0001 - Salient Characteristics .pdf
PDF 2 MB Posted
- Attached to
- 100 ARW Incognito Secure Workstations Federal contract opportunity
- Solicitation number
- FA558725Q0078
About this file
This document is a Salient Characteristics Document for the 100 ARW Secure Incognito Workstations procurement. The requirement is for 3 Trusted System SIPRGuard incognito workstations and 1 additional SIPRGuard two-factor authentication system to be delivered to RAF Mildenhall, specifically to Building 239 (3 workstations) and Building 809 (1 system). The workstations must be constructed from high-quality maple wood in specific dimensions and colors (weathered oak/golden brown and Apple Cider), with unique security features including a concealed armored Information Processing System (IPS) container, two-factor authentication, CAC token login, time-delay motion sensor, and the ability to operate multiple gateways.
The workstations must meet rigorous security compliance standards, including Defense Information Systems Agency (DISA) Security Technical Implementation Guidance (STIG), Cyber Operational Readiness Assessment (CORA), and Trade Agreement Act (TAA) compliance. The IPS container specifications require a GSA class 5 container with 30-man hours resistance against covert entry, 20-man hours against surreptitious entry, and 10-man hours against forced entry. The procurement includes a 1-year warranty and basic operational training, with all shipping and transit costs to be included in the total purchase price. The workstations are designed to remain online 24/7 with up-to-date anti-virus patches and provide secure access to the Secure Internet Protocol Router (SIPR) network.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Solicitation Amendment FA558725Q00780001 SF 30.pdf | ||
| 0002 - Quote Sheet Template.pdf | ||
| Combo Solicitation - FA558725Q0078.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
100 ARW Secure Incognito Workstations – Salient Characteristics Document
Background The 100 ARW Command Team require a secure solution for accessing the Secure Internet Protocol Router (SIPR) network.
Scope This is a brand name, or equivalent requirement includes the installation of 3 (EA) complete secure Trusted System SIPRGuard incognito workstations and a 1 (EA) additional SIPRGuard two-factor authentication system. The requirement includes delivery of 3 desks to building 239, and 1 SIPRGuard to building 809 RAF Mildenhall and the installation of all necessary control devices, wiring, plugs and related equipment on the desk module to gain access to the SIPR network. A 1-year warranty is to be provided as well as basic operational training to be provided with the installation.
Product Specifications The contractor must provide 3 (EA) Trusted System SIPRGuard incognito workstations, brand name or equivalent, each with a concealed armored Information processing System (IPS) container.
Additionally, we require 1 (EA) SIPRGuard and Gateway module to be installed to a Trusted Systems (IPS) container model TSM131V24FC, brand name or equivalent. All equipment must be in new and unused condition and aligned with the following specifications:
• Incognito workstation to be made from high quality maple wood o 1 x Rectangle 71 in x 31in with an opening for legs to go under; Color: weathered oak/golden brown o 1 x L-Shaped 94 in x 74 in x (inner side of desk – sitting area -51 in) with an opening for legs to go under; Color: weathered oak/golden brown o 1 x L-Shaped 84 in x 64 in x (inner side of desk – sitting area -41 in) with an opening for legs to go under; Color: Apple Cider
• Pull out shelf for mouse and keyboard
• Two factor authentication – pin and fingerprint on a desktop module
• Connect desktop KVM and ethernet devices to the network equipment secured in an IPS
Container
• CAC token log in access without opening the IPS Container
• Time delay motion sensor to kill the circuit when the desktop is left unattended
• Manual on/off control
• Ability to operate multiple gateways from a single desktop and control module allowing for multiuser, multidomain and multimedia output
• Defense Information Systems Agency (DISA) Security Technical Implementation Guidance
(STIG) and Cyber Operational Readiness Assessment (CORA) compliance
• Trade Agreement Act (TAA) compliance
• Ability to remain online 24/7
• Anti-virus patches that remain up to date
IPS Container specifications
• General Services Administration (GSA) class 5 container
• Armored computer cabinet that is concealed within the desk
• 30-man hours against covert entry
• 20-man hours against surreptitious entry
• 10-man hours against forced entry
• Federal specification FF-L-2740 lock
• Temperature controlled cooling system
• Slide out rack with push button release
Shipping Instructions
• Shipment shall be FOB destination to Building 239 (3 complete incognito workstations) and
Building 809 (1 SIPRGuard system) RAF Mildenhall, Suffolk, England IP28 8NG.
