8.08 _ 70CMSD21Q00000044 Attachment 2 - SOW.pdf

PDF 776 KB Posted

Attached to
Electronic Security Services (ESS) Federal contract opportunity
Solicitation number
70CMSD21Q00000044
Issued by
Immigration and Customs Enforcement

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Immigration and Customs Enforcement

Office of Professional Responsibility

Security Division

Physical Security Operations Unit

Electronic Security Systems (ESS)

Scope of Work

IDS/VSS Upgrade and EPACS Modifications

Location: ERO/HSI

3950 Faber Place Dr.

N. Charleston, SC.

(SC2345)

Version: (4) January 29, 2021

WARNING: This document is FOR OFFICIAL USE ONLY

(FOUO). It contains information that may be exempt from public release under the Freedom of Information Act (5 U.S.C.

552). It is to be controlled, stored, handled, transmitted, distributed, and disposed of in accordance with DHS policy relating to FOUO information and is not to be released to the public or other personnel who do not have a valid "need-to-know" without prior approval of an authorized DHS official.

Document Control: At a minimum, this document, and any products made from this document, will be marked as “FOR

OFFICIAL USE ONLY,” disseminated only on a need-to-know basis, and stored in a locked container or password-protected file or system offering sufficient protection against theft, compromise, inadvertent access, and unauthorized disclosure.

When no longer needed, destroy physical copies by shredding, pulping, or burning to assure destruction beyond recognition.

SOW Version: 12-15-2018 https://icegov.sharepoint.com/sites/opr/sec/ps/np/Shared%20Documents/Forms/AllItems.aspx?id=%2Fsites%2Fopr%2Fsec%2Fps%2Fnp%2FShared%20Documents%2FSOW%20Templates

TABLE OF CONTENTS

SECTION I - GENERAL REQUIREMENTS

1. Project Overview

2. Project Location and Contacts

3. Project Scope

4. Compliance

5. Qualifications

6. Project Site Visit

7. Timeline and Benchmarks

8. Project Closeout

9. Training

10. General Notes

11. Infrastructure

12. Warranty

13. Review and Approvals

SECTION II - ELECTRONIC SECURITY TYPICAL BLOCK DIAGRAMS

SECTION III - ELECTRONIC SECURITY SYSTEMS (ESS) COMPONENT TASKS

A. Physical Access Control (PACS)

B. Intrusion Detection Systems (IDS)

C. Video Surveillance System (VSS)

SECTION IV - SECURITY SYSTEMS DETAILS

A. Interior Physical Access Control System (PACS) Devices

B. Interior Intrusion Detection System (IDS) Devices

C. Interior Video Surveillance System (VSS) Devices

D. Exterior Physical Access Control System (PACS) Devices

E. Exterior Video Surveillance System (VSS) Devices

ATTACHMENTS

PACS Paperwork

ESS Component Checklists

MegaCenter Alarm Requirements (MAR) Form

SECTION I - GENERAL REQUIREMENTS

1. Project Overview

1.1. The U.S. Immigration and Customs Enforcement (ICE) is the premier Federal Law Enforcement

Agency within the U.S. Department of Homeland Security with primary mission to promote homeland security and public safety through the criminal and civil enforcement of federal laws governing border control, customs, trade and immigration.

1.2 ICE requires the Contractor/vendor to design and install our Electronic Security Systems (ESS). The

Contractor proposed ESS solution must reflect consideration for the sensitivity of the ICE mission, the safety and security of all personnel, information, facilities and the requirements set forth in this document.

2. Project Location and Contacts

2.1 The place of work performance is the ICE office located at 3950 Faber Place Dr. North Charleston, SC.

2.2. The following ICE Office of Professional Responsibility (OPR) Field Security Manager (FSM), or his/her supervisor in their absence, is the final technical security authority for this project:

Rance Culver, Field Security Manager, ICE/OPR

904-288-4718 (Office)

202-336-9396 (Cell)

Email: Rance.A.Culver@ice.dhs.gov

2.3. The ICE Office of Assets and Facilities Management (OAFM) Project Manager is:

Robert Swann, Space Management Specialist, Region 4

ICE Office of Asset & Facilities Management

202-732-6321 (Office)

202-577-1070 (Mobile)

Email: robert.b.swann@ice.dhs.gov

2.4 The ICE field office program management point(s) of contact is:

Jimmy D. (J.D.) Thorp, AFOD

Enforcement and Removal Operations (ERO)

843-746-2806 (Office)

229-321-0567 (Mobile)

Email: Jimmy.D.Thorp@ice.dhs.gov

Michael (Mike) Carver, TEO

Homeland Security Investigations (HSI)

843-200-5944 (Office)

Email: Michael.L.Carver@ice.dhs.gov

3. Project Scope mailto:Rance.A.Culver@ice.dhs.gov mailto:robert.b.swann@ice.dhs.gov mailto:Jimmy.D.Thorp@ice.dhs.gov mailto:Michael.L.Carver@ice.dhs.gov

3.1. ICE requires the Security Contractor to design, procure, install, configure, program, test, document, maintain components and installation work through the warranty period and train personnel on a turn-key

Electronic Security Systems (ESS). The ESS sub-systems shall include but may not be limited to: (1)

Physical Access Control System (PACS); (2) Intrusion Detection System (IDS); and (3) Video Surveillance

System (VSS).

3.2. All programming, software loads and maintenance will be done on-site. The Contractor will not be authorized remote (client) access to the network or systems to perform maintenance, troubleshoot problems, or apply software changes.

