STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 1 Release: 3 Benchmark Date: 15 Jun 2020:

Industrial Security - DD Form 254

DISA Rule

SV-41039r3_rule

Vulnerability Number

V-30993

Group Title

Industrial Security - DD Form 254

Rule Version

ID-01.02.01

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. DD Forms 254 must be on hand for each classified contract.

2. All security requirements must be properly detailed on the form, particularly for Information Technology related requirements, such as IT Position levels (in addition to security clearance, training and certification requirements)for the positions or types of work to be performed.

Check Contents

1. Check there are DD Forms 254 available for all classified contracts.

NOTE: These forms may be held by the site contracting officials but should be available to the site security manager and information security manager for review.

2. Conduct a cursory review of the DD 254 to ensure all security requirements are properly detailed on the form, especially with regard to Information Assurance (ie., IT Position level designation) in addition to security clearance, training and certification requirements.

NOTE: Applicable to tactical environments if there are contractor personnel performing classified work. This form will likely only be found at fixed locations rather than field locations. While the DD 254 may not be available on site or even in Theater, the completed document's location should be identified and if possible a scanned and emailed copy requested for review. This will likely only be able to occur via SIPRNet email because some of these forms contain classified information, while all others are only FOUO.

Vulnerability Number

V-30993

Documentable

False

Rule Version

ID-01.02.01

Severity Override Guidance

1. Check there are DD Forms 254 available for all classified contracts.

NOTE: These forms may be held by the site contracting officials but should be available to the site security manager and information security manager for review.

2. Conduct a cursory review of the DD 254 to ensure all security requirements are properly detailed on the form, especially with regard to Information Assurance (ie., IT Position level designation) in addition to security clearance, training and certification requirements.

NOTE: Applicable to tactical environments if there are contractor personnel performing classified work. This form will likely only be found at fixed locations rather than field locations. While the DD 254 may not be available on site or even in Theater, the completed document's location should be identified and if possible a scanned and emailed copy requested for review. This will likely only be able to occur via SIPRNet email because some of these forms contain classified information, while all others are only FOUO.

Check Content Reference

M

Target Key

2506

Comments