APPENDIX K - ICE ESS SOW.pdf
PDF 1 MB Posted
- Attached to
- Single Award Construction Contract (SACC) Indefinite Delivery Indefinite Quantity (IDIQ)s Federal contract opportunity
- Solicitation number
- 70CMSW26R00000012
- Issued by
- Immigration and Customs Enforcement
About this file
This is a Scope of Work (SOW) for Electronic Security Systems (ESS) design, procurement, installation, and maintenance at the ICE Advanced Training Operations Center in Fort Benning, Georgia.
The contractor must deliver a turnkey solution encompassing three integrated subsystems: Physical Access Control System (PACS) using Software House C•CURE 9000 Enterprise, Intrusion Detection System (IDS) monitored by Federal Protective Service MegaCenter, and Video Surveillance System (VSS) on an isolated IP-based network. Mandatory PACS requirements include iSTAR controller panels, Innometriks Cheetah SE readers configured with OSDP secure channel protocol and PIV certificate validation, and integration with AiPhone IP-based intercom systems featuring door release capability. IDS must employ Bosch (Radionics) panels with balanced magnetic switches, dual-technology motion detectors, glass break sensors, and duress devices with local annunciation. VSS requires Network Video Recorder equipment with open-file format export capability, supporting 2-megapixel minimum cameras (5-megapixel for critical areas), 30-day minimum storage, and comprehensive coverage of perimeters, detention areas, and high-security zones. The contractor must comply with HSPD-12, FIPS 201-2, NIST 800-53/800-116, ISC Standards, and all applicable NFPA codes. Critical qualifications include GSA MAS SIN 541330SEC certification with CSEIP-certified staff, Software House Enterprise Partner status, three references demonstrating HSPD-12 compliant C•CURE 9000 implementations within five years, and dedicated project management with federal experience. Deliverables include final security designs and device lists within 30 days of award, PACS paperwork and MegaCenter Alarm Requirements form, as-built documentation packages, training materials, and completion of ESS component checklists. The warranty period is one year from acceptance, with 72-hour repair requirements for critical components and 14-day service calls for non-critical items. The contractor must also propose extended warranty and preventative maintenance plans including firmware/software updates and equipment replacement costs.
View the file
Other files for this federal contract opportunity
Show all 47
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Immigration and Customs Enforcement
Office of Professional Responsibility Security Division
Physical Security Operations Unit
Electronic Security Systems (ESS) Scope of Work
E-PACS/IDS/VSS
Ft. Benning Georgia Immigrations and Customs Enforcement
Advance Training Operations Center
Version: 2 June 18, 2026
WARNING: This document is FOR OFFICIAL USE ONLY (FOUO). It contains information that may be exempt from public release under the Freedom of Information Act (5 U.S.C. 552). It is to be controlled, stored, handled, transmitted, distributed, and disposed of in accordance with DHS policy relating to FOUO information and is not to be released to the public or other personnel who do not have a valid "need-to- know" without prior approval of an authorized DHS official.
Document Control: At a minimum, this document, and any products made from this document, will be marked as “FOR OFFICIAL USE ONLY,” disseminated only on a need-to-know basis, and stored in a locked container or password-protected file or system offering sufficient protection against theft, compromise, inadvertent access, and unauthorized disclosure.
When no longer needed, destroy physical copies by shredding, pulping, or burning to assure destruction beyond recognition.
Internal SOW Template Version: 4/8/2022
TABLE OF CONTENTS
SECTION I - GENERAL REQUIREMENTS
1. Project Overview
2. Project Location and Contacts
3. Project Scope
4. Compliance
5. Qualifications
6. Project Site Visit
7. Timeline and Benchmarks
8. Project Closeout
9. Training
10. General Notes
11. Infrastructure
12. Warranty
13. Review and Approvals
SECTION II - ELECTRONIC SECURITY TYPICAL BLOCK DIAGRAMS
SECTION III - ELECTRONIC SECURITY SYSTEMS (ESS) COMPONENT TASKS
A. Physical Access Control (PACS) B. Intrusion Detection Systems (IDS) C. Video Surveillance System (VSS)
SECTION IV - SECURITY SYSTEMS DETAILS
A. Interior Physical Access Control System (PACS) Devices B. Interior Intrusion Detection System (IDS) Devices C. Interior Video Surveillance System (VSS) Devices D. Exterior Physical Access Control System (PACS) Devices E. Exterior Video Surveillance System (VSS) Devices
ATTACHMENTS
PACS Paperwork ESS Component Checklists MegaCenter Alarm Requirements (MAR) Form
SECTION I - GENERAL REQUIREMENTS
1. Project Overview
1.1. The U.S. Immigration and Customs Enforcement (ICE) is the premier Federal Law Enforcement Agency within the U.S. Department of Homeland Security with primary mission to promote homeland security and public safety through the criminal and civil enforcement of federal laws governing border control, customs, trade and immigration.
1.2. ICE requires the Contractor/vendor to design and install our Electronic Security Systems (ESS). The Contractor proposed ESS solution must reflect consideration for the sensitivity of the ICE mission, the safety and security of all personnel, information, facilities and the requirements set forth in this document.
2. Project Location and Contacts
2.1. The place of work performance is the ICE office located at Ft Benning Georgia Immigration & Customs Enforcement Advanced Training Operations Center.