3.3. A description of acceptable fielded security devices and typical ESS block diagrams are included in this document for reference. The Contractor may propose other ESS solutions they believe will be beneficial to ICE.

3.4. A detailed listing of all ESS equipment product data (including quantity, make, model, part numbers) and fielded device locations must be provided by The Contractor and approved by the FSM to ensure compliance with this document.

3.5. The Contractor shall provide drawings for each ESS component sub-system (PACS, IDS, VSS) and a combined ESS drawing with all component sub-systems. Drawings shall list each component individually

(i.e. workstation(s), panels, enclosures, power supplies, fielded devices) and their installation locations. The

Contractor shall ensure that all mounting details and all devices are cross referenced in the drawings including all data cabling that interconnect components, and all power connections.

3.6. Any conflicts between the requirements of this Security SOW and any other project requirements or specifications, to include the ICE Facilities Design Guide (FDG), will be identified to the ICE OAFM

Project Manager and FSM for resolution. All coordination and resolution shall occur through prescribed

GSA channels.

3.7. This Scope of Work (SOW) will be periodically reviewed to assess the future use of the components described within. ICE reserves the right to change system components listed within this SOW through proper coordination through prescribed GSA channels.

4. Compliance

4.1. In compliance with General Services Administration (GSA) specifications or in the absence of GSA

Schedules the following will apply and are required for all U.S. Immigration and Customs Enforcement

(ICE) security system projects: Homeland Security Presidential Directive 12 (HSPD-12), Office of

Management and Budget (OMB) M-11-11 and M-05-24, Interagency Security Committee (ISC) Standards, Department of Homeland Security (DHS) Management Directive System, National Institute of Standards and Technology (NIST) 800-116 and 800-53, Federal Information Processing Standards (FIPS) 201-2, and

Underwriters Laboratory (UL).

4.2. All work performed shall comply with national and local codes, ordinances, regulations, and other legal requirements of the authority having jurisdiction (AHJ), which bear on the performance of work. The

Contractor is to acquire all necessary permits for the completion of this work. All ESS components provided by the Contractor are required to meet applicable regulations, directives and guidelines for that respective activity.

4.3. The Contractor shall comply with the most recent applicable codes and standards published by the

National Fire Protection Association (NFPA). This includes, but is not limited to, NFPA 1 Fire Code, NFPA 70 National Electric Code (NEC) and NFPA 101 Life Safety Code.

5. Qualifications

5.1. The Contractor or Sub-Contractor shall strictly adhere to engineering, installation and testing procedures in accordance with the requirements of GSA and equipment manufacturer(s) and maintain a service center near the project site or the ability to expedite parts to the project site within 24 hours.

5.1.1. Contractor or sub-Contractor for PACS - Due to DHS PACS Modernization requirements, Software House C•CURE 9000 is the only Physical Access Control System (PACS) that may be used;

no other PACS systems may be substituted for this project. The Contractor or Sub-Contractor for

PACS must:

5.1.1.1. Be an approved vendor of FIPS 201 compliant PACS components and services on

Federal Acquisition Service (FAS) Schedule 84, or of HSPD-12 product and service components on FAS Schedule 70.

5.1.1.2. Be listed in the Software House Dealer Certification Program

(http://www.swhouse.com/support/Dealer_Certification.aspx), or provide proof of certification.

5.1.1.3. Be qualified to perform the software application functions for Software House

C•CURE 9000 Enterprise installation and connectivity back to ICE HQ’s infrastructure

5.2. 5.2. Technician - All ESS components shall be installed by an Electronics or Security System

Installation Technician. The technician must have sufficient experience, knowledge, skills, and abilities to perform the required tasks for the installation of the ESS as outlined in this scope. The following skills are preferred:

• Possess a 2-year degree or certification in the electronics discipline from an accredited educational institution or trade school

• Be proficient at maintaining, repairing, and installing access control, intrusion detection/alarm and IP video systems

• Possess the ability to isolate network deficiencies, equipment failures and operational anomalies through use of technical manual reference, diagnostic equipment/software and established troubleshooting techniques

• Have a working knowledge of network architecture with an understanding of IP configuration and transport principals

• Experience in how to run and install conduit and cabling per NEC code

5.3. Specialized Technician - A Specialized Technician for PACS must possess all Technician qualifications as identified above and one of the following current Tyco Software House certifications:

• C•CURE 9000 System Installer/Maintainer (AC9001)

• C•CURE 9000 Advanced Integrator (AC9005)

5.3.1. The certification shall be provided to the FSM upon award of the contract.

http://www.swhouse.com/support/Dealer_Certification.aspx

5.3.2. During the installation and testing phase, the Contractor shall make no substitutions of specialized technicians unless the substitution is necessitated by illness, death, termination of employment or other non-discretional reason. The Contractor shall notify ICE personnel within five

(5) business days after the occurrence of any of these events and provide a detailed explanation of the circumstances necessitating the proposed substitution, complete credentials for the proposed substitute, and any additional information requested by ICE personnel. All proposed substitutes shall possess the same minimum qualifications to those of the persons being replaced. The ICE personnel will notify the

Contractor within fifteen (15) calendar days after receipt of all required information of the decision on the substitution.

5.4. Project Manager - The Contractor shall also ensure that a Project Manager is assigned to the project from contract award until project acceptance is achieved. The Project Manager shall have:

5.4.1. A minimum of four (4) years of progressive experience in the security systems field, including at least three (3) years in a management capacity directing security systems implementations, preferably on behalf of a Federal client.

