See attached SOW with quantities, drawings, and CDRL's.
FOB Destination Panama City, FL *Prices shall include shipping charges*
CLIN 0001 and CLIN 0002 needed for quote.
Section C - Specifications
Minimum Requirements for Access to Controlled Unclassified Information (CUI): Prior to access contractor personnel requiring access to DON controlled unclassified information (CUI) or "user level access to DON or DoD networks and information systems system security and network defense systems or to system resourcesproviding visual access and/or ability to input delete or otherwise manipulate sensitive information without controls to identify and deny sensitive information" contractors must have clearance eligibility or submit an Electronic Questionnaire for Investigation Processing (SF 86) to NSWC PCD Security for processing and subsequent adjudication by the DOD Consolidated Adjudications Facility.
Minimum Protection Requirements for Controlled Unclassified Information: Security classification guides (OPNAVINST 5513 series) and unclassified limited documents (e.g. FOUO Distribution Statement Controlled) are not authorized for public release and therefore cannot be posted on a publicly accessible webserver or transmitted over the Internet unless appropriately encrypted.
Controlled Unclassified Information (CUI): Controlled unclassified information (CUI) is official information that requires the application of controls and protective measures for a variety of reasons and has not been approved for publicrelease to include technical information proprietary data information requiringprotection under the Privacy Act of 1974 and Government-developed privileged information involving the award of contracts. CUI is a categorical designation that refers to unclassified information that does not meet the standards for National Security Classification under Executive Order 13526 but is (a) pertinent to the national interest of the United States or to the important interests of entities outside the Federal Government and (b) under law or policy requires protection from unauthorized disclosure special handling safeguards or prescribed limitson exchange or dissemination.
For Official use Only (FOUO) is a document designation not a classification.This designation is used by Department of Defense (DoD) and a number of other federal agencies to identify information or material which although unclassified disclosure to the public of the information would reasonably be expected to cause a foreseeable harm to an interest protected by one or more provisions of the FOIA. This includes information that qualifies for protection pursuant to the provisions of the Privacy Act of 1974 as amended. FOUO must be marked controlled and safeguarded in accordance with DoD 5200.01 Vol. 4 DoD Information Security Program: Controlled Unclassified Information (CUI) February 24 2012
Security of Unclassified DoD Information on Non-DoD Information Systems (DoD8582.01)
DoD policy: adequate security be provided for all unclassified DoD information on non-DoD information systems. Appropriate requirements shall be incorporated into all contracts grants and other legal agreements with non-DoD entities.
Information Safeguards are applicable to unclassified DoD information in thepossession or control of non-DoD entities on non-DoD information systems to theextent provided by the applicable contract grant or other legal agreement with the DoD.
Information Safeguards
Unclassified DoD information that has not been cleared for public release may be disseminated by the contractor grantee or awardee to the extent required to further the contract grant oragreement objectives provided that the information is disseminated within the scope of assigned duties and with a clear expectation that confidentiality will be preserved. Examples include:
a. Non-public information provided to a contractor (e.g. with a request for proposal)
b. Information developed during the course of a contract grant or other legal agreement (e.g. draft documents reports or briefings and deliverables)
c. Privileged information contained in transactions (e.g. privileged contract information program schedules contract-related event tracking)
It is recognized that adequate security will vary depending on the nature and sensitivity of the information on any given non-DoD information system. However all unclassified DoD information in the possession or control of non-DoD entities on non-DoD information systems shall minimally be safeguarded as follows:
a. Do not process unclassified DoD information on publically available computers (e.g. those available for use by the general public in kiosks or hotelbusiness centers)
b. Protect unclassified DoD information by at least one physical or electronic barrier (e.g. locked container or room logical authentication or logon procedure) when not under direct individual control of an authorized user.
c. At a minimum overwrite media that have been used to process unclassified DoD information before external release or disposal.
d. Encrypt all information that has been identified as CUI when it is storedon mobile computing devices such as laptops and personal digital assistants compact disks or authorized removable storage media such as thumb drives and compact disks using the best encryption technology available to the contractor or teaming partner.
e. Limit transfer of unclassified DoD information to subcontractors or teaming partners with a need to know and obtain a commitment from them to protect theinformation they receive to at least the same level of protection as that specified in the contract or other written agreement.
f. Transmit e-mail text messages and similar communications containing unclassified DoD information using technology and processes that provide the best level of privacy available given facilities conditions and environment. Examples of recommended technologies or processes include closed networks virtual private networks public key-enabled encryption and transport layer security (TLS)
g. Encrypt organizational wireless connections and use encrypted wireless connections where available when traveling. If encrypted wireless is not availableencrypt document files (e.g. spreadsheet and word processing files) using at least application-provided password protected level encryption.
h. Transmit voice and fax transmissions only when there is a reasonable assurance that access is limited to authorized recipients.
i. Do not post unclassified DoD information to website pages that are publicly available or have access limited only by domain or Internet protocol restriction. Such information may be posted to website pages that control access by useridentification and password user certificates or other technical means and provide protection via use of TLS or other equivalent technologies during transmission. Access control may be provided by the intranet (vice the website itself or the application it hosts)
j. Provide protection against computer network intrusions and data exfiltration minimally including:
(1) Current and regularly updated malware protection services e.g. anti-virus anti-spyware.