2.2. The following ICE Office of Professional Responsibility (OPR) Field Security Manager (FSM), or his/her supervisor in their absence, is the final technical security authority for this project:
Brian K. Alexander Brian.K.Alexander@ice.dhs.gov
(504) 239-2738
2.3. The ICE Office of Assets and Facilities Management (OAFM) Project Manager is:
Connor Kreston Facilities Portfolio Manager Connor.B.Kreston@associates.ice.dhs .gov Mobile: (215) 630-8171
3. Project Scope
3.1. ICE requires the Security Contractor to design, procure, install, configure, program, test, document, maintain components and installation work through the warranty period and train personnel on a turn-key Electronic Security Systems (ESS). The ESS sub-systems shall include but may not be limited to:
(1) Physical Access Control System (PACS); (2) Intrusion Detection System (IDS); and (3) Video Surveillance System (VSS).
3.2. All programming, software loads and maintenance will be done on-site. The Contractor will not be authorized remote (client) access to the network or systems to perform maintenance, troubleshoot problems, or apply software changes.
3.3. A description of acceptable fielded security devices and typical ESS block diagrams are included in this document for reference. The Contractor may propose other ESS solutions they believe will be beneficial to ICE.
3.4. A detailed listing of all ESS equipment product data (including quantity, make, model, part numbers) and fielded device locations must be provided by The Contractor and approved by the FSM to mailto:Brian.K.Alexander@ice.dhs.gov mailto:Connor.B.Kreston@associates.ice.dhs.gov mailto:Connor.B.Kreston@associates.ice.dhs.gov ensure compliance with this document.
3.5. The Contractor shall provide drawings for each ESS component sub-system (PACS, IDS, VSS) and a combined ESS drawing with all component sub-systems. Drawings shall list each component individually (i.e. workstation(s), panels, enclosures, power supplies, fielded devices) and their installation locations. The Contractor shall ensure that all mounting details and all devices are cross referenced in the drawings including all data cabling that interconnect components, and all power connections.
3.6. Any conflicts between the requirements of this Security SOW and any other project requirements or specifications, to include the ICE Facilities Design Guide (FDG), will be identified to the ICE OAFM Project Manager and FSM for resolution. All coordination and resolution shall occur through prescribed GSA channels.
3.7. This Scope of Work (SOW) will be periodically reviewed to assess the future use of the components described within. ICE reserves the right to change system components listed within this SOW through proper coordination through prescribed GSA channels.
4. Compliance
4.1. In compliance with General Services Administration (GSA) specifications or in the absence of GSA Schedules the following will apply and are required for all U.S. Immigration and Customs Enforcement (ICE) security system projects: Homeland Security Presidential Directive 12 (HSPD-12), Office of Management and Budget (OMB) M-19-17, M-11-11 and M-05-24, Interagency Security Committee (ISC) Standards, Department of Homeland Security (DHS) Management Directive System, National Institute of Standards and Technology (NIST) 800-116 and 800-53, Federal Information Processing Standards (FIPS) 201-2, and Underwriters Laboratory (UL).
4.2. All work performed shall comply with national and local codes, ordinances, regulations, and other legal requirements of the authority having jurisdiction (AHJ), which bear on the performance of work.
The Contractor is to acquire all necessary permits for the completion of this work. All ESS components provided by the Contractor are required to meet applicable regulations, directives and guidelines for that respective activity.
4.3. The Contractor shall comply with the most recent applicable codes and standards published by the National Fire Protection Association (NFPA). This includes, but is not limited to, NFPA 1 Fire Code, NFPA 70 National Electric Code (NEC) and NFPA 101 Life Safety Code.
5. Qualifications
5.1. The Contractor or Sub-Contractor shall strictly adhere to engineering, installation and testing procedures in accordance with the requirements of GSA and equipment manufacturer(s) and maintain a service center near the project site or the ability to expedite parts to the project site within 24 hours.
5.1.1. Contractor or sub-Contractor for PACS - Due to DHS PACS Modernization requirements, Software House C•CURE 9000 is the only Physical Access Control System (PACS) that may be used;
no other PACS systems may be substituted for this project. The Contractor or Sub-Contractor for PACS must:
5.1.1.1. Be an approved vendor of Security System Integration, Design, Management, and Life Cycle Support under the GSA Multiple Award Schedule (MAS) program: SIN541330SEC. This requirement includes services related to PACS design, integration, implementation, and installation/testing. Employees of offerors of this SIN are CSEIP (Certified System Engineer
ICAM PACS) certified, and such certification can be verified at IDmanagment.gov." Offerors under this SIN have at least one employee who is CSEIP (Certified System Engineer ICAM PACS) certified and such certification can be verified at IDmanagment.gov. GSA eLibrary Contractor Listing
5.1.1.2. Be listed as a Software House Enterprise Partner in the Software House Dealer-Certification Program (http://www.swhouse.com/support/Dealer_Certification.aspx), or provide proof of certification.
5.1.1.3. Be qualified to perform the software application functions for Software House C•CURE 9000 Enterprise installation and connectivity back to ICE HQ’s infrastructure
5.1.2. Contractor must provide a minimum of three past performance references demonstrating successful implementation and configuration of a HPSD-12 compliant CCURE9000 solution within the past 5 years.