• All shipping and transit costs must be included as part of the total purchase price submitted to the Government (vendor to include shipping costs in the costs of the items).
• The Government will provide the vendor with the point of contact for the delivery upon award. The delivery will be inspected/accepted by the same POC.
Appendix: Related Documents
STIG: Security checklist V2 R6: V-245825 (IS-01.02.01) - attached below
CORA Concept of Operations:
TAA Compliance: https://vsc.gsa.gov/drupal/node/138
Color Palettes:
Weathered Oak/Golden Brown
Apple Cider https://vsc.gsa.gov/drupal/node/138
Storage/Handling of Classified Documents, Media, Equipment - must be under continuous personal protection and control of an authorized (cleared) individual OR guarded or stored in an approved locked security container
(safe), vault, secure room, collateral classified open storage area or SCIF.
Quick Actions
STIG VIEWER
https://stigviewer.com/ https://stigviewer.com/
We are continuing to improve Stigviewer and we are planning on rolling out new services in the near future. Would you like to be part of the conversation on what those features should be? If so, click here.
Overview
Finding
ID
Version Rule ID
IA
Controls Severity
V-
245825
IS-
05.01.01
SV-
245825r822882_rule High
Description https://stigviewer.com/survey
STIG Date
Traditional Security Checklist 2024-08-09
Details
Check Text (C-49256r770135_chk)
1. In areas containing SIPRNet assets - Check to ensure that classified documents, information system (IS) equipment and removable media that is not under the direct personal control and observation of an authorized person is guarded or stored in a locked security container (GSA approved safe), vault, secure room, collateral classified open storage area or SCIF with protection equal to or exceeding the highest classification of the material/equipment. (CAT
I)
2. Check to ensure that site security personnel develop written procedures for response to incidents of classified materials found not in secure storage or under continuous observation and control of a cleared employee and make the procedures readily available to each employee via electronic means, such as in space on an organizational intranet, shared folders or other means available. (CAT III)
Procedures for response to classified materials discovered that are not in proper storage or under proper control of a cleared person must include the following:
a. Site security personnel, security reviewers/inspectors, employees or anyone making discovery of classified material not in secure storage or under continuous observation and control of a cleared employee immediately take control and properly secure the classified materials not under proper control when not in approved storage.
Second they must report the discovery to their supervisory chain and/or site security officials. (CAT III)
b. Site security personnel must initiate a preliminary inquiry if appropriate to determine the cause of the improperly secure material and to determine if any material was lost or compromised (security incident). (CAT III)
c. Site security personnel must conduct remedial training action https://stigviewer.com/stigs/traditional_security_checklist subsequent to incidents of classified materials found not in secure storage or under continuous observation and control of a cleared employee to remind employees of procedures and requirements to maintain positive control of classified materials removed from approved storage. (CAT III)
d. Site managers/supervisors must discipline employees, as appropriate who do not comply with appropriate requirements to maintain positive control of classified material they have removed from secure storage. (CAT III)
3. Check to ensure that's site security personnel conduct initial and annual training to indoctrinate and remind employees of procedures and requirements to maintain positive control of classified materials removed from approved storage and measures to take upon discovery of classified material not in proper storage or under proper control of a cleared person. (CAT II)
Suggested methodology for reviewers:
During the review/walk-around be observant for classified materials
(documents media, and equipment) that have been removed from approved storage. Specifically look to determine if employees are maintaining positive control of the material. Unless a properly cleared employee is able to clearly see and control the material - this will be a finding.