(2) Monitoring and control of both inbound and outbound network traffic (e.g. at the external boundary sub-networks individual hosts) including blocking unauthorized ingress egress and exfiltration through technologies such as firewalls and router policies intrusion prevention or detection services and host-based security services.
(3) Prompt application of security-relevant software patches service packs and hot fixes.
k. Comply with other current Federal and DoD information protection and reporting requirements for specified categories of information (e.g. medical proprietary critical program information (CPI) personally identifiable information export controlled) as specified in contracts grants and other legal agreements.
l. Report loss or unauthorized disclosure of unclassified DoD information inaccordance with contract grant or other legal agreement requirements and mechanisms.
m. Do not use external IT services (e.g. e-mail content hosting database document processing) unless they provide at least the same level of protection as that specified in the contract or other written agreement.
Operations Security
Operations Security (OPSEC) is concerned with the protection of critical information: facts about intentions capabilities operations or activities that are needed by adversaries or competitors to bring about failure or unacceptable consequences of mission accomplishment.
Critical information includes information regarding:
- Operations missions and exercises test schedules or locations;
- Location/movement of sensitive information equipment or facilities;
- Force structure and readiness (e.g. recall rosters);
- Capabilities vulnerabilities limitations security weaknesses;
- Intrusions/attacks of DoD networks or information systems;
- Network (and system) user IDs and passwords;
-Movements of key personnel or visitors (itineraries agendas etc.); and
- Security classification of equipment systems operations etc.
The contractor subcontractors and their personnel shall employ the followingcountermeasures to mitigate the susceptibility of critical information to exploitation when applicable:
- Practice OPSEC and facilitate OPSEC awareness;
- Immediately retrieve documents from printers assessable by the public;
- Shred sensitive and Controlled Unclassified Information (CUI) documents when no longer needed;
- Protect information from personnel without a need-to-know;
- When promulgating information limit details to that essential for legitimacy;
- During testing and evaluation practice OPSEC methodologies of staging out of sight desensitization or speed of execution whenever possible.
Section F - Deliveries or performance
F.O.B.
52.247-34 Destination
Section G
252.232-7006 Wide Area Workflow Payment Instructions
252.232-7003
Section I - Contract Clauses
52.204-22 Alternative Line Item Proposal (Jan 2017)
52.212-4 Contract Terms and Conditions -- Commercial Items (May 2015)
52.212-5 Contract Terms and Conditions Required to Implement Statutes or Executive Orders -- Commercial Items
Preselected:
52.203-19 Prohibition on Requiring Certain Internal Confidentiality Agreements or Statement (Jan 2017)
52.209-10 Prohibition on Contracting with Inverted Domestic Corporations (Nov 2015)
52.233-3 Protest After Award (Aug 1996)
52.233-4 Applicable Law for Breach of Contract Claim (Oct 2004)
Required:
52.222-50 Combatting Trafficking in Persons (Mar 2015)
52.223-18 Encouraging Contractor Policies to Ban Text Messaging While Driving (Aug 2011)
52.232-33 Payment by Electronic Funds Transfer--System for Award Management JUL 2013
52.232-39 Unenforceability of Unauthorized Obligations (Jun 2013)
52.232-40 Providing Accelerated Payments to Small Business Subcontractors (Dec 2013)
52.243-1 Changes Fixed-Price
252.203-7000 Requirements Relating to Compensation of Former DoD Officials (SEP 2011)
252.203-7002 Requirement toInform Employees of Whistleblower Rights (Sep 2013)
252.204-7003 Control of Government Work Product (Apr 1992)
252.204-7008 Compliance with Safeguarding Covered Defense Information Controls (Oct 2016)
252.204-7009 Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information
252.204-7012 Safeguarding Covered Defense Information and CyberIncident Reporting (Oct 2016)
252.204-7015 Notice of Authorized Disclosureof Information by Litigation Support (May 2016)
252.213-7000 Notice to Prospective Suppliers on Use of PPIRS (JUN 2015)
252.225-7048 Export Controlled Items (Jun 2013)
252.232-7010 Levies on Contract Payments (Dec 2006)
252.247-7023 Transportation of Supplies by Sea (Apr 2014)
Section K Representations
52.203-18 Prohibition on Contracting with Entities that Require Certain Internal Confidentiality Agreements or Statements--Representation (Jan 2017)
52.204-8 Annual Representations and Certifications FEB 2016
52.204-19 Incorporation by Reference of Representations and Certifications (Dec 2014)
52.209-11 Representation by Corporations Regarding Delinquent Tax Liability or a Felony Conviction (Feb 2016)
Section L - Instructions Conditions and Notices to Bidders
52.204-7 System for Award Management (Jul 2013)
52.211-14 Notice of Priority Rating
52.212-1 Instructions to Offerors-Commercial Items (Jan 2017)
52.246-15 Certificate of Conformance
Section M - Evaluation Factors for Award
52.212-2 Evaluation Commercial Items FAR 13.106-1 Best Value based on Price,PPIRS (pass/fail), proposed delivery terms, conforming to drawings specifications, and ability to furnished the required CoC's/Test Inspection Report stated inthe CDRL.
CITE: https://www.fbo.gov/notices/b0b8fa6e6adc41c1b44c854487aff43e