5.2. Technician - All ESS components shall be installed by an Electronics or Security System Installation Technician. The technician must have sufficient experience, knowledge, skills, and abilities to perform the required tasks for the installation of the ESS as outlined in this scope. The followingskills are preferred:
• Possess a 2-year degree or certification in the electronics discipline from an accredited educational institution or trade school
• Be proficient at maintaining, repairing, and installing access control, intrusion detection/alarm and IP video systems
• Possess the ability to isolate network deficiencies, equipment failures and operational anomalies through use of technical manual reference, diagnostic equipment/software and established troubleshooting techniques
• Have a working knowledge of network architecture with an understanding of IP configuration and transport principals
• Experience in how to run and install conduit and cabling per NEC code
5.3. Specialized Technician - A Specialized Technician for PACS must possess all Technician qualifications as identified above and one of the following current Tyco Software House certifications:
• C•CURE 9000 System Installer/Maintainer
• C•CURE 9000 Advanced Integrator
5.3.1. The certification shall be provided to the FSM upon award of the contract.
5.3.2. During the installation and testing phase, the Contractor shall make no substitutions of specialized technicians unless the substitution is necessitated by illness, death, termination of employment or other non-discretional reason. The Contractor shall notify ICE personnel within five
(5) business days after the occurrence of any of these events and provide a detailed explanation of the circumstances necessitating the proposed substitution, complete credentials for the proposed substitute, and any additional information requested by ICE personnel. All proposed substitutes shall possess the same minimum qualifications as those of the persons being replaced. The ICE personnel will notify the Contractor within fifteen (15) calendar days after receipt of all required information of the decision on the substitution.
http://www.swhouse.com/support/Dealer_Certification.aspx)
5.4. Project Manager - The Contractor shall also ensure that a Project Manager is dedicated to the project from contract award until project acceptance is achieved. The Project Manager shall have:
5.4.1. A minimum of four (4) years of progressive experience in the security systems field, including at least three (3) years in a management capacity directing security systems implementations, preferably on behalf of a federal client.
5.4.2. The Project Manager should also demonstrate experience managing projects of similar size and scope to this ICE project.
5.4.3. The Contractor shall ensure that the Project Manager is on-site for all critical phases of the project. Critical phases include project kickoff, all testing phases for project closeout, final ICE acceptance, and any security coordination meetings to resolve critical issues.
5.5. Systems Engineer - A Systems Engineer with demonstrated experience in the implementation of PKI and federal ICAM architectures for E-PACS of similar size and scope to this ICE project must be used. Professional services by CSEIP Certified Staff required for system installation, on site configuration, commissioning, documentation and acceptance tests.
5.6. The Systems Engineer shall have attained:
5.6.1. Software Ho use C•CURE 9000 Advanced Integrator or C•CURE 9000 Enterprise Architecture certification, and
5.6.2. Be a current Certified System Engineer ICAM PACS (CSEIP) listed on the Secure Technology Alliance Registry (https://www.securetechalliance.org/activities-cseip-registry/).
6. Project Site Visit
6.1. Prior to commencing work, the Contractor is required to perform a site walkthrough with the GSA, ICE Field Security Manager or designated alternate and the local ICE program office management to discuss aspects of the facility and job specific requirements, specific work methods and proposed schedules. If the FSM is not available to meet at the project site, the Contractor may request a conference call through GSA.
6.1.1. The Contractor shall become familiar with local conditions under which work is to be performed and correlate observations with requirements of contract documents.
6.1.2. The Contractor shall identify areas of concern, review important procedural and safety precautions, and agree upon desired installation timetables through a project plan developed by the Contractor.
6.1.3. Before ordering any materials or performing work, the Contractor shall verify space requirements and be responsible for their correctness.
6.1.4. For observation(s) that should be made during the site visit no allowance for claims of concealed conditions by the Contractor shall be made. If in-wall inspections are requested but not allowed, the Contractor shall note this on their quote.
6.1.5. Based on NFPA fire code requirements all doors shall be identified as either fail safe or fail secure during the walkthrough. Doors that require delayed egress will also be identified. ICE http://www.securetechalliance.org/activities-cseip-registry/) perimeter doors and high security doors will typically be fail secure (normally locked) while yet allowing appropriate egress.
7. Timeline and Benchmarks
7.1. The requirement to provide a turnkey solution will necessitate the Contractor to coordinate several actions and deliverables with the Architectural Engineer, General Contractor, other sub-contractors and various ICE program offices. All coordination shall occur through prescribed GSA channels.
7.2. Typically, within 30 days of award, the Contractor shall provide, or incorporate in the overall project schedule, a plan which will address date of completion for the following administrative benchmarks. This information should be displayed in a Gantt Chart or other timeline product with key dates annotated.
Please note that expedited coordination may be required for small projects or urgent circumstances.
Activity / Deliverable Benchmark
Provide final security design/drawings, device lists and updated project schedule
Within 30 days of contract award
Provide product data submittal, proof of certification, etc.
Provide all PACS paperwork (port charts, Input/Output worksheets, etc.) and MegaCenter Alarm Requirements (MAR) form to FSM for review and approval.
Local ICE Office to provide PACS personnel worksheet Coordinate installation of IP connection with project team Coordinate with FSM to provide necessary information for Site Security Addendum Provide final copy of ICE approved MAR form to FPS MegaCenter for programming via FSM. (Minimum 3-
No later than 30 days prior to projected test and acceptance date day turnaround by FPS) Provide confirmation of test and acceptance date Provide Letter of Completion and completed ESS COMPONENT CHECKLISTS to FSM; place approved Port Charts in each PACS panel enclosure
No later than 14 days prior to projected test and acceptance date
Provide training, materials, handouts, passwords, and O&M Manuals (1 complete set)
On projected training date
Completion of punch list corrections Within 14 days of discovery Provide closeout docs Within 30 days of project completion, unless specified otherwise by GSA
8. Project Closeout
8.1. When the Contractor has completed all ESS work, the Contractor is to test and certify the work performed has been completed, and the systems/hardware provided are in good working order. A Letter of Completion must be signed by a senior company official on letterhead identifying each task and ESS component applicable to the certification. The Contractor must complete the ESS COMPONENT CHECKLISTS referenced at the end of this document. The Contractor must follow the prescribed GSA channels when submitting certifications.
8.2. Approximately two weeks after receipt of the Letter of Completion, the ICE Field Security Manager, or designated alternate, and the Contractor will perform a final walk-through inspection and acceptance test of the ESS to ensure the system is complete and acceptable. Inspections and tests will be conducted during the final walk-through, including but not limited to the following:
8.2.1. During the inspection, the Contractor shall demonstrate all equipment and system features, to include emergency power solution demonstration, to ICE Field Security Manager.