5.4.2. The Project Manager should also demonstrate experience managing projects of similar size and scope to this ICE project.

5.4.3. The Contractor shall ensure that the Project Manager is on-site for all critical phases of the project. Critical phases include project kickoff, all testing phases for project closeout, final ICE acceptance, and any security coordination meetings to resolve critical issues.

6. Project Site Visit

6.1. Prior to commencing work, the Contractor is required to perform a site walkthrough with the GSA, ICE Field Security Manager or designated alternate and the local ICE program office management to discuss aspects of the facility and job specific requirements, specific work methods and proposed schedules. If the FSM is not available to meet at the project site, the Contractor may request a conference call through GSA.

6.1.1. The Contractor shall become familiar with local conditions under which work is to be performed and correlate observations with requirements of contract documents.

6.1.2. The Contractor shall identify areas of concern, review important procedural and safety precautions, and agree upon desired installation timetables through a project plan developed by the

Contractor.

6.1.3. Before ordering any materials or performing work, the Contractor shall verify space requirements and be responsible for their correctness.

6.1.4. For observation(s) that should be made during the site visit no allowance for claims of concealed conditions by the Contractor shall be made. If in-wall inspections are requested but not allowed, the Contractor shall note this on their quote.

6.1.5. Based on NFPA fire code requirements all doors shall be identified as either fail safe or fail secure during the walkthrough. Doors that require delayed egress will also be identified. ICE perimeter doors and high security doors will typically be fail secure (normally locked) while yet allowing appropriate egress.

7. Timeline and Benchmarks

7.1. The requirement to provide a turnkey solution will necessitate the Contractor to coordinate several actions and deliverables with the Architectural Engineer, General Contractor, other sub-contractors and various ICE program offices. All coordination shall occur through prescribed GSA channels.

7.2. Typically, within 30 days of award, the Contractor shall provide, or incorporate in the overall project schedule, a plan which will address date of completion for the following administrative benchmarks. This information should be displayed in a Gantt Chart or other timeline product with key dates annotated. Please note that expedited coordination may be required for small projects or urgent circumstances.

Activity / Deliverable Benchmark

Provide final security design/drawings, device lists and updated project schedule

Within 30 days of contract award

Provide product data submittal, proof of certification, etc.

*Provide all PACS PAPERWORK (Port Charts, Input/Output Worksheets, etc.), and

MEGACENTER ALARM REQUIREMENTS

FORM to FSM for review and approval

Local ICE office(s) to provide PACS Personnel

Worksheets

Coordinate installation of POTS or IP connection with project team

Coordinate with FSM to provide necessary information for Site Security Addendum

Provide final copy of ICE-approved

MEGACENTER ALARM REQUIREMENTS

FORM to FPS MegaCenter for programming via

FSM (minimum 3-day turn around)

No later than 30 days prior to projected test and acceptance date

Provide confirmation of test and acceptance date

Provide Letter of Completion and completed ESS

COMPONENT CHECKLISTS to FSM; place approved Port Charts in each PACS panel enclosure

No later than 14 days prior to projected test and acceptance date

Provide training, materials and handouts On projected training date

Completion of punch list corrections Within 14 days of discovery

Provide closeout docs

Within 30 days of project completion, unless specified otherwise by GSA

8. Project Closeout

8.1. When the Contractor has completed all ESS work, the Contractor is to test and certify the work performed has been completed, and the systems/hardware provided are in good working order. A Letter of

Completion must be signed by a senior company official on letterhead identifying each task and ESS component applicable to the certification. The Contractor must complete the ESS COMPONENT

CHECKLISTS referenced at the end of this document. The Contractor must follow the prescribed GSA channels when submitting certifications.

8.2. Approximately two weeks after receipt of the Letter of Completion, the ICE Field Security Manager, or designated alternate, and the Contractor will perform a final walk-through inspection and acceptance test of the ESS to ensure the system is complete and acceptable. Inspections and tests will be conducted during the final walk-through, including but not limited to the following:

8.2.1. During the inspection, the Contractor shall demonstrate all equipment and system features, to include emergency power solution demonstration, to ICE Field Security Manager.

8.2.2. Any portions of work found to be deficient or not in compliance with these requirements must be responded to and/or corrected within 14 days. A reasonable time extension may be granted as determined by ICE Field Security Manager. Upon correction of deficiencies, the Contractor shall submit a request in writing for another acceptance test with the ICE Field Security Manager.

8.2.3. After all deficiencies have been corrected and prior to the final acceptance test walk-through there will be a one-week monitoring period of all installed equipment to ensure proper operation.

8.2.4. If all work is found to be acceptable and in compliance with the requirements, the Government will issue a letter of acceptance.

8.2.5. Additional testing may be done or required by the ICE Field Security Manager.

8.3. The start date of the beneficial use and warranty will not commence prior to a successful final walk-through test. Failure of any contractor-provided hardware or software system to perform as specified will be construed as a failure to comply with requirements of the contract.

8.4. The Contractor will provide an as-built package including one electronic PDF format file and three (3) hard copies of the Electronic Security Systems (ESS) diagrams identifying the locations of all ESS components, unless directed otherwise by the FSM. This will include but is not limited to floor plans, riser diagrams, port charts, door details and device wiring details. Additionally, the as-built package shall contain any other deliverable items to include documents generated as a result of the final walk through checklist and acceptance testing.

