunition and Explosives, Army Regulation 190-51, Security of Unclassified Army Property (Sensitive and
Nonsensitive), Army Regulation 380-5, Department of the Army Information Security Program and ATC Regulation 380-8, Security Key and Lock Control. The contractor shall develop and implement procedures to account for, control and safeguard metal and electronic keys and proximity cards received from the Government in accordance with above regulations.
Security Training. The contractor shall develop and implement a security education program to ensure contractor personnel understand and are familiar with security requirements. The contractor shall conduct security indoctrination for all new employees within 30 days after their arrival and refresher sessions annually thereafter. Upon completion of the security indoctrination, the contractor will have each employee sign the Standard Form (SF) 312 Classified Information Nondisclosure Agreement prior to granting access to classified information. The contractor will maintain the SF 312 on each employee and this document should be available to the government upon request. Contractor personnel may attend ATC’s annual refresher training; however, contractor personnel who are unable to attend the training shall receive the same training from contractor management. This training will include general security education, OPSEC awareness, Information Systems Security, Force Protection, and training on the Threat Awareness Reporting Program (TARP). Designated ATC Security personnel will conduct Anti-Terrorism/Force Protection training for contractor personnel traveling OCONUS. The FSO or the alternate FSO will provide through the COR a record of all contractor employees who have attended annual mandatory training by name and date of attendance to the ATC Security Manager.
iWATCH Training. All contractors who perform their tasks within an Army controlled installation, facility or area must be briefed on iWATCH procedures. The contractor and all associate sub-contractors shall brief all employees on the local iWATCH program (training standards provided by the requiring activity Anti-Terrorism Officer (ATO)). This locally developed training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 30 days of new employees commencing performance with the results reported to the COR upon completion of this training.
Disclosure of Proprietary and Intellectual Information. The contractor may be required to access data and information that is proprietary to another government agency, government contractor or of such a nature that its dissemination or use other than as specified would be adverse or contradictory to the government’s interest. The contractor and their employees shall not divulge or release data or information developed or obtained under this contract except to authorized government personnel or upon written approval from the Contracting Officer. The Contractor shall not use, disclose or reproduce proprietary data that bears a restrictive legend.
The Contractor shall obtain written permission of the originator prior to releasing any information. Under Title 18, Sections 793 and 798, the Contractor and the Contractor employees are liable for any improper release. The Contractor will direct all inquiries, comments, or complaints arising from matters observed, experienced, or learned as a result of, or in connection with the performance of this contract to the Contracting Officer. The resolution of which may require dissemination of official information. In this case, the Contracting Officer, upon a request from the contractor, will coordinate with the ATC Security Manager or designee for guidance. Inquiries the Contractor receives for information relative to the Freedom of Information Act (FOIA) shall be directed to the Contracting Officer, or COR for evaluation. The Government retains the authority to release or deny access to the information. The Contractor shall be responsible for search and submission of records under the Contractors control upon Government request. All work, including but not limited to intellectual property and data rights, produced under this contract is the sole property of the Government.
Departing Employees. The contractor shall ensure all contractor employees return photographic security identification badges and Common Access Cards/ Identification Cards and all permits issued by the Government at the completion of their employment. All issued keys/proximity cards will be returned prior to departure. The turn in of these items will be completed no later than 24 hours after their departure. The contractor will ensure that all contract employees receive a security debriefing upon their departure. Following the debriefing, the employee will sign the bottom portion of the SF 312. The contractor will ensure that all employees who maintain a hand receipt do not leave the installation until all items have been accounted for and all equipment under their control has been transferred to the new hand receipt holder. An employment/installation clearance procedure and checklist will be developed and implemented by the contractor to ensure that an employee has turned in all badges, Government property, and keys before leaving employment on the installation and access to the Local Area Network (LAN)/email has been cancelled. This checklist will contain a signature block for the ATC S2 to initial to ensure all contract employees have cleared all aspects of employment at ATC. Security badges will be returned to the ATC S2 on the employee’s last day of employment with the government. If departure is after normal business hours, the FSO will collect the badge on the last day of employment and turn the badge in to ATC Visitor Control Desk the next business day. Keys and proximity cards will be returned to the issuing key custodian prior to the employee departing ATC.
Force Protection. The contractor shall ensure that each contractor employee receives annual Level I Antiterrorism awareness training per Army Regulation 525-13 (Antiterrorism).
Contractor personnel may attend ATC’s annual Force Protection training; however, contractor personnel who are unable to attend the training shall receive the same training from contractor management. In addition, contractor personnel traveling outside the 50 States, its territories and possessions shall receive an OCONUS briefing within two (2) months of their scheduled travel.
They shall also have received annual Antiterrorism training with 12 months of travel.
File details come from the government source that posted it. Updated .