8.2.2. Any portions of work found to be deficient or not in compliance with these requirements must be responded to and/or corrected within 14 days. A reasonable time extension may be granted as determined by ICE Field Security Manager. Upon correction of deficiencies, the Contractor shall submit a request in writing for another acceptance test with the ICE Field Security Manager.
8.2.3. After all deficiencies have been corrected and prior to the final acceptance test walk-through there will be a one-week monitoring period of all installed equipment to ensure proper operation.
8.2.4. If all work is found to be acceptable and in compliance with the requirements, the Government will issue a letter of acceptance.
8.2.5. Additional testing may be done or required by the ICE Field Security Manager.
8.3. The start date of the beneficial use and warranty will not commence prior to a successful final walk-through test. Failure of any contractor-provided hardware or software system to perform as specified will be construed as a failure to comply with requirements of the contract.
8.4. The Contractor will provide an as-built package including one electronic PDF format file and three
(3) hard copies of the Electronic Security Systems (ESS) diagrams identifying the locations of all ESS components, unless directed otherwise by the FSM. This will include but is not limited to floor plans, riser diagrams, port charts, door details and device wiring details. Additionally, the as-built package shall contain any other deliverable items to include documents generated as a result of the final walk-through checklist and acceptance testing.
8.5. The Contractor shall provide a training sign-in roster with the closeout documents. The roster shall include a description of the topics covered, date of training, name and signatures of attendees, and name and signature of instructor.
9. Training
9.1. The Contractor shall provide training upon completion and acceptance of the ESS. Training services must provide attendees with the necessary skills to configure, install, operate, and troubleshoot installed security systems and devices. Training is to be a combination of face-to-face lecture and lab instruction with emphasis on hands-on activities. Operational system hardware shall be utilized during training to provide attendees with installed security systems environment familiarization.
9.2. The Contractor will provide a minimum 4-hour basic training session to system operators. The dates and times of each session shall be jointly determined by the ICE supervisor, the Field Security Manager and the Contractor.
9.3. Training material used, a complete set of product manuals, quick reference guides, and a certificate of training completion are to be given to each participant.
9.4. Training will cover all ESS components:
9.4.1. Physical Access Control System (PACS) training topics will include:
• Location and identification of PACS panels and enclosure keys
• Reading controller status and diagnostic information from LCD display
• Identifying card reader type
• Recognition of audio and visual indicators from card readers
• Identifying electronic locking device type (electric strike or mortise electrified lockset)
• Function of Request-to-Exit (REX) device and Door State Monitor (DSM)
• Overview and maintenance of emergency power (how to identify correct battery type and replace, if needed)
9.4.2. Intrusion Detection System (IDS) training topics will include:
• Location and identification of IDS panels and enclosure keys
• Adding and removing personnel from the system (manually via the keypad)
• Activating the Duress and resetting
• Location and resetting of any local Duress annunciation devices
• Performing an annual test with the MegaCenter
• Recognizing and investigating zone/device faults
• How to bypass and un-bypass a zone/device
• Viewing zone/device status
• Resetting sensors
• Silencing and clearing alarms via the keypad
• Overview and maintenance of emergency power (how to identify correct battery type and replace, if needed)
9.4.3. Video Surveillance System (VSS) training topics will include:
• Location and identification of VSS components and any enclosure keys
• Accessing and viewing cameras
• Moving and focusing cameras
• Changing monitor view mode from single to multicamera mode
• Enabling and administering privacy masking
• Searching, retrieving, and reviewing camera videos
• Downloading and exporting video in open file format and proprietary format
• Adding personnel to the system as both operator and administrator roles with passwords
• Overview and maintenance of emergency power (how to identify correct battery type and replace, if needed)
• How to obtain and install future software and firmware updates
10. General Notes
10.1. The Contractor is responsible for damage to any equipment, materials, surfaces or other work disrupted as result of the work. The Contractor will patch and paint any holes and make any repairs to any surface (i.e. walls, doors, ceiling, etc.) that is the result of the Contractor's work. Repair work must match existing construction in grade and likeness. Repair or remuneration will be the sole responsibility of the Contractor. If such work cannot be repaired within a reasonable time, the Government reserves the right to repair damaged equipment, materials or surfaces and offset the costs for such repairs from the awarded contract price. The Contractor will coordinate any anticipated ESS downtime with the ICE FSM and local ICE Program Offices.
10.2. Conflicts between manufacturer’s recommendations, specifications, and/or contract documents must be reported in writing to the GSA or Contracting Officer Representative for resolution.
10.3. All passwords for ESS component systems will be changed from the default and be provided to local management in the training session and recorded in the closeout documentation.
11. Infrastructure
11.1. The Contractor is to install all wiring including, but not limited to, communication and power support necessary for the operation of the ESS. All wiring shall consist of a single, unbroken run that is free of splices and T-Taps. Wiring for all ESS devices shall be tamper resistant. Wiring for all ESS field devices shall not be exposed (i.e. must be internal to a secure space wall, ceilings, doorframes, etc.) upon installation. Wiring for all ESS components shall fully remain within ICE space possible. When it is not feasible for wiring to remain internal to ICE space the Contactor shall provide a tamper resistant or conduit solution. Writing approval by the ICE Field Security Manager is required for any wiring to be placed externally of ICE controlled space.
11.1.1. In compliance with NFPA 70 NEC and as prescribed by the manufacturer, for PACS card readers, all cabling shall be plenum-grade, listed as having adequate fire-resistant and low smoke-producing characteristics.