The employee(s) must be specifically aware the classified material is in their area AND that they are responsible for ensuring it is controlled/protected. Just having cleared employee(s) "in the area" of the classified material or assuming other cleared employees in the area are responsible for the classified material is not sufficient control.
An example of a possible finding is when someone working on a classified system departs their work space (cube environment) for lunch or other type of break and does not ask another cleared employee to take control of their classified equipment, documents or media OR does not place the classified hard drive, classified documents and classified media in approved storage.
TACTICAL ENVIRONMENT: This check is applicable in a tactical environment.
The only exception will be where there is a lack of permanent storage solutions for urgent (short term) tactical operations or other contingency situations. Primarily this involves field/mobile environments where fixed facilities and equipment are not yet present or incapable of being used. However, all classified equipment, documents or media not properly stored in a safe, vault or secure room must still be under the continuous observation and control of an appropriately cleared person.
Fix Text (F-49211r770136_fix)
Primary Requirements for Control of Classified Material:
Classified documents, information system (IS) equipment and removable media must be:
1. Under the direct personal control and observation of an authorized person, who possesses a security clearance and need-to know equal to or greater than the classified information or material being controlled. The properly cleared employee(s) must be able to clearly see and control the classified material. The employee(s) must be specifically aware the classified material is in their area AND that they are responsible for ensuring it is protected.
or
2. Guarded by a trained professional security official who possesses a security clearance equal to or greater than the classified information or material being controlled.
or
3. Stored in a locked security container (GSA approved safe), vault, secure room, collateral classified open storage area or SCIF with protection equal to or exceeding the highest classification of the material/equipment.
Secondary Requirements:
Actions to enhance protection of classified materials:
1. Site security personnel must conduct initial and annual training to indoctrinate and remind employees of procedures and requirements to maintain positive control of classified materials removed from approved storage.
2. Site security personnel must develop written procedures for protection and storage of classified materials and make the procedures readily available to each employee via electronic means, such as in space on an organizational intranet, shared folders or other means available.
3. Site security personnel must conduct regular checks of their areas of responsibility and constantly be observant to ensure that classified materials (documents media, and equipment) that have been removed from approved storage are under the continuous personal observation and control of cleared persons.
Tertiary Requirements:
Required Actions upon discovery of classified material not in secure storage or under continuous observation and control of a cleared employee:
1. Site security personnel, security reviewers/inspectors, employees or anyone making discovery of classified material not in secure storage or under continuous observation and control of a cleared employee must immediately take control and properly secure any classified materials not under proper control when not in approved storage. Second they must report the discovery to their supervisory chain and/or site security officials.
2. Site security personnel must initiate a preliminary inquiry if appropriate to determine the cause of the improperly secure material and to determine if any material was lost or compromised (security incident).
3. Site security personnel must develop written procedures for response to incidents of classified materials found not in secure storage or under continuous observation and control of a cleared employee and make the procedures readily available to each employee via electronic means, such as in space on an organizational intranet, shared folders or other means available.
4. Site security personnel must conduct remedial training action subsequent to incidents of classified materials found not in secure storage or under continuous observation and control of a cleared employee to remind employees of procedures and requirements to maintain positive control of classified materials removed from approved storage.
5. Site managers/supervisors must discipline employees, as appropriate who do not comply with appropriate requirements to maintain positive control of classified material they have removed from secure storage.
STIG VIEWER
A comprehensive tool for accessing, analyzing, and implementing Defense Information Systems Agency
(DISA) Security Technical Implementation Guides (STIGs).
Support
Contact Us
FAQ
Newsletter Sign Up
Our Address
OpenControls.ai
254 Chapman Rd Ste 208 PMB 22000
Newark, DE 19702-5422
United States https://stigviewer.com/contact_us https://public.cyber.mil/stigs/faqs/
Appendix: Related Documents
File details come from the government source that posted it. Updated .