UCF STIG Viewer Logo

Industrial Security - DD Form 254


Overview

Finding ID Version Rule ID IA Controls Severity
V-30993 ID-01.02.01 SV-41039r2_rule PECF-1 PRAS-2 PRNK-1 Medium
Description
Failure to complete a DD Form 254 (Contract Security Classification Specification) or to specify security clearance and/or IT requirements for all contracts that require access to classified material can result in unauthorized personnel having access to classified material or mission failure if personnel are not authorized the proper access.
STIG Date
Traditional Security 2013-07-11

Details

Check Text ( C-39660r3_chk )
1. Check there are DD Forms 254 available for all classified contracts.

NOTE: These forms may be held by the site contracting officials but should be available to the site security manager and information security manager for review.

2. Conduct a cursory review of the DD 254 to ensure all security requirements are properly detailed on the form, especially with regard to Information Assurance (ie., IT Position level designation).

NOTE: Applicable to tactical environments if there are contractor personnel performing classified work. This form will likely only be found at fixed locations rather than field locations. While the DD 254 may not be available on site or even in Theater, the completed document's location should be identified and if possible a scanned and emailed copy requested for review. This will likely only be able to occur via SIPRNet email because some of these forms contain classified information, while all others are only FOUO.
Fix Text (F-34805r3_fix)
1. DD Forms 254 must be on hand for each classified contract.

2. All security requirements must be properly detailed on the form, particularly for Information technology related requirements, such as IT Position levels for the positions or types of work to be performed.