11.1.2. Additionally, for PACS, the Contractor shall ensure that all cabling within the enclosure does not exceed one spare pair per cable and is properly terminated with a sleeve to prevent unraveling/unwinding.
11.2. For PACS renovation projects, The Contractor is required to remove the existing access control infrastructure including controllers, card readers and reader modules, power supplies, door position switches, request-to exit devices, and cabling. The Contractor may reuse the existing electrified lock sets.
If the Contractor chooses to reuse the existing electrified lock sets, the Contractor shall maintain and at no cost to the government these locks sets during the warranty period. If the Contractor cannot remove existing cable, they shall terminate all cable ends and tag the cable as “Abandoned Security Wire” and shall not re-use any portion of the legacy PACS wire in the new PACS.
11.3. The Contractor shall securely fasten all ESS wiring above drop ceilings to provide adequate support in an approved method and per the latest version of the GSA PBS-P100 Facilities Standards for the Public Building Service and the National Electric Code (NEC). No wiring may be directly in contact with acoustical ceiling tiles. When replacing existing security system wiring the Contractor must remove abandoned ESS wiring in the ceiling. Line security to end devices shall be implemented through End-of- Line resistors installed at the device.
11.4. High security screws must be used for all ESS components that are exposed (i.e. can be viewed externally or are not secured behind a face plate).
11.5. All wiring shall be labeled at both ends using a numerical system to allow for identification. The wire labeling configuration shall be called out on the as-built ESS drawings to be provided and verified during final walk through and acceptance.
11.6. All grounding is to be performed in accordance with ANSI-J-STD-607-A, NFPA 70 NEC and local codes and practices. Grounding for all electrical work performed by The Contractor shall include, but is not limited to, the highlights below:
11.6.1. Provide grounding at security device location and ensure proper bonding to existingfacilities.
11.6.2. Ensure equipment racks are properly grounded to facility grounding buss bar.
11.6.3. Ensure grounding continuity by properly bonding appropriate cabling, closures, cabinets, conduits, service boxes, and head end equipment.
11.6.4. Power shall only be applied to the system after re-checking for proper grounding of the system and measuring all loops for lack of shorts and open circuits.
11.7. The Contractor will provide lockable electronics equipment rack(s), mounts, slides, shelves and other necessary items to install and mount hardware. (Do not install security equipment into ICE OCIO IT racks(s)/cabinet(s) unless approved in writing by the FSM.
11.8. The Contractor’s proposal must identify by square footage all wall and floor space requirements for rack and wall mounted equipment. The Contractor’s proposal must identify by amperage all ESS power requirements to ensure appropriate rated circuit breakers are installed in power panels supporting the equipment.
11.9. The Contractor shall coordinate with GSA and OAFM to request that all security equipment be on its own dedicated electrical circuit. The security technician is not responsible for this; a licensed electrician will need to make sure this is accomplished.
11.10. The Contractor is to provide and install all equipment associated power for ESS operation. All ESS management and backend equipment (i.e. reader controllers, IDS panels, etc.) is to be installed in the suite’s IT LAN room, security equipment room or other secured area, with approval from the FSM.
The Contractor will ensure each equipment room contains sufficient HVAC air circulation and conditioning to support electronic equipment requirements. In each designated equipment room, high quality fire rated plywood, or better, must be installed by the Contractor to support wall mounted backend equipment (i.e. panels, power supplies, etc.).
11.11. The Contractor shall provide and install a minimum of an 8-hour emergency power solution for all ESS hardware. The power solution can be provided through the use of batteries, emergency generators, UPS, or a combination thereof to meet the requirements.
11.11.1. If emergency power is available, via generator, a battery backup must be provided to cover transfer time.
11.11.2. Unless specified differently by the manufacturer, PACS power supplies have 12 Vdc/18ah batteries. Any batteries for IDS panels shall have no less than a 12 Vdc/7ah battery each, unless specified differently by the manufacturer.
11.11.3. For uninterruptable power supply (UPS) installations the UPS must have surge protection and line conditioning features.
11.12. Power supplies to ESS equipment shall be wired to minimize likelihood of accidental disconnect.
Unsecured plug-ins to power supplies not located in a rack or enclosure are not acceptable.
11.13. The Contractor shall ensure that all power supplies are rated to power the maximum load plus a minimum of 10 percent spare capacity. ICE defines maximum load as the simultaneous use of all devices at their maximum current requirements.
11.14. The Contractor shall supply voltage load calculations for each Electrical/LAN closet that supports the PACS. The Contractor shall calculate power supplies and back-up capacity by maximum load.
Separately, The Contractor shall calculate nominal power and typical duty-cycle to determine the duration of the back-up system.
11.15. The Contractor shall ensure that all power supplies to PACS panel(s) are co-located. The Contractor shall ensure that new power supplies are optioned to transmit a trouble condition to the PACS when the following conditions exist: (a) low battery, (b) AC fail.
11.16. The Contractor shall ensure outputs are individually fused and sufficient for the connected load.
The Contractor shall ensure that all battery calculations are based upon peak usage (i.e. simultaneous use of all devices.). The Contractor shall provide batteries sufficiently sized to support the stand-by requirements.
11.17. In compliance with NFPA 101 Life Safety Code means of egress standards and as determined from the pre-construction site walkthrough the Contractor shall ensure that all doors are properly wired for either fail safe or fail secure mode of operation. All egress path doors, unless otherwise designated by the FSM, scheduled with electronic hardware shall unlock from inside the facility upon actuation of a life safety device or fire alarm.
12. Warranty
12.1. A warranty period of one year will commence on official date of use after testing and acceptance by ICE Field Security Manager or designated alternate. ICE shall incur no equipment or labor costs during this warranty period.
12.2. The Contractor will identify a technical support or service contact for consultation during normal business hours, which is reachable by telephone or email.
12.3. Any critical security component that becomes inoperable must be replaced or repaired within 72 hours. Critical components are those required to provide security (PACS, IDS, VSS) for a perimeter access point or high security/critical area.
12.4. For any non-critical component that becomes inoperable, the Contractor shall schedule a service call as soon as practical but not to exceed 14 days.
12.5. The Contractor must notify the customer of all projected downtime and estimated time for repair and provide a written report of all services rendered at time of repair.
12.6. Replacement security devices must be approved by FSM prior to installation.
12.7. ICE shall receive the full benefit of all manufacturers’ warranties on all components beyond the initial warranty period.
12.8. The Contractor shall propose an extended warranty plan that includes ESS equipment replacement costs and hourly labor costs for service requirements. The proposed extended warranty should include the regularly scheduled and routine upkeep of equipment. The repair or replacement of any critical security component, as defined above, must occur within the same timeframe established in this document. For any non-critical security component that becomes inoperable, the Contractor shall schedule a service call as soon as practical.
12.9. The Contractor shall propose a preventative maintenance and repair plan that includes firmware/software updates, equipment replacement costs and hourly labor costs for service requirements.
The proposed maintenance plan should include the regularly scheduled and routine upkeep of equipment and software as prescribed by the manufacturer. The repair or replacement of any critical security component, as defined above, must occur within the same timeframe established in this document. For any non-critical security component that becomes inoperable or requires servicing, the Contractor shall schedule a service call as soon as practical.
13. Review and Approvals
Completed by: Field Security Manager: Brian Alexander
Signature: Date:
Approved by: Regional Security Manager: Steven Tod Ingwersen
Signature:________________________________________________ Date: ______________________
Transmitted to (OAFM PM)
Signature: Date:
SECTION II - ELECTRONIC SECURITY TYPICAL BLOCK DIAGRAMS
REX
DSM
Card Reader iSTAR Controller panel
IRMNet switch
VLAN75
Port(s)
Emergency Power electric locking device
Card Readers iSTARs
ICE Headquarters
PIR
glass break
IDS
Controller IPconnectivity
BMS
FPS MegaCenter duress PIR – Passive infrared motion detector BMS – Balanced Magnetic Switch
Intrusion Detection System (IDS)
REX – Request-to-Exit DSM – Door State Monitor
Enterprise Physical Access Control System (E-PACS)
POE
capable switch
Workstations/ Decoders monitor(s)
IP Network Cameras
Emergency Power NVR
NVR – Network Video Recorder
Video Surveillance System (VSS) – local facility
SECTION III - ELECTRONIC SECURITY SYSTEMS (ESS) COMPONENT TASKS
A. Enterprise Physical Access Control System (E-PACS)
A.1. This ICE location will be established as a client to the ICE E-PACS; no other PACS systems may be substituted for this project. ICE has procured Software House C•CURE 9000 Enterprise Physical Access Control System (E-PACS) to implement HSPD-12 within the Agency. The E-PACS hardware, system architecture and parameters described in this E-PACS task have been approved by the FIPS 201 Evaluation Program and meet the directives, regulations and standards referenced within this document.
No deviation from the products specified and/or described, or from the installation methods identified is allowed.
A.2. Hardware Compatibility. The Contractor is responsible for ensuring the hardware provided is compatible with the ICE Enterprise Software House C•CURE 9000 E-PACS (Approved Products List #10115).
A.3. Connect the iSTAR panel to the designated IRMNET switch/port. The IRMNET switch is Government Furnished Equipment (GFE), and the Contractor is responsible for connecting each iSTAR panel to the IRMNET device for communications over the enterprise network. Contractor must consult with OCIO staff and E-PACS team to ensure panel connectivity with IRMNET.
A.4. PACS Panels.
A.4.1. The only acceptable E-PACS panels for this project are the following Tyco Software House products:
• For E-PACS Panels that require up to 16 readers o iSTAR Ultra G2 (not SE model) o Life Safety FPO250/250-2D8P2M8PNL4E8S/P16-B Power Supply Enclosure
(Supplies power to panel and Innometriks Readers) o Two (2) 12V 18Amp Hour Batteries
• For E-PACS Panels that require only 8 readers o iSTAR Ultra G2 (not SE model) o Life Safety FPO150/150-D8PM8PNL4E6S/P8-A Power Supply Enclosure
(Supplies power to panel and Innometriks Readers) o Two (2) 12V 18Amp Hour Batteries
• For panels requiring up to 4 readers and no more than 16 inputs and 4 outputs o iSTAR Edge2 o Life Safety FPO75/150-D8PM8PNL4E4S-EB01 Power Supply Enclosure o One (1) Life Safety FPO250-2DPE2 Power Supply (Supplies power to panel and
Innometriks Readers) o Two (2) 12V 18 Amp Hour Batteries
A.4.2. Ensure power supply is set to the appropriate voltage. The Innometriks readers will be configured to use 24V.
A.4.3. Power source must deliver at least 4 Amps of in-rush current for initial power up.
A.4.4. If adding Innometriks readers to an existing E-PACS panel:
o 16 readers add Two (2) Life Safety FPO250-2D8PE2 Power Supplies w/two (2) 12V 18
Amp Hour batteries in each enclosure for powering the new Innometriks readers.
o 8 readers add One (1) Life Safety FPO250-2DPE2 Power Supply w/two (2) 12V 18 Amp Hour batteries for powering the new Innometriks readers.
A.4.5. Access Control doors require a UL Listed and Rated Type CMP Plenum Composite cable to support OSDP reader communications, power, and door control.
The cable shall be or equivalent to:
• SMARTWIRE OSDP COMPOSITE CABLE E102194 CL2P (UL) 6C 18+8C
22AWG75C CMP C(UL)RS-485 ROHS.
A.4.6. Ground all reader cable drains or shields at the panel. This is important for reliable connectivity and to prevent comm fails between the Ultra controller and card readers
A.5. E-PACS Programming. The Contractor will provide a completed E-PACS Paperwork (E-PACS Port Charts Form, Input/Output Board Form and as-built drawings showing the location of each card reader) in order for the ICE E-PACS Team to complete programming and for the local ICE Program Office to complete related actions. Local ICE program office personnel are responsible for completing the Personnel Worksheets. Advice on establishing the clearance codes and Master Granting Authority List (MGAL) will be provided by the FSM. The current version of the Port Charts Form will be provided to the Contractor by the ICE Field Security Manager. Prior to final acceptance the Contractor shall ensure acopy of the ICE-approved Port Charts is placed in each PACS panel enclosure.
A.6. Card Reader.
A.6.1. The only acceptable card reader type for this project is the Innometriks Cheetah SE Reader.
This product has been tested and approved as a component of a full FICAM solution. This reader component comprises one aspect of the E-PACS end-to-end solution.
Note: As all PKI validation will be managed centrally through DHS-ICE Headquarters PCN, procuring and installing the Innometriks Validation System and High Assurance Software Suite is NOT required for this project.
Innometrik’s Cheetah SE Reader:
A.6.1.1. Name of Product: Innometriks Cheetah SE A.6.1.2. Part Number: INN-SECHTA-CTO A.6.1.2. Part Number: INN-RDR-LIC (1-Per Reader) A.6.1.3. Firmware must be current manufactures released version A.6.1.4. Approved Products List (APL) #10130
CCURE System Serial Number: 9-17612
Satellite Application Server Serial Number (SAS):
EAST SAS Serial # 9-10527
A.6.2. The Contractor shall ensure card readers are wired to meet factory standards and to ensure proper grounding
A.6.3. The Contractor shall ensure that the card reader is configured using the Open Supervised Device Protocol (OSDP) Secure Channel RS-485 connectivity, and the reader is set in the FICAM mode ensuring high assurance validation of single (PKI-CAK) and dual (PKI-AUTH) at the E-PACS through the challenge-response exchange protocol of the PIV certificates.
A.6.4. The Contractor shall ensure that the card readers are installed in compliance with theAmerican with Disabilities Act (ADA) and Uniform Federal Accessibility Standards (UFAS) and provide the following audio/visual indication:
A.6.4.1. An audio beeper providing various tone sequences to signify access granted, access denied
A.6.4.2. Two LED light bars at the left and right sides of the reader indicate status:
• Red – access denied, or reader not ready
• Green – access granted
• Gold – The gold LED light bar at the bottom of the contact reader indicates reader readiness for user to insert a chip card.
A.6.4.3. The Contractor shall interface the PACS into the ADA/UFAS automatic dooropeners.
A.7. Card Readers. Card readers shall be installed on the same side as the door handle, unless specified otherwise by the FSM.
A.8. Contractor must read the attached Innometriks Cheetah SE Reader Release Notes – Firmware Version 2.2.1 or later version. This document provides important information on installing the Innometriks Cheetah SE Reader.
A.9. Card reader-controlled doors shall be connected to a Door State Monitor (DSM) and Request-to- Exit (REX) device for operation of the door.
A.9.1 The Contractor shall configure doors with a REX device so an authorized egress from the secure area does not cause an alarm. No REX device is necessary if the door is controlled by a card reader on both sides.
A.9.1.1 REX devices can be push-button, motion sensors or incorporated in the mortise electrified lockset and shall shunt the alarm, not release the locking mechanism, unless specified otherwise by applicable NFPA 101 Life Safety Codes or the AHJ.
A.9.1.2 The Contractor shall ensure that the REX is a listed device for the specific operation to provide delay time to the DSM to prevent false alarms and is installed and configured to prevent activation by normal movement inside the secure area.
A.9.1.3 The Contractor shall ensure that the REX remains active for a maximum durationof five
(5) seconds and that the timer is non-resettable.
A.9.1.4 Crash bar/delayed egress exit devices installed on doors must be approved by the FSM and shall have a local annunciator.
A.10. The Contractor shall ensure the DSM connects as an input or output directly to the PACS panels for communication to ICE’s Enterprise C•CURE 9000 server. PACS shall not interface with double-pole, double-throw (DPDT) switches that interface to the IDS.
A.10.1. For all card reader equipped doors the Contractor shall install a DSM that monitors the position of the door so that a forced-door or held-open door causes an alarm.
A.10.2. The DSM shall be concealed, a self-lock mounting, have rugged construction, ¾” in diameter, ABS plastic enclosure, be a hermetically sealed reed switch, be of high security, and is similar in color to the door frame.
A.11. Locks. Electric strikes, electrified mortise locksets and magnetic locks are acceptable locking mechanisms for this project. All locking mechanisms are to return to a locked state immediately after use or within 3 seconds of non-use, unless specified differently by the ICE Field Security Manger. Electric locking mechanisms must meet UL 1034, Standard for Burglary-Resistant Electric Locking Mechanisms and be listed as burglary-resistant. Additionally, electric strikes must meet American NationalStandard for Electric Strikes and Frame Mounted Actuators - ANSI/BHMA A156.31, Grade 1 (Cycle 500,000, Static Strength—Voltage @ 100% and 85% of rated = 1500 pounds., Dynamic Strength— Voltage @ 100% and 85% of rated = 70 ft. lb. (95J).
A.11.1. Additional electric strike specifications:
• Construction: Stainless steel, tamper resistant, internal solenoid
• Operation: Field reversible, plug-in connectors
• Solenoid: Internally mounted to facilitate electric strike installation in hollow metal, concrete filled, and aluminum and wood jambs, operated by direct current to provide silent operation
• Electric Strike: Capable of operation with less than 30 pounds of force against keeper
A.11.2. Additional magnetic lock specifications:
• 600 lbs. holding force to be placed controlled interior rooms and secure areas within buildings
• 1200 lbs. holding force to be placed on detention and perimeter doors
• Magnetic locks shall have magnetic bond sensor
• Power override solution to be proposed for doors not identified as fail safe
A.12. Other Door Hardware. For card reader-controlled doors the Contractor shall provide and install:
A.12.1. A door latch guard which will prevent the lock bolt from being retracted from the unsecure side of the door or install a door strike that engages the guard bolt or auxiliary dead latch located on door hardware.
A.12.2. A functioning heavy-duty door closer.
A.12.3. All deadbolts with minimum 1-inch throw on perimeter or high security doors shall be independent action, not integrated with the card readers. The Contractor shall coordinate with the FSM on which high security doors need deadbolts. As specified in the ICE FDG, the deadbolts required for all ICE perimeter doors, O P R / HSI Seized Evidence Storage Rooms and HSI Computer Forensics Lab shall be Underwriters Laboratories (UL) listed under UL437 and certified under American National Standards Institute (ANSI)/Builder’s Hardware Manufacturer’s Association (BHMA) certification A156.30, Levels M1AAAM and ANSI/BHMA A156.5, Grade 1. In the event the deadbolt is not integrated into the Heavy-Duty Grade 1 Mortised Hardware storeroom function lock, both the lock and cylinder (or core) must meet or exceed the listing and certification requirements specified above.
A.12.4. Transfer hinge for electrified lockset or REX devices, as necessary.
A.12.5. The Contractor will coordinate with the Project Team to ensure there are no conflicts between door hardware and door or door frames.
A.13. Connectivity Handshake. The Contractor shall work with the ICE PACS Team for any network handshakes that will be required to do with the installed E-PACS panels and IRMNET network switch devices. This work is not limited to re-programming the devices to set specifications using the iSTAR Configuration Utility (ICU). The Contractor will remain involved in this task until the connection is successfully completed. After acceptance by ICE the Contractor will provide a CD (or other acceptable electronic medium) with system configurations as a back-up in case of C•CURE server failure.
A.14. The Contractor shall design and install a complete hardwired IP based audio and video intercom system with door station(s) and room master/sub-station(s) based upon the site layout and operational requirements. It shall not have any wireless capability to include interconnection for communications through a wireless router for mobile or remote application management. The system shall be installed in accordance with American National Standards Institute (ANSI) 568 Commercial Building Telecommunication Cabling Standard. A non-IP digital system installation based upon site layout and operational requirements may be authorized based on FSM’s written approval.
A.14.1. The video intercom system will provide door release capability integrated into the Physical Access Control System (PACS) by shunting the system to provide a valid entrance notification when releasing the door. For door release, the system shall be configured as an input into the PACS door control panel to release the lock and shunt the door contact when the door release button has been activated. The intercom system shall not be further integrated into the PACS.
A.14.2. Door station. Door stations installed in outdoor settings shall be vandal resistant and rated for the prevailing weather conditions of the area.
A.14.3. Video capabilities shall contain:
• Equipped with an advanced light adjustment feature to compensate for varying light levels.
If a picture is too dark, increase of the brightness level at the door station shall be controlled at the master/sub-station.
• The door station will be mounted within the manufacturer’s recommendations (typically 5 feet from the ground).
A.14.4. A list of locations/rooms or doors that require video intercoms is contained in the SECURITY SYSTEMS DETAILS section of this document.
A.15. Device Labeling. The Contractor shall label all PACS panels, power supplies, security enclosures, workstations, and any other enclosure installed in support of the project using a plastic label permanently mounted to the door that meets the requirements listed below:
A.15.1. Engraved-- Plastic Labels: Engraving stock, melamine plastic laminate punched or drilled for mechanical fasteners, 1/16-inch minimum thickness for signs up to 20 sq. in. and 1/8-inch minimum thickness for larger sizes. The Contractor shall provide an engraved legend in black letters on white background. Additionally, the Contractor shall label all card readers with the designation on the port charts.
A.15.2. The Contractor shall identify, with ½” lettering, all cabinets including security equipment panels, power supplies, system interface cabinets, and similar security equipment.
A.16. The location of E - PACS fielded devices is identified in the SECURITY SYSTEMS DETAILS section of this document.
ALL INPUTS MUST HAVE END OF LINE RESISTORS
A.17. Workstation Configuration. On a limited, case by case basis, the ICE program office will provide the Contractor with a Software House C•CURE 9000 workstation. Approval to deploy the workstation is granted by the E-PACS Program Manager.
A.17.1. In such a scenario, the Contractor shall procure, install and test the workstation that meets the requirements specified by Software House.
A.17.2. The Contractor is responsible for all costs to ship the workstation to ICE HQ for programming and back to the project site. The Contractor shall ensure a shipping label with a complete return address to the project site is provided. The shipping address is identified above.
A.17.3. The E-PACS Program Office shall assign administrator and operator logons for each workstation at the direction of the FSM.
A.17.4. The Contractor shall ensure that PACS software is accessible from the PACS workstation with administrator / operator log-on for viewing located in the ICE facility. The Contractor shall supply, install and terminate to TIA 586B standard plenum-rated Category 6 cable between workstations and IRMNET network switch device. ICE personnel will provide the Contractor with the network switch location and ports.
A.17.5.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .