A07-DD254_A1803_MVP_ATTACH.pdf

PDF 601 KB Posted

Attached to
OPTION - CISCO Network Optimization support services subscription CON-AS-DCN Federal contract opportunity
Solicitation number
W91RUS18RDC37RFQ
Issued by
Department of the Army

View the file

Other files for this federal contract opportunity

Other files attached to OPTION - CISCO Network Optimization support services subscription CON-AS-DCN, newest first.
File Type Posted
A07-DD254_A1803_MVP_ATTACH.PDF PDF
A07-W91RUS-18-R-DC37.pdf PDF
A07-W91RUS-18-R-DC37.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CLASSIFICATION (When filled in): Unclassified

A-1803

PREVIOUS EDITION IS OBSOLETE. Page 1 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 1 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018

DEPARTMENT OF DEFENSE

CONTRACT SECURITY CLASSIFICATION SPECIFICATION

(The requirements of the National Industrial Security Program (NISP) apply to all security aspects of this effort involving classified information.)

OMB No. 0704-0567 OMB approval expires:

October 31, 2020

The public reporting burden for this collection of information, 0704-0567, is estimated to average 70 minutes per response, including the time for reviewing instructions, searching existing data sources, gathering and maintaining the data needed, and completing and reviewing the collection of information. Send comments regarding this burden estimate or any other aspect of this collection of information, including suggestions for reducing the burden, to the Department of Defense, Washington Headquarters Services, at whs.mc-alex.esd.mbx.dd-dod-information-collections@mail.mil. Respondents should be aware that notwithstanding any other provision of law, no person shall be subject to any penalty for failing to comply with a collection of information if it does not display a currently valid OMB control number.

RETURN COMPLETED FORM AS DIRECTED IN THE INSTRUCTIONS.

1. CLEARANCE AND SAFEGUARDING

a. LEVEL OF FACILITY SECURITY CLEARANCE (FCL) REQUIRED (See Instructions)

Secret

b. LEVEL OF SAFEGUARDING FOR CLASSIFIED INFORMATION/

MATERIAL REQUIRED AT CONTRACTOR FACILITY

None (See instructions)

2. THIS SPECIFICATION IS FOR: (X and complete as applicable.)

a. PRIME CONTRACT NUMBER (See instructions.)

See block 6.a. below.

b. SUBCONTRACT NUMBER

c. SOLICITATION OR OTHER NUMBER DUE DATE (YYYYMMDD)

3. THIS SPECIFICATION IS: (X and complete as applicable.)

a. ORIGINAL (Complete date in all cases.)

DATE (YYYYMMDD)

20180503

b. REVISED (Supersedes all previous specifications.)

REVISION NO. DATE (YYYYMMDD)

c. FINAL (Complete Item 5 in all cases.) DATE (YYYYMMDD)

4. IS THIS A FOLLOW-ON CONTRACT? No Yes If yes, complete the following:

Classified material received or generated under (Preceding Contract Number) is transferred to this follow-on contract.W91RUS-14-P-0128

5. IS THIS A FINAL DD FORM 254? No Yes If yes, complete the following:

In response to the contractor's request dated , retention of the classified material is authorized for the period of:

6. CONTRACTOR (Include Commercial and Government Entity (CAGE) Code)

a. NAME, ADDRESS, AND ZIP CODE

This DD Form 254 is for planning/solicitation purposes only. If received with a contract award, immediately notify the KO, it may not reflect accurate security requirements as changes may have occurred after date of signatures in Blocks 13 and 16.

b. CAGE CODE

TBD

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

TBD

7. SUBCONTRACTOR(S) (Click button if you choose to add or list the subcontractors -- but will still require a separate DD Form 254 issued by a prime contractor to each subcontractor)

a. NAME, ADDRESS, AND ZIP CODE

N/A

b. CAGE CODE

N/A

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

N/A

8. ACTUAL PERFORMANCE (Click button to add more locations.)

a. LOCATION(S) (For actual performance, see instructions.)

NETCOM TAC-E

Bldg 1007, Clay Kaserne, Wiesbaden Germany Unit 29623, Box 90

APO AE 09096-0090

b. CAGE CODE (If applicable, see Instructions.)

N/A

c. COGNIZANT SECURITY OFFICE(S) (CSO) (Name, Address, ZIP Code, Telephone required; Email Address optional)

HQ, 2d Theater Signal Brigade, S2

NETC-SEC-IS

Unit 29623, Box 90

APO AE 09096-0090

9. GENERAL UNCLASSIFIED DESCRIPTION OF THIS PROCUREMENT

This contract is for non-personal Information Technology (IT) support services to augment and support the mission of the 5th Signal Command and U.S. Army Europe, within the USAREUR and U.S. European Command (EUCOM) Areas of Responsibility (AOR) that include Europe and parts of Africa. Primary place of performance will be at Clay Kaseme, Wiesbaden, Germany, but other locations may also be involved. The actual place of performance will be specified in each task order issued under this contract. Contractor personnel will have access to SIPRNET. Temporary duty (TDY) will be a requirement.

A-1803

PREVIOUS EDITION IS OBSOLETE. Page 2 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 2 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018

10. CONTRACTOR WILL REQUIRE ACCESS TO: (X all that apply. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. COMMUNICATIONS SECURITY (COMSEC) INFORMATION f. SPECIAL ACCESS PROGRAM (SAP) INFORMATION

b. RESTRICTED DATA

g. NORTH ATLANTIC TREATY ORGANIZATION

(NATO) INFORMATION

c. CRITICAL NUCLEAR WEAPON DESIGN INFORMATION (CNWDI) (If CNWDI applies, RESTRICTED DATA must also be marked.)

h. FOREIGN GOVERMENT INFORMATION

d. FORMERLY RESTRICTED DATA

i. ALTERNATIVE COMPENSATORY CONTROL MEASURES

(ACCM) INFORMATION

e. NATIONAL INTELLIGENCE INFORMATION:

(1) Sensitive Compartmented Information (SCI)

(2) Non-SCI

j. CONTROLLED UNCLASSIFIED INFORMATION (CUI) (See instructions.)

k. OTHER (Specify) (See instructions.)

NIPRNet; SIPRNet

11. IN PERFORMING THIS CONTRACT, THE CONTRACTOR WILL: (X all that apply. See instructions. Provide details in Blocks 13 or 14 as set forth in the instructions.)

a. HAVE ACCESS TO CLASSIFIED INFORMATION ONLY AT

ANOTHER CONTRACTOR'S FACILITY OR A GOVERNMENT

ACTIVITY

(Applicable only if there is no access or storage required at contractor facility.

See instructions.)

b. RECEIVE AND STORE CLASSIFIED DOCUMENTS ONLY

c. RECEIVE, STORE, AND GENERATE CLASSIFIED

INFORMATION OR MATERIAL

d. FABRICATE, MODIFY, OR STORE CLASSIFIED HARDWARE

e. PERFORM SERVICES ONLY

f. HAVE ACCESS TO U.S. CLASSIFIED INFORMATION OUTSIDE

THE U.S.,PUERTO RICO, U.S. POSSESSIONS AND TRUST

TERRITORIES

g. BE AUTHORIZED TO USE THE SERVICES OF DEFENSE

TECHNICAL INFORMATION CENTER (DTIC) OR OTHER

SECONDARY DISTRIBUTION CENTER

h. REQUIRE A COMSEC ACCOUNT

i. HAVE A TEMPEST REQUIREMENT

j. HAVE OPERATIONS SECURITY (OPSEC) REQUIREMENTS

k. BE AUTHORIZED TO USE DEFENSE COURIER SERVICE

l. RECEIVE, STORE, OR GENERATE CONTROLLED UNCLASSIFIED

INFORMATION (CUI).

(DoD Components: refer to DoDM 5200.01, Volume 4 only for specific CUI protection requirements. Non-DoD Components: see instructions.)

m. OTHER (Specify) (See instructions.)

Have Information Technology (IT) Requirements - See DD Form 254, Block 13 Continuation Sheets

12. PUBLIC RELEASE

Any information (classified or unclassified) pertaining to this contract shall not be released for public dissemination except as provided by the National Industrial Security Program Operating Manual (NISPOM) or unless it has been approved for public release by appropriate U.S. Government authority.

Proposed public releases shall be submitted for review and approval prior to release to the appropriate government approval authority identified here with at least office and phone contact information and if available, an e-mail address. (See instructions)

DIRECT THROUGH (Specify below)

Public release of Non-SCI information is not authorized.

Public Release Authority:

Contracting Officer, ACC-APG (C4ISR), Building 61801, Rm.

3212, Fort Huachuca, AZ 85613

13. SECURITY GUIDANCE

The security classification guidance for classified information needed for this effort is identified below. If any difficulty is encountered in applying this guidance or if any other contributing factor indicates a need for changes in this guidance, the contractor is authorized and encouraged to provide recommended changes; to challenge the guidance or the classification assigned to any information or material furnished or generated under this contract;

and to submit any questions for interpretation of this guidance to the official identified below. Pending final decision, the information involved shall be handled and protected at the highest level of classification assigned or recommended.

(Fill in as appropriate for the classified effort. Attach, or forward under separate correspondence, any documents/guides/extracts referenced herein. The field will expand as text is added. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted. Also allows for up to 6 internal reviewers to digitally sign. See instructions for additional guidance or use of the fillable PDF.)

1. Ref 1a: Contractor requires at least a final SECRET facility clearance at time of contract award.

2. Ref 1b: There is no requirement for the contractor to establish safeguarding capability at any company location.

See DD Form 254 Block 13 Continuation Sheets for further guidance.

List of Attachments (All Files Must be Attached Prior to Signing, i.e., for any digital signature on the form)

A-1803

PREVIOUS EDITION IS OBSOLETE. Page 3 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018 PREVIOUS EDITION IS OBSOLETE. Page 3 of 3 AEM LiveCycle Designer

DD FORM 254, APR 2018

NETCOM TAC-E, Engineering Division Unit 29623, APO AE 09096

NAME & TITLE OF REVIEWING OFFICIAL

Bradley Floray Bradley.C.Floray.civ@mail.mil

SIGNATURE

14. ADDITIONAL SECURITY REQUIREMENTS

Requirements, in addition to NISPOM requirements for classified information, are established for this contract.

No Yes If Yes, identify the pertinent contractual clauses in the contract document itself, or provide an appropriate statement which identifies the additional requirements. Provide a copy of the requirements to the CSO. The field will expand as text is added or you can also use item 13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.

(See instructions for additional guidance or use of the fillable PDF.)

See DD Form 254, Block 13 Continuation Sheets for further guidance.

15. INSPECTIONS

Elements of this contract are outside the inspection responsibility of the CSO.

No Yes If Yes, explain and identify specific areas and government activity responsible for inspections. The field will expand as text is added or you can also use item

13. When removing any expanded text area, use delete key or backspace key, then click out of the text field for it to shrink after the text has been deleted.

(See instructions for additional guidance or use of the fillable PDF.)

Contractor personnel are integrated into the government requiring activity workforce. Inspections will be conducted by the government requiring activity. When contractor personnel are embedded or integrated into government workforce, they are also integrated into the requiring activity AR 380-5 inspections.

16. GOVERNMENT CONTRACTING ACTIVITY (GCA) AND POINT OF CONTACT (POC)

a. GCA NAME

Army Contracting Command - APG

b. ACTIVITY ADDRESS CODE (AAC) OF THE CONTRACTING OFFICE (See Instructions)

W91RUS

c. ADDRESS (Include ZIP Code)

2133 CUSHING ST.

BLDG 61801 RM 3212

FORT HUACHUCA AZ 85613

d. POC NAME

e. POC TELEPHONE (Include Area Code)

f. EMAIL ADDRESS (See Instructions)

17. CERTIFICATION AND SIGNATURES

Security requirements stated herein are complete and adequate for safeguarding the classified information to be released or generated under this classified effort. All questions shall be referred to the official named below. Upon digitally signing Item 17h, no changes can be made as the form will be locked.

a. TYPED NAME OF CERTIFYING OFFICIAL (Last, First, Middle Initial) (See Instructions)

Marc V Palmer

b. TITLE

Security Manager

c. ADDRESS (Include ZIP Code)

HQ, 2d Theater Signal Brigade, S2

NETC-SEC-IS

Unit 29623, Box 90

d. AAC OF THE CONTRACTING OFFICE (See Instructions)

W91RUS

e. CAGE CODE OF THE PRIME CONTRACTOR (See Instructions.)

TBD

f. TELEPHONE (Include Area Code)

+1 (314) 565-0210

g. EMAIL ADDRESS (See Instructions) marc.v.palmer.civ@mail.mil

h. SIGNATURE

i. DATE SIGNED (See Instructions)

18. REQUIRED DISTRIBUTION BY THE CERTIFYING OFFICIAL

a. CONTRACTOR

b. SUBCONTRACTOR

c. COGNIZANT SECURITY OFFICE FOR PRIME AND

SUBCONTRACTOR

d. U.S. ACTIVITY RESPONSIBLE FOR OVERSEAS SECURITY

ADMINISTRATION

e. ADMINISTRATIVE CONTRACTING OFFICER

f. OTHER AS NECESSARY (If more room is needed, continue in Item 13 or on additional page if necessary.)

As identified by the COR.

Contract #: __________________________ Solicitation #: ________________________ NETCOM TAC-E Network Access Control and Optimization DD 254, 20180503, Block 13 Continuation Sheets Page 1 of 10

3. Ref 10.e.(2): ICD 703, Control and Dissemination of Intelligence Information, provides policy on control, access, and dissemination of intelligence information. This policy is available from the Government requiring activity.

Written approval of the Contracting Officer is required prior to subcontracting any work effort that requires access to intelligence information.

4. Ref 10.g.: Personnel not assigned to a NATO staff position, but requiring access to NATO classified information, NATO COSMIC, NATO Secret or access to the NATO accredited SIPRNET terminals, must possess the equivalent FINAL or Interim U.S. Security Clearance based upon the appropriate personnel security investigation required.

Personnel with access to NATO ATOMAL information must have the appropriate level FINAL U.S. Security Clearance. The government program/project manager is the designated representative that will ensure the contractor security manager and concerned employees are NATO briefed prior to access being granted. The contractor will maintain strict compliance in regards to NATO information IAW NISPOM Ch. 10, Section 7. Prior approval from the Contracting Officer is required for subcontracting. In performance of this contract all cleared contractor personnel who require access to SIPRNET or who require access to NATO classified information by some other means will receive a NATO Access Security Briefing and execute the required NATO Access Briefing Certificate.

JPAS shall be updated to reflect NATO Secret access.

5. Ref 10j: Safeguarding “For Official Use Only” (FOUO) information. See Attachment A. FOUO information or Personal Identifying Information (PII) received or generated under this contract shall be controlled and protected, marked, and safeguarded, as specified in AR 25-55, DA Freedom of Information Act Program, AR 380-5 (Chapter 5), DA Information Security Program, and DoD 5200.01-M, Volume 4, DoD Information Security Program:

Controlled Unclassified Information (CUI). This includes PII, as defined in DoDD 5400.11 (DoD Privacy Program).

6. Ref 10k: This work performance will require Contractor access to Army Knowledge Online (AKO), NIPRNet and SIPRNet. The contractor shall not access, download or further disseminate any special access data (i.e. intelligence, NATO, COMSEC, etc.) outside the execution of the defined contract requirements and without the guidance and written permission of the KO. In the event that any special access is required, the KO must modify the requirements for the DD Form 254. All access to SIPRNet shall only be at Government requiring activity work locations. All system access will be sponsored by the Contracting Officer’s Representative (COR).

8a. Ref 10k: Accreditation of the SIPRNet backbone to transport NATO Secret and below information resulted in additional security measures across the board. Per DoDM 5200.01-V1, all cleared DoD military, civilian and contractor personnel briefed on their responsibilities for protecting U.S. classified information, shall be briefed simultaneously on the requirements for protecting NATO classified information. The Contractor Facility Security Officer (FSO) shall provide a NATO “awareness briefing” to contractor personnel performing work at Government requiring activity work locations and shall maintain a written acknowledgment of the individual's receipt of the awareness briefing along with statement of understanding of responsibilities for safeguarding NATO classified information. The NATO awareness briefing does not constitute “need to know or access approval” to NATO classified information and shall not be entered in Joint Personnel Adjudication System (JPAS). The Contractor shall provide copies of NATO awareness briefings to the COR, upon request.

7. Ref 11a: Contractor access to classified information shall be limited to that which is necessary to support this contract. Government agency or activity will provide security classification guidance for performance of this contract. Properly cleared contractor personnel who have an established need-to-know in accordance with this contract are authorized access to classified information which supports this work effort. Access to classified information shall only be at Government work locations, to include while in a temporary duty (TDY) travel status in support of this contract. The Contractor shall not remove any classified materials or information, from the Government work site(s), nor shall the Contractor reproduce, generate, or store any classified materials or information relating to this contract at other than specified Government work locations. This includes downloading, storing, or transmitting classified information on or to any unauthorized software, hardware, or information technology system. Classified material shall only be stored at Government requiring activity work locations in Government furnished GSA approved security containers, or as directed by the COR and/or Government Security Officials. Hand-carry of classified information is not authorized.

NETCOM TAC-E Network Access Control and Optimization DD 254, 20180503, Block 13 Continuation Sheets Page 2 of 10

7a. Ref 11a: Contractor Responsibility: By memorandum dated 1 April 2005, the Deputy Under Secretary of Defense (Counterintelligence and Security) authorized the use of JPAS to verify security clearance levels for personnel who require access to classified information within DOD. Within Army use of JPAS is mandated. The Contractor FSO shall ensure all personnel performing on this work effort have security access level, Information Technology (IT) level, Contractor affiliation, Security Management Office (SMO) affiliation and all other required information accurately reflected/populated in JPAS. The Contractor shall make available to the Government requiring activity, and all work locations under this effort, all information necessary to enable verification of security access level/affiliation via JPAS. When Visit Authorization Requests (VARs) are required by the Government requiring activity, they shall be transmitted via JPAS.

7b. Ref 11a: The Contractor shall submit a VAR, which reflects all cleared contractor personnel who will be performing on this contract. VARs shall include the contract number in the additional information block and COR/Government Requiring Activity (RA) POC name and telephone number. All VARs shall be maintained current throughout the life of the contract and shall be updated as personnel or other relevant changes occur. All Contractor personnel must be reflected on a current VAL/Roster in order to perform on this contract. Prime contractor shall ensure all subcontractors comply with these requirements. Contractor shall contact the COR for Security Management Office (SMO) code for all work locations.

7c. Ref 11a: Collateral Security In/out-processing. All contractor personnel integrated or embedded with NETCOM organizations shall in-process through the supporting NETCOM organizational G2/S2/Security Office at work performance start date. All contractor personnel integrated or embedded with NETCOM organizations shall out-process and clear through the supporting NETCOM organizational G2/S2/Security Office upon termination of employment on the contract or upon contract expiration/termination, whichever occurs first. Above requirements are applicable if there is a change in primary work performance location while employed on the contract. The prime contractor shall ensure above requirements are included in sub-contracts and lower tier contracts when personnel are integrated or embedded with NETCOM organizations. Per AR 380-49, embedded and/or integrated contractors are those who operate out of government-supplied on-base space.

7d. Ref 11a: Required Security Training: Army Learning Management System (ALMS) Initial Security Orientation and Annual Refresher Training. Within 30 business days of work start date, contractor personnel shall complete the Department of the Army standardized computer web-based Initial Security Orientation training and annually thereafter, shall complete the Annual Security Refresher Training, both available at https://www.lms.army.mil under Information Security Program training. The system will automatically direct the user to the appropriate course based on their training history. Certificates of successful completion, of initial and/or annual refresher training, shall be provided to the COR within three (3) business days of completion of training. This training is in addition to unit or installation specific security training.

8. Ref 11e: Contractor shall comply with FAR 52.204-2, Security Requirements. This clause involves access to information classified “Confidential,” “Secret,” or “Top Secret” and requires contractors to comply with the Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DoD 5220.22-M) and any revisions to DoD 5220.22-M.

8a. Ref 11e: This is a non-personal services contract (see Block 9). The highest level security clearance requirement for this work effort is SECRET. Contractor personnel shall have a Final security clearance at contract performance start date and shall maintain the required security clearance over the life of the contract. Contractor personnel who require a Secret security clearance and who will require IT Level I system access or who will be performing IT level I functions require a Tier 5 (T5) / T5 Reinvestigation (T5R) Investigation completed with a favorable fitness determination for IT Level I access. If Contractor personnel do not have a favorable T5 investigation on record, the Contractor shall contact the supporting Government Security Office/G2/S2 for submission of the T5 investigation (SF 86). The Contractor shall provide the contract/task order number as authority to request the investigation.

Contractor interim privileged level access to Army systems prior to completion and favorable fitness determination of the required investigation will be in accordance with AR 25-2. If Contractor personnel have a favorable T5 or T5R on record in JPAS, the AR 25-2 investigative requirement for IT Level I is satisfied.

https://www.lms.army.mil/

NETCOM TAC-E Network Access Control and Optimization DD 254, 20180503, Block 13 Continuation Sheets Page 3 of 10

8b. Ref 11e:.Classified information generated or received during work performance on this contract shall be controlled, marked, protected, transmitted, and safeguarded in accordance with AR 380-5 and current Army and DoD policy and shall only be at specified Government requiring activity work locations.

8c. Ref 11e: The process of extracting, paraphrasing, restating or generating classified information based on a security classification guide or one or more source documents, or both, is derivative classification. Any derivatively classified information generated in performance of this contract shall normally be marked according to the classification markings reflected on the source material(s). However, a compilation of information, to include a compilation of unclassified information, could warrant a change in classification level of the information, or, it could warrant the classification of previously unclassified information. The Contractor shall consult with the COR regarding any potential classification issues when generating information and/or deliverables in support of this contract.

8d. Ref 11e: The Government requiring activity will identify, or provide, additional instruction or appropriate security classification guides/guidance to the Contractor, as required. The Contractor shall notify the COR, in writing, of any instance where referenced security classification guides/guidance cannot be accessed at links or sites specified in this contract or specified in separate correspondence. The prime contractor shall ensure all applicable security classification guides/guidance are made available to any subcontractor(s), as appropriate.

8e. Ref 11e: Personnel who derivatively classify information and who apply derivative classification markings shall receive training in the proper application of derivative classification principles. The Contractor, in coordination with the COR, shall identify by name and position title, those contractor, subcontractor or any lower tier subcontractor personnel who will be generating and derivatively classifying information during work performance on this contract.

This includes, but is not limited to, personnel who require SIPRNET accounts. The Government will not create an account for any classified system prior to successful completion of the required training. The Prime Contractor shall ensure contractor and subcontractor personnel successfully complete initial Derivative Classification Training at work performance start date, and complete refresher training once every two years thereafter. Initial training consists of the Derivative Classification Course (IF103.16) and Derivative Classification Exam (IF103.06) and refresher training consists of Derivative Classification Refresher (IF 109.16) and Derivative Classification Exam (IF 103.06) both available on-line at the DSSA/STEPP website http://www.cdse.edu/stepp/index.html, under Information Security. Exam certificates showing successful completion of initial OR refresher training, shall be provided to the COR within three (3) business days.

8f. Ref 11e: The prime contractor shall require subcontractors to include above requirements in lower tier contracts.

9. Ref 11f: Contractor personnel will require access to classified information OCONUS. Such access is restricted to U.S. Government controlled work locations/compounds. Primary work performance location is in the Federal Republic of Germany. Storage, custody, and control of classified information OCONUS remains the responsibility of the U.S. Government. Hand-carry of classified information is not authorized.

10. Ref 11j: The Contractor shall comply with DOD Directive 5205.02E, Army Regulation 530-1, and the requiring activity OPSEC program. The Contractor shall ensure all contractor employees and subcontractors performing work under this contract complete Level I OPSEC training within 30 calendar days of start of employee performance on this contract and annually thereafter. The Contractor shall maintain all OPSEC training records and shall provide copies to the COR upon request.

11. Ref 11l: Refer to paragraph 4. Ref 10j above.

12. Ref 11m. Information Assurance (IA) Training. All contractor personnel with access to Government information systems and networks shall successfully complete all required initial and annual IA awareness training as specified in AR 25-2 and as directed by the Government requiring activity. Training is available at https://ia.signal.army.mil.

12a. Ref 11m: Contractor employees and subcontractor employees performing work under this contract who have access to Government information systems and networks shall create a user account and profile in the Army https://ia.signal.army.mil/

NETCOM TAC-E Network Access Control and Optimization DD 254, 20180503, Block 13 Continuation Sheets Page 4 of 10

Training and Certification Tracking System website (ATCTS) at https://atc.us.army.mil/iastar/index.php, in the unit container designated by the COR. Certificates of successful completion of IA training, Acceptable Use Policies (AUP), applicable baseline and computing environment certifications, and continuing professional education credits, as required by DoD 8570.01-M, shall be uploaded to the ATCTS and provided to the COR for continuous compliance monitoring and reporting.

12b. Ref 11m: The Contractor shall ensure that all contractor employees and subcontractor employees requiring IA awareness training complete the training at the start of work performance on this contract and annually thereafter for the duration of this contract.

12c. Ref 11m: Information Assurance Workforce Certification. DFARS clause 252.239-7001 (Information Assurance Contractor Training and Certification) applies to this contract. This contract is subject to the mandates of DoD 8570.01-M, which establishes baseline technical and management IA skills for personnel performing IA functions within DoD. Functions spanning multiple levels require certification of the highest level functions.

Contractor personnel performing functions in multiple categories or specialties shall hold certifications appropriate to the functions performed in each category or specialty.

12d. Ref 11m: The Contractor shall ensure its IA workforce members have the baseline certifications corresponding to their IA functions, as defined in Chapters 3, 4, 5, 10, and 11, and Appendix 3 of DoD 8570.01-M at work performance start date. Contractors will obtain all required Computing Environment (CE) certificates within 6 months of being engaged. The IAT Level I baseline certification is the minimum requirement for unsupervised privileged access. The Contractor shall ensure that all employee certifications remain active and are renewed prior to expiration.

12e. Ref 11m: The Contractor shall ensure that all employees IA certifications are released to the Department of Defense through the Defense Workforce Certification Application at https://www.dmdc.osd.mil/milconnect.

12f. Ref 11m: Table 1 reflects the Personnel Security (IT Level) and IA Workforce Specialty requirements, aligning the IA functional responsibilities and access levels to the contract tasks, in accordance with DoD 8570.01-M.

Table 1. Information Technology Access and IA Certification Requirements.

Functional Category

IT Level

(IAW

AR 25-

2)

Security Clearance

Investigation Required

IA Certification Category and

Level (IAW DOD 8570.01-M and

BBP 05-PR-M-

0002)

Computing Environment Certifications

Network Consulting Engineer I SECRET Tier 5 (T5) IAT III Yes

12g. Ref 11m: Non-Government-owned computing devices. The Contractor shall comply with AR 25-1 and AR 25-

2. The Contractor shall not install or connect non-Government-owned computing systems or devices to Government networks without the COR coordinating and obtaining proper authorization from the appropriate Information System Security Manager (ISSM), ensuring that all software has a Government Certificate of Networthiness or has been authorized under the Risk Management Framework Assess Only process. The non- Government-owned computing systems or devices include, but are not limited to personal or contractor-owned thumb drives (e.g.

memory sticks, flash drives, Universal Serial Bus (USB) drives, jump drives, pen drives), removable or external hard drives, Personal Digital Assistants (PDA), PC Cards/Express Cards, MP3 players, cell phones, digital media, floppy disks, compact disc (CD)/digital video disk (DVD) burners, optical recordings, photo flash cards, laptops, or any devices that can store data.

12h. Ref 11m: Protection of Sensitive Unclassified Data The Contractor shall ensure any sensitive information, including but not limited to Personably Identifiable Information (PII) , For Official Use Only (FOUO), proprietary, and Law Enforcement Sensitive information residing on Mobile Computing Devices (MCD) or other external media https://atc.us.army.mil/iastar/index.php https://www.dmdc.osd.mil/milconnect

NETCOM TAC-E Network Access Control and Optimization DD 254, 20180503, Block 13 Continuation Sheets Page 5 of 10 is protected in accordance with current Data at Rest (DAR) guidelines and requirements. . The Contractor shall use an authorized, approved and prescribed DAR solution. MCD's include but are not limited to laptop, Netbook, notebook, or tablet computers; Blackberry or equivalent devices. External media includes optical disc media such as compact discs (CD), Digital Video Disks (DVD),USB drives, also referred to as flash or thumb drives (when authorization to use them is restored), and floppy disks, or other portable digital storage devices.

13. Access to Protected Information. Protected information means all non-public information, including, but not limited to, trade secrets or proprietary information of other Contractors, Government source selection information, Privacy Act or personally identifiable information (PII), or any other information with distribution limited by the U.S. Government. If, during the performance of this requirement, Contractor personnel obtain access by any means to protected information, they shall not disclose, publish, divulge, release, or make known, in any manner or to any extent, the information except as necessary to carry out duties under this contract. Protected information shall be given only to persons specifically granted access to this sensitive information and may not be further divulged without specific prior written approval from an authorized U.S. Government individual. Further, contractor employees may use any non-public information for official/authorized U.S. Government purposes, and they shall not use the information for their personal gain, the gain of their employer, or the gain of anyone else. The Contractor shall notify the Contracting Officer of any potential organizational conflicts of interest created by any such access;

however, a nondisclosure agreement will not overcome an Organizational Conflict of Interest (OCI) as defined in FAR Subpart 9.5. Moreover, the Trade Secrets Act prohibits releasing proprietary information without the owner’s consent. Accordingly, all Government Contractors are required to mark their proprietary information, and any time the Contractor is given inadvertent access to such marked information, the Contractor shall inform the Contracting Officer of the access.

14. Common Access Card (CAC). The Government will provide special access badges as necessary. The Prime Contractor Facility Security Officer (FSO) shall ensure that all Contractor personnel acquire and maintain CACs.

The approving Government Trusted Agent (TA) may give access to the FSO using the online Trusted Associate Sponsorship System (TASS), https://www.dmdc.osd.mil/tass. Contractor eligibility remains in force during employment under the contract for those employees who have a valid and recurring requirement for access to Government facilities or automation systems to perform those duties stipulated in the contract. The Contractor shall use a valid CAC to access the Government domain. The Contractor shall immediately return the CACs to the COR when the Contractor employee’s employment is terminated or upon expiration of the contract. The CACs expire when Contractor employee’s eligibility terminates or three years from the issuance date, whichever occurs first. The Contractor is responsible for all CACs and shall report all lost or stolen CACs to the COR immediately.

15. Contractor Identification Requirements. In accordance with FAR 37.114 (c), all contractor personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious are required to identify themselves as such to avoid being mistaken for Government officials. Contractors performing work at Government workplaces shall provide their employees with an easily readable identification (ID) badge indicating the employee's name, the contractor's name, the functional area of assignment, and a recent color photograph of the employee. Contractors shall require their employees wear the ID badges visibly when performing work at Government workplaces. Contractor personnel shall also ensure that all e-mails, documents or reports they produce are suitably marked as Contractor products and/or that Contractor participation is appropriately disclosed. All signature blocks on e-mails shall indicate that the sender is a Contractor employee and include the Contractor's company name.

16. Access and General Protection Security Policy and Procedures Contractor and all associated sub-contractor employees shall provide all information required for background checks to meet installation access requirements to be accomplished by installation Provost Marshal Office, Director of Emergency Services or Security Office.

Contractor workforce must comply will all personal identity verification requirements of FAR clause 52.204-9, Personal Identity Verification of Contractor Personnel. In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in contractor security matters or processes. Contractor personnel shall comply with all security policies/procedures in effect at all work and TDY locations.

https://www.dmdc.osd.mil/tass

NETCOM TAC-E Network Access Control and Optimization DD 254, 20180503, Block 13 Continuation Sheets Page 6 of 10

17. Antiterrorism Level I Training. The Contractor shall ensure that all contractor employees, including subcontractor employees, requiring access to Army installations, facilities, or controlled access areas complete Antiterrorism (AT) Level I awareness training within 30 calendar days after start of employee performance on this contract. Within 5 calendar days after successful completion of training, the contractor shall certify to the COR or KO that all employees performing work under this contract have completed the AT Level I awareness training. AT Level I awareness training is available at https://jkodirect.jten.mil, course #-US007. This training is in addition to any required unit or theater specific AT Level I training which may be more stringent based on area of operation or need for heightened awareness.

18. Threat Awareness and Reporting Program (TARP). Contractor personnel shall comply with all Threat Awareness and Reporting Program (TARP) reporting requirements in accordance with AR 381-12, and as directed by the Government requiring activity. Contractor personnel shall report threat-related incidents, behavioral indicators, and other matters of Counterintelligence (CI) interest as specified in AR 381-12, Chapter 3, to the nearest military CI office, the Facility Security Officer, the Federal Bureau of Investigation, or the Defense Security Service.

18a. The Contractor shall ensure all employees, to include subcontractor employees, attend threat awareness training within 30 calendar days of employee work start date and annually thereafter. Training must be conducted by a supporting CI agent. The initial training may be satisfied by taking the authorized on-line training at https://www.lms.army.mil if attendance at a CI training session is not possible within 30 calendar days of employee work start. Certificate of completion shall be maintained on file. The on-line training does not replace the requirement to attend the first available CI conducted threat awareness training session. The contractor shall maintain training records which include employee names, training dates, training locations, and method of training and shall make such records available to the COR, upon request.

18b. Contractor personnel who require access to information, or who will be performing or participating in any functions, as outlined in AR 381-12, Ch. 2, Sec. III, para. 2-6, shall contact their COR who will coordinate with the supporting Government Security Manager for scheduling of special CI threat-awareness briefings/and debriefings, as appropriate. This includes contractor personnel who require access to Sensitive Compartmented Information (SCI), Special Access Program (SAP) information, cryptographic information, or who are system administrators or key information network personnel with administrator-level privileges on classified or unclassified Army information systems. These contractor personnel shall notify their COR in advance of any foreign travel to determine if special CI threat travel briefings/debriefings are a requirement, as specified in paragraph AR 381-12, Ch. 2, Sec. III, para. 2-6. The COR will in-turn coordinate with the supporting Government on-site Security Manager for this determination.

19. iWATCH. The Contractor shall ensure that all employees and subcontractor employees performing work under this contract are trained on the local iWATCH program within 30 calendar days of start of employee performance on this contract. The requiring activity ATO will provide the locally developed iWATCH training. The Contractor shall maintain all iWATCH training records and shall provide copies to the COR upon request.

20. Contractor personnel shall comply with all applicable security regulations, guidance, and procedures, including local, referenced in this DD Form 254, the Performance Work Statement (PWS), and in effect at all work locations.

Contractor personnel shall attend all Government provided security and security awareness training as specified by the Government requiring activity. This includes successful completion of all required on-line security training, as directed by the Government requiring activity.

21. Ref 17: Required Distribution: The prime contractor shall provide a copy of the DD Form 254 for any classified sub-contract supporting this work effort to the addresses indicated below. In addition, the prime contractor shall require any sub-contractors who have lower tier contractors to also comply with this requirement. DD Forms 254 shall be provided to the following:

NETCOM, RM #2320 HQ, 2d Theater Signal Brigade, S2 2133 Cushing Street NETC-SEC-IS https://jkodirect.jten.mil/ https://www.lms.army.mil/

NETCOM TAC-E Network Access Control and Optimization DD 254, 20180503, Block 13 Continuation Sheets Page 7 of 10

ACofS G2, Box #2 Unit 29623, Box 90 Fort Huachuca, AZ 85613-7070 APO AE 09096-0090

FAX (520) 538-8787 DSN 879-8787

Other locations as directed by the Government requiring activity/COR.

22. Emergencies and Force Protection Conditions. During declared emergencies and/or elevated Force Protection Conditions (FPCONs) Charlie or Delta, contractor performance under this contract shall be determined by the COR or KO. All Contractor employees providing services under this contract are required to report for duty as scheduled and remain on duty during declared emergencies and/or elevated FPCON levels unless otherwise directed by the KO or COR. The Contractor Project Manager shall keep the COR apprised of all personnel whereabouts when in a temporary duty (TDY) location.

23. IAW AR 380-49, Ch. 2-3(e), 'All fully executed DD Form 254s for subcontractors must be provided to the COR.

The COR will ensure that the ISSM also receives a copy.

24. Federal Acquisition Regulation (FAR) Clause 52.204-9 (Identity Verification of Contractor Personnel) is applicable to this contract.

25. FAR Clause 52.204-2 (Security Requirements) is applicable to this contract.

24. Additional References:

AR 25-1 Army Information Technology AR 25-2 Information Assurance AR 25-55 The Department of the Army Freedom of Information Act Program AR 190-13 The Army Physical Security Program (FOUO requires AKO access) AR 190-51 Security of Unclassified Army Property (Sensitive and Nonsensitive) AR 350-1 Army Training and Leader Development AR 380-5 Department of the Army Information Security Program AR 380-49 Industrial Security Program AR 380-67 Personnel Security Program AR 381-12 Threat Awareness and Reporting Program (TARP) AR 525-13 Antiterrorism (FOUO) AR 530-1 Operations Security (OPSEC)

DoDD 5205.02E DoD Operations Security (OPSEC) Program DoDD 5400.11 DoD Privacy Program DoDD 8140.01 Cyberspace Workforce Management

DoDI 8500.01 Cybersecurity DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT)

DoD 5220.22-M National Industrial Security Program Operating Manual (NISPOM) DoD 8570.01-M Information Assurance Workforce Improvement Program DoDM 5200.01-V1 DoD Information Security Program: Overview, Classification, and Declassification DoDM 5200.01-V2 DOD Information Security Program: Marking of Classified Information DoDM 5200.01-V3 DOD Information Security Program: Protection of Classified Information DoDM 5200.01-V4 DoD Information Security Program: Controlled Unclassified Information (CUI)

Army CIO/G-6 Best Business Practice 05-PR-M-0002, Information Assurance (IA Training and Certification (available at https://www.milsuite.mil/wiki/Best_Business_Practices)

Committee on National Security Systems Instructions (CNSSI) 4009, National Information Assurance Glossary https://www.milsuite.mil/wiki/Best_Business_Practices

NETCOM TAC-E Network Access Control and Optimization DD 254, 20180503, Block 13 Continuation Sheets Page 8 of 10

(available at http://www.cnss.gov/CNSS/issuances/instructions.cfm)

Deputy Under Secretary of Defense memorandum, 1 Apr 2005, Subject: Facilitating Classified Visits within the Department of Defense

Department of the Army G2 memorandum, 29 May 2007, subject: Classified Visit Request Process

US Army Cyber Command and Second Army Security Classification Guide for Cyberspace Operations and Security, 19 May 2016 (FOUO available from the Government requiring activity).

http://www.cnss.gov/CNSS/issuances/instructions.cfm

NETCOM TAC-E Network Access Control and Optimization DD 254, 20180503, Block 13 Continuation Sheets Page 9 of 10

ATTACHMENT A

SAFEGUARDING “FOR OFFICIAL USE ONLY” (FOUO) INFORMATION

1. GENERAL:

a. The "For Official Use Only" (FOUO) marking is assigned to information at the time of its creation in a DoD User Agency. It is not authorized as a substitute for a security classification marking but is used on official government information that may be withheld from the public under exemptions 2 through 9 of the Freedom of Information Act (FOIA).

b. Other non-security markings, such as "Limited Official Use" and "Official Use Only" are used by non-DoD User Agencies for the same type of information and should be safeguarded and handled in accordance with instruction received from such agencies.

c. Use of the above markings does not mean that the information cannot be released to the public under FOIA, only that the Government must review the information prior to its release to determine whether a significant and legitimate government purpose is served by withholding the information or portions thereof.

2. MARKINGS:

a. An unclassified document containing FOUO information will be marked "For Official Use Only" at the bottom of the front cover (if any), on the first page, on each page containing FOUO information, on the back page, and on the outside of the back cover (if any).

b. Within a classified document, an individual page that contains both FOUO and classified information will be marked at the top and bottom with the highest security classification of information appearing on the page. If an individual portion contains FOUO information but no classified information, the portion will be marked, "FOUO."

c. Any "For Official Use Only" information released to a contractor by a DoD User Agency is required to be marked with the following statement prior to transfer.

“This document contains information EXEMPT FROM MANDATORY DISCLOSURE UNDER THE FOIA.

Exemptions apply.”

d. Removal of the "For Official Use Only" marking can only be accomplished by the originator or other competent authority. When the "For Official Use Only" status is terminated, all known holders will be notified to the extent practical.

3. DISSEMINATION: Contractors may disseminate "For Official Use Only" information to their employees and subcontractors who have a need for the information in connection with a classified contract. Contractors must ensure employees and subcontractors are aware of the special handling instructions detailed below.

4. STORAGE: During working hours, "For Official Use Only" information shall be placed in an out-of-sight location if the work area is accessible to persons who do not have a need for the information. During nonworking hours, the information shall be stored to preclude unauthorized access. Filing such material with other unclassified records in unlocked files or desks, is adequate when internal building security is provided during nonworking hours. When such internal security control is not exercised, locked buildings or rooms will provide adequate after-hours protection or the material can be stored in locked receptacles such as file cabinets, desks, or bookcases.

5. TRANSMISSION: "For Official Use Only" information may be sent via first-class mail or parcel post. Bulky shipments may be sent by fourth-class mail. DoD components, officials of DoD components, and authorized DoD contractors, consultants, and grantees send FOUO information to each other to conduct official DoD business. Tell recipients the status of such information, and send the material in a way that prevents unauthorized public

NETCOM TAC-E Network Access Control and Optimization DD 254, 20180503, Block 13 Continuation Sheets Page 10 of 10 disclosure. Make sure documents that transmit FOUO material call attention to any FOUO attachments. Normally, you may send FOUO records over facsimile equipment. To prevent unauthorized disclosure, consider attaching special cover sheets, the location of sending and receiving machines, and whether authorized personnel are around to receive FOUO information. FOUO information may be passed to officials in other departments and agencies of the executive and judicial branches to fulfill a government function. Mark the records "For Official Use Only" and tell the recipient the information is exempt from public disclosure under the FOIA and requires special handling.

6. DISPOSITION: When no longer…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.