8.5 The Contractor shall provide a training sign-in roster with the closeout documents. The roster shall include a description of the topics covered, date of training, name and signatures of attendees, and name and signature of instructor.

9. Training

9.1. The Contractor shall provide training upon completion and acceptance of the ESS. Training services must provide attendees with the necessary skills to configure, install, operate, and troubleshoot installed security systems and devices. Training is to be a combination of face-to-face lecture and lab instruction with emphasis on hands-on activities. Operational system hardware shall be utilized during training to provide attendees with installed security systems environment familiarization.

9.2. The Contractor will provide a minimum 4-hour basic training session to system operators. The dates and times of each session shall be jointly determined by the ICE supervisor, the Field Security Manager and the Contractor.

9.3. Training material used, a complete set of product manuals, quick reference guides, and a certificate of training completion are to be given to each participant.

9.3. Training will cover all ESS components:

9.3.1. Physical Access Control System (PACS) training topics will include:

• Location and identification of PACS panels and enclosure keys

• Reading controller status and diagnostic information from LCD display

• Identifying card reader type

• Recognition of audio and visual indicators from card readers

• Identifying electronic locking device type (electric strike or mortise electrified lockset)

• Function of Request-to-Exit (REX) device and Door State Monitor (DSM)

• Overview and maintenance of emergency power

9.3.2. Intrusion Detection System (IDS) training topics will include:

• Location and identification of IDS panels and enclosure keys

• Adding and removing personnel from the system (manually via the keypad)

• Activating the Duress and resetting

• Location and resetting of any local Duress annunciation devices

• Performing an annual test with the MegaCenter

• Recognizing and investigating zone/device faults

• How to bypass and un-bypass a zone/device

• Viewing zone/device status

• Resetting sensors

• Silencing and clearing alarms via the keypad

• Overview and maintenance of emergency power (how to identify correct battery type and replace, if needed)

9.3.3. Video Surveillance System (VSS) training topics will include:

• Location and identification of VSS components and any enclosure keys

• Accessing and viewing cameras

• Moving and focusing cameras

• Changing monitor view mode from single to multicamera mode

• Enabling and administering privacy masking

• Searching, retrieving and reviewing camera video

• Downloading and exporting video in open file format and proprietary format

• Adding personnel to the system as both operator and administrator roles with passwords

• Overview and maintenance of emergency power

• How to obtain and install future software and firmware updates

10. General Notes

10.1. The Contractor is responsible for damage to any equipment, materials, surfaces or other work disrupted as result of the work. The Contractor will patch and paint any holes and make any repairs to any surface (i.e. walls, doors, ceiling, etc.) that is the result of the Contractor's work. Repair work must match existing construction in grade and likeness. Repair or remuneration will be the sole responsibility of the

Contractor. If such work cannot be repaired within a reasonable time, the Government reserves the right to repair damaged equipment, materials or surfaces and offset the costs for such repairs from the awarded contract price. The Contractor will coordinate any anticipated ESS downtime with the ICE FSM and local

ICE Program Offices.

10.2. Conflicts between manufacturer’s recommendations, specifications, and/or contract documents must be reported in writing to the GSA or Contracting Officer Representative for resolution.

10.3. All passwords for ESS component systems will be changed from the default and be provided to local management in the training session and recorded in the closeout documentation.

11. Infrastructure

11.1. The Contractor is to install all wiring including, but not limited to, communication and power support necessary for the operation of the ESS. All wiring shall consist of a single, unbroken run that is free of splices and T-Taps. Wiring for all ESS devices shall be tamper resistant. Wiring for all ESS field devices shall not be exposed (i.e. must be internal to a secure space wall, ceilings, doorframes, etc.) upon installation. Wiring for all ESS components shall remain within ICE space to the fullest extent possible.

When it is not feasible for wiring to remain internal to ICE space the Contactor shall provide a tamper resistant or conduit solution. Written approval by the ICE Field Security Manager is required for any wiring to be placed external of ICE controlled space.

11.1.1. In compliance with NFPA 70 NEC and as prescribed by the manufacturer, for PACS card readers, all cabling shall be plenum-grade, listed as having adequate fire-resistant and low smoke-producing characteristics.

11.1.2. Additionally, for PACS, the Contractor shall ensure that all cabling within the enclosure does not exceed one spare pair per cable and is properly terminated with a sleeve to prevent unraveling/unwinding.

11.2. For PACS renovation projects, The Contractor is required to remove the existing access control infrastructure including controllers, card readers and reader modules, power supplies, door position switches, request-to exit devices, and cabling. The Contractor may reuse the existing electrified lock sets. If the Contractor chooses to reuse the existing electrified lock sets, the Contractor shall maintain and at no cost to the government these locks sets during the warranty period. If the Contractor cannot remove existing cable, they shall terminate all cable ends and tag the cable as “Abandoned Security Wire” and shall not re-use any portion of the legacy PACS wire in the new PACS.

11.3. The Contractor shall securely fasten all ESS wiring above drop ceilings to provide adequate support in an approved method and per the latest version of the GSA PBS-P100 Facilities Standards for the Public

Building Service and the National Electric Code (NEC). No wiring may be directly in contact with acoustical ceiling tiles. When replacing existing security system wiring the Contractor must remove abandoned ESS wiring in the ceiling. Line security to end devices shall be implemented through End-of-

Line resistors installed at the device.

11.4. High security screws must be used for all ESS components that are exposed (i.e. can be viewed externally or are not secured behind a face plate).

11.5. All wiring shall be labeled at both ends using a numerical system to allow for identification. The wire labeling configuration shall be called out on the as-built ESS drawings to be provided and verified during final walk through and acceptance.

11.6. All grounding is to be performed in accordance with ANSI-J-STD-607-A, NFPA 70 NEC and local codes and practices. Grounding for all electrical work performed by The Contractor shall include, but is not limited to, the highlights below:

11.6.1. Provide grounding at security device location and ensure proper bonding to existing facilities.

11.6.2. Ensure equipment racks are properly grounded to facility grounding buss bar.

11.6.3. Ensure grounding continuity by properly bonding appropriate cabling, closures, cabinets, conduits, service boxes, and head end equipment.

11.6.4. Power shall only be applied to the system after re-checking for proper grounding of the system and measuring all loops for lack of shorts and open circuits.

11.7. The Contractor will provide lockable electronics equipment rack(s), mounts, slides, shelves and other necessary items to install and mount hardware.

11.8. The Contractor’s proposal must identify by square footage all wall and floor space requirements for rack and wall mounted equipment. The Contractor’s proposal must identify by amperage all ESS power requirements to ensure appropriate rated circuit breakers are installed in power panels supporting the equipment.

11.9. The Contractor shall coordinate with GSA and OAFM to request that all security equipment be on its own dedicated electrical circuit. The security technician is not responsible for this; a licensed electrician will need to make sure this is accomplished.

11.10. The Contractor is to provide and install all equipment associated power for ESS operation. All ESS management and backend equipment (i.e. reader controllers, IDS panels, etc.) is to be installed in the suite’s IT LAN room, security equipment room or other secured area, with approval by the FSM. The

Contractor will ensure each equipment room contains sufficient HVAC air circulation and conditioning to support electronic equipment requirements. In each designated equipment room, high quality fire rated plywood, or better, must be installed by the Contractor to support wall mounted backend equipment (i.e.

panels, power supplies, etc.).

11.11. The Contractor shall provide and install a minimum of an 8-hour emergency power solution for all

ESS hardware. The power solution can be provided through the use of batteries, emergency generators, UPS, or a combination thereof to meet the requirements.

11.11.1. If emergency power is available, via generator, a battery backup must be provided to cover transfer time.

11.11.2. Unless specified differently by the manufacturer, PACS power supplies have 12 Vdc/18ah batteries. Any batteries for IDS panels shall have no less than a 12 Vdc/7ah battery each, unless specified differently by the manufacturer.

11.11.3. For uninterruptable power supply (UPS) installations the UPS must have surge protection and line conditioning features.

11.12. Power supplies to ESS equipment shall be wired to minimize likelihood of accidental disconnect.

Unsecured plug-ins to power supplies not located in a rack or enclosure are not acceptable.

11.13. The Contractor shall ensure that all power supplies are rated to power the maximum load plus a minimum of 10 percent spare capacity. ICE defines maximum load as the simultaneous use of all devices at their maximum current requirements.

11.14. The Contractor shall supply voltage load calculations for each Electrical/LAN closet that supports the PACS. The Contractor shall calculate power supplies and back-up capacity by maximum load.

Separately, The Contractor shall calculate nominal power and typical duty-cycle to determine the duration of the back-up system.

11.15. The Contractor shall ensure that all power supplies to PACS panel(s) are co-located. The Contractor shall ensure that new power supplies are optioned to transmit a trouble condition to the PACS when the following conditions exist: (a) low battery, (b) AC fail.

11.16. The Contractor shall ensure outputs are individually fused and sufficient for the connected load. The

Contractor shall ensure that all battery calculations are based upon peak usage (i.e. simultaneous use of all devices.). The Contractor shall provide batteries sufficiently sized to support the stand-by requirements.

11.17. In compliance with NFPA 101 Life Safety Code means of egress standards and as determined from the pre-construction site walkthrough the Contractor shall ensure that all doors are properly wired for either fail safe or fail secure mode of operation. All egress path doors, unless otherwise designated by the FSM, scheduled with electronic hardware shall unlock from inside the facility upon actuation of a life safety device or fire alarm.

12. Warranty

12.1. A warranty period of one year will commence on official date of use after testing and acceptance by

ICE Field Security Manager or designated alternate. ICE shall incur no equipment or labor costs during this warranty period.

12.2. The Contractor will identify a technical support or service contact for consultation during normal business hours, which is reachable by telephone or email.

12.3. Any critical security component that becomes inoperable must be replaced or repaired within 72 hours. Critical components are those required to provide security (PACS, IDS, VSS) for a perimeter access point or high security/critical area.

12.4. For any non-critical component that becomes inoperable, the Contractor shall schedule a service call as soon as practical but not to exceed 14 days.

12.5. The Contractor must notify the customer of all projected downtime and estimated time for repair and provide a written report of all services rendered at time of repair.

12.6. Replacement security devices must be approved by FSM prior to installation.

12.7. ICE shall receive the full benefit of all manufacturers’ warranties on all components beyond the initial warranty period.

12.8. The Contractor shall propose an extended warranty plan that includes ESS equipment replacement costs and hourly labor costs for service requirements. The proposed extended warranty should include the regularly scheduled and routine upkeep of equipment. The repair or replacement of any critical security component, as defined above, must occur within the same timeframe established in this document. For any non-critical security component that becomes inoperable, the Contractor shall schedule a service call as soon as practical.

13. Review and Approvals

Completed by:

Signature: __________________________________________________ Date: ___________________

Approved by (RSM or SC):

Transmitted to (OAFM Title & Name): __________________________________________________

SECTION II - ELECTRONIC SECURITY TYPICAL BLOCK DIAGRAMS

Enterprise Physical Access Control System (E-PACS)

Juniper IRMNet switch Unmanaged switch iSTAR

Controller panel iSTARs

Card Reader

DSM

REX

Emergency

Power

ICE Headquarters REX – Request-to-Exit DSM – Door State Monitor

Card Readers electric locking device

Intrusion Detection System (IDS)

IDS

Controller

PIR

glass break

BMS

duress

PIR – Passive infrared motion detector BMS – Balanced Magnetic Switch

Telephone line or IP connectivity

FPS MegaCenter

Video Surveillance System (VSS) – local facility

NVR

POE

capable switch monitor(s)

IP Network Cameras

Emergency

Power

Workstations/ Decoders

NVR – Network Video Recorder

SECTION III - ELECTRONIC SECURITY SYSTEMS (ESS) COMPONENT TASKS

A. Physical Access Control (PACS)

EPACS has already been established under a previous project.

A.1. This ICE location will be established as a client to the ICE E-PACS; no other PACS systems may be substituted for this project. ICE has procured Software House C•CURE 9000 Enterprise Physical Access

Control Systems (E-PACS) to implement HSPD-12 within the Agency. The PACS hardware, system architecture and parameters described in this PACS task have been approved by the FIPS 201 Evaluation

Program and meet the directives, regulations and standards referenced within this document. No deviation from the products specified and/or described, or from the installation methods identified is allowed.

A.2. Hardware Compatibility. The Contractor is responsible for ensuring the hardware provided is compatible with the ICE Enterprise Software House C•CURE 9000 PACS and capable of managing current

ICE PIV cards. Compatibility is defined as the integration of a non-standard device into a configuration and to fully operate like a similar device as prescribed by the system manufacturer. This would include all hardware, firmware and software capabilities of the non-standard device.

A.3. Juniper. A contractor-provided Juniper device is needed to connect to the ICE intranet. A contractor-provided Cisco Systems or Linksys unmanaged switch(es) may also be necessary if more than four (4)

PACS panels are to be connected. The only acceptable Juniper device for this project is:

• Juniper Networks SRX320 Services Gateway (non-POE)

A.3.1. The Contractor is responsible for all costs to ship the Juniper device to ICE HQ for programming and back to the project site. The Contractor shall ensure a shipping label with a complete return address to the project site is provided. The ICE HQ shipping address is:

U.S. Immigration and Customs Enforcement

950 L’Enfant Plaza SW, Mail Stop: 5501

Washington DC, 20536

Attention: Physical Security Operations Unit (PACS Team)

Phone Number: (202) 732-8352

A.3.2. The Contractor is responsible for connecting each PACS panel to the Juniper device for communications over the enterprise network.

A.4. PACS Panels.

A.4.1. The only acceptable PACS panels for this project are the following Tyco Software House products:

• iSTAR Ultra (not SE model)

• iSTAR Edge (not SE model)

A.4.2. The operating voltage, as set from the PACS panels, of all card readers shall be changed from the factory default of 5 Vdc to 12 Vdc to avoid performance issues.

A.4.3. The Contractor shall install new plenum-rated cable between the new PACS panel enclosures and card readers.

A.5. PACS Programming. The Contractor will provide a completed PACS Paperwork (PACS Port Charts

Form, Input/Output Board Form and as-built drawings showing the location of each card reader) in order for the ICE PACS Team to complete programming and for the local ICE Program Office to complete related actions. Local ICE program office personnel are responsible for completing the Personnel

Worksheets. Advice on establishing the clearance codes and Master Granting Authority List (MGAL) will be provided by the FSM. The current version of the Port Charts Form will be provided to the Contractor by the ICE Field Security Manager. Prior to final acceptance the Contractor shall ensure a copy of the ICE-approved Port Charts is placed in each PACS panel enclosure.

A.6. Card Readers.

A.6.1. The only acceptable card reader types for this project are the following HID Global Corporation

(HID) pivClass products:

• Model Number: pivCLASS RP40

Description: Wall Switch Contactless Reader

Part Number & Configuration: 920PHRNEK00005

• Model Number: pivCLASS RPK40

Description: Wall Switch Contactless Keypad Reader (with PIN validation)

Part Number & Configuration: 921PHRNEK0002G

• Model Number: pivCLASS RP10

Description: Mini-Mullion Contactless Reader

Part Number & Configuration: 900PHRNEK00005

A.6.2. The Contractor shall ensure card readers are factory configured with a 75-Bit format read. Card reader field modifications (or field flashing) are not authorized.

A.6.3. The Contractor shall ensure that the card readers are installed in compliance with the American with Disabilities Act (ADA) and Uniform Federal Accessibility Standards (UFAS) and provide the following audio/visual indication:

A.6.3.1. An audio beeper providing various tone sequences to signify: access granted, access denied

A.6.3.2. A clear visual status on the high-intensity light bar for:

• Red – access denied

• Green – access granted

• Amber – system busy or trouble

A.6.3.3. The Contractor shall interface the PACS into the ADA/UFAS automatic door openers.

A.7. Card Reader Spacers. Each card reader shall be mounted with an HID reader spacer, part number

6132AK, to interference with metal junction boxes, wall material such as metal mesh, back-to-back reader locations, etc.

A.8. Each outdoor card reader will be installed with HID gasket kit IP65GSKT-### (model dependent).

A.9. Card Readers. Card readers shall be installed on the same side as the door handle, unless specified otherwise by the FSM. The mini-mullion readers identified in this document are acceptable only on narrow-framed or aluminum-frame glass type (store front) doors. All other mullion card reader installations shall require the written approval of the FSM.

A.10. Card reader-controlled doors shall be connected to a Door State Monitor (DSM) and Request-to- Exit

(REX) device for operation of the door.

A.10.1. The Contractor shall configure doors with a REX device so an authorized egress from the secure area does not cause an alarm. No REX device is necessary if the door is controlled by a card reader on both sides.

A.10.1.1. REX devices can be push-button, motion sensors or incorporated in the mortise electrified lockset and shall shunt the alarm, not release the locking mechanism, unless specified otherwise by applicable NFPA 101 Life Safety Codes or the AHJ.

A.10.1.2. The Contractor shall ensure that the REX is a listed device for the specific operation to provide delay time to the DSM to prevent false alarms and is installed and configured to prevent activation by normal movement inside the secure area.

A.10.1.3. The Contractor shall ensure that the REX remains active for a maximum duration of five (5) seconds and that the timer is non-resettable.

A.10.1.4. Crash bar/delayed egress exit devices installed on doors must be approved by the FSM and shall have a local annunciator.

A.10.2. The Contractor shall ensure the DSM connects as an input or output directly to the PACS panels for communication to ICE’s Enterprise C•CURE 9000 server. PACS shall not interface with double-pole, double-throw (DPDT) switches that interface to the IDS.

A.10.2.1. For all card reader equipped doors the Contractor shall install a DSM that monitors the position of the door so that a forced-door or held-open door causes an alarm.

A.10.2.2. The DSM shall be concealed, a self-lock mounting, have rugged construction, ¾” in diameter, ABS plastic enclosure, be a hermetically sealed reed switch, be of high security, and is similar in color to the door frame.

A.11. Locks. Electric strikes, electrified mortise locksets and magnetic locks are acceptable locking mechanisms for this project. All locking mechanisms are to return to a locked state immediately after use or within 3 seconds of non-use, unless specified differently by the ICE Field Security Manger. Electric locking mechanisms must meet UL 1034, Standard for Burglary-Resistant Electric Locking Mechanisms and be burglary-resistant listed. Additionally, electric strikes must meet American National Standard for

Electric Strikes and Frame Mounted Actuators - ANSI/BHMA A156.31, Grade 1 (Cycle 500,000, Static

Strength—Voltage @ 100% and 85% of rated = 1500 pounds., Dynamic Strength—Voltage @ 100% and

85% of rated = 70 ft. lb. (95J).

A.11.1. Additional electric strike specifications:

• Construction: Stainless steel, tamper resistant, internal solenoid

• Operation: Field reversible, plug-in connectors

• Solenoid: Internally mounted to facilitate electric strike installation in hollow metal, concrete filled, and aluminum and wood jambs, operated by direct current to provide silent operation

• Electric Strike: Capable of operation with less than 30 pounds of force against keeper

A.11.2. Additional magnetic lock specifications:

• 600 lbs. holding force to be placed controlled interior rooms and secure areas within buildings

• 1200 lbs. holding force to be placed on detention and perimeter doors

• Magnetic lock shall have magnetic bond sensor

• Power override solution to be proposed for doors not identified as fail safe

A.12. Other Door Hardware. For card reader-controlled doors the Contractor shall provide and install:

A.12.1. A face plate which will prevent the lock bolt from being retracted from the unsecure side of the door or install a door strike that engages the guard bolt or auxiliary dead latch located on door hardware.

A.12.2. A functioning heavy-duty door closer.

A.12.3. All deadbolts with minimum 1-inch throw on perimeter or high security doors shall be independent action, not integrated with the card readers. The Contractor shall coordinate with the FSM on which high security doors need deadbolts. As specified in the ICE FDG, the deadbolts required for all ICE perimeter doors, HSI Seized Evidence Storage Rooms and HSI Computer Forensics Lab shall be Underwriters Laboratories (UL) listed under UL437 and certified under American National

Standards Institute (ANSI)/Builder’s Hardware Manufacturer’s Association (BHMA) certification

A156.30, Levels M1AAAM and ANSI/BHMA A156.5, Grade 1. In the event the deadbolt is not integrated into the Heavy-Duty Grade 1 Mortised Hardware storeroom function lock, both the lock and cylinder (or core) must meet or exceed the listing and certification requirements specified above.

A.12.4. Transfer hinge for electrified lockset or REX devices, as necessary.

A.12.5. The Contractor will coordinate with the Project Team to ensure there are no conflicts between door hardware and door or door frames.

A.13. Connectivity Handshake. The Contractor shall work with the ICE PACS Team for any network handshakes that will be required to do with the installed PACS panels and Juniper devices. This work is not limited to re-programming the devices to set specifications using the iSTAR Configuration Utility

(ICU). The Contractor will remain involved in this task until the connection is successfully completed.

After acceptance by ICE the Contractor will provide a CD (or other acceptable electronic medium) with system configurations as a back-up in case of C•CURE server failure.

A.14. Video Phones. A video/audio intercom (Aiphone type system) may be used for door release and may be recorded on the VSS system. When used for door release, the video phones shall be configured as an input to the iSTAR Access Control Module to release the lock and shunt the DSM or contact when the door release button has been activated. Video phones shall not be further integrated into or controlled by the

C•CURE 9000. The Contractor shall recommend an IP or non-IP digital system installation based upon site layout and operational requirements. Any intercom stations scheduled in detention areas will not include video.

A.15. Device Labeling. The Contractor shall label all PACS panels, power supplies, security enclosures, workstations, and any other enclosure installed in support of the project using a plastic label permanently mounted to the door that meets the requirements listed below:

A.15.1. Engraved-- Plastic Labels: Engraving stock, melamine plastic laminate punched or drilled for mechanical fasteners, 1/16-inch minimum thickness for signs up to 20 sq. in. and 1/8-inch minimum thickness for larger sizes. The Contractor shall provide an engraved legend in black letters on white background. Additionally, the Contractor shall label all card readers with the designation on the port charts.

A.15.2. The Contractor shall identify, with ½” lettering, all cabinets including security equipment panels, power supplies, system interface cabinets, and similar security equipment.

A.16. The location of PACS fielded devices is identified in the SECURITY SYSTEMS DETAILS section of this document.

B. Intrusion Detection Systems (IDS)

B.1. The Contractor shall also design an IDS solution for ICE perimeter entry points (suite or building), high security areas, and general office spaces. This solution may include balanced magnetic switches

(BMS) meeting UL 634, motion sensors, glass break sensors and duress devices.

B.2. The Intrusion Detection System will be programmed, administered and monitored by the Federal

Protective Service (FPS) MegaCenter. As such, the requirements set forth in the MEGACENTER

ALARM REQUIREMENTS referenced at the end of this document, to include Installer (Contractor) deliverables, must be met in addition to this task description.

B.2.1. The MegaCenter is capable of monitoring UL commercially grade listed panels from the following manufacturers only (proprietary panels cannot be monitored or supported):

B.2.1.1. For Plain Old Telephone Service (POTS) monitored accounts:

• Honeywell (Ademco)

• Bosch (Radionics)

• Digital Monitoring Products (DMP)

B.2.1.2. For Internet monitored accounts:

• Bosch (Radionics)

B.3. The Contractor shall coordinate with the project team, ICE OAFM Project Manager, FSM and local program office representative to determine if connection to the MegaCenter will be a POTS or IP line.

Further coordination may be necessary throughout the project to ensure the POTS or IP line are available in a timely manner. All coordination shall occur through prescribed GSA channels.

B.4. All IDS devices and panels containing ESS equipment must have functional internal tamper switches which create a point specific alarm, unless directed otherwise by the FSM.

B.5. All devices and points/zones are to be separately identified in the IDS panel to support the responding entity with an exact locality description for a quick and accurate response.

B.6. Motion detectors must be dual technology (microwave and passive infrared or adaptive RADAR and passive infrared) unless otherwise specified.

B.7. ICE suite or facility perimeter doors will be designed in a multi-layered approach with balanced magnetic switches and a motion sensor(s) inside.

B.7.1. Double doors or split doors shall be zoned on each leaf, not as one zone.

B.7.2. Overhead doors should have a sensor on each side to prevent the lifting on one side without an alarm.

B.7.3. Door contacts will be installed on the secure side of the door near the opening and shall not allow the door to open far enough to provide the ability to tamper with the contact inside without going into alarm.

B.8. All IDS keypads will be located on the interior of the protected space or room, to include for individual partitions/areas, unless expressly instructed otherwise by the Field Security Manager in writing.

B.9. Duress devices shall be concealed from the public and shall annunciate for an immediate response.

Reset of duress devices shall require a deliberate manual function of the alarm button i.e. flip/toggle switch, pullout mushroom or key reset.

B.9.1. Duress annunciation may include locally installed strobe lights and sirens and a signal sent to the MegaCenter.

B.9.2. If required, strobe lights should be visual/audible tri-colored units with minimum 70-decibel audible alarm.

B.9.3. The Contractor shall coordinate with FSM on annunciation requirements, to include strobe light colors and device locations.

B.10. The Contractor must complete all “Installer Sections” of the MEGACENTER ALARM

REQUIREMENTS FORM referenced at the end of this document and provide the final IDS floor plan to the MegaCenter after review by the FSM.

B.10.1. Each point/zone of ESS must be individually identified at the keypad and at the MegaCenter.

B.10.2. The Contractor shall use a naming convention for each alarm point/zone that contains the architectural room number and room description, unless specified otherwise by the FSM.

B.11. All points/zones must be tested with the FPS MegaCenter to ensure they are fully operational and provide accurate reporting prior to acceptance.

B.11.1. The Contractor will ensure that all points/zones, including duress activation locations and annunciation methods, have been fully tested and communicate with the FPS MegaCenter prior to the final acceptance test and job completion.

B.11.2. The ICE FSM may require a retest or additional testing during the acceptance process.

B.12. A temperature monitoring system shall also be established within the IT/LAN room (or Security

Equipment Room) with trouble notification to the FPS MegaCenter. The acceptable temperature shall be set between 65 to 75-degrees Fahrenheit.

B.13. A list of locations/rooms or doors that require IDS components is contained in the SECURITY

SYSTEMS DETAILS section of this document.

C. Video Surveillance System (VSS)

C.1. The Contractor shall provide a complete VSS solution designed such that it meets the physical security needs of the facility. The solution shall include cameras, network video recorders (NVR) and associated peripheral hardware for management and network transport purposes. The VSS solution must be built on an Internet Protocol (IP) based architecture on an isolated LAN platform; this network will not connect to the Internet nor any other network. The Contractor shall provide all network related hardware for this platform.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .