Attachment 01a - Contractor Access to USPTO Version 3.7.pdf

PDF 1 MB Posted

Attached to
Patent Data and Document Management Federal contract opportunity
Solicitation number
ACQ-20-0057
Issued by
Department of Commerce US Patent and Trademark Office

About this file

This document provides details for a forthcoming solicitation seeking indexing and scanning services, patent data capture and composition, and related deliverables in support of the United States Patent and Trademark Office. Key requirements include front-end processing through indexing and scanning of paper documents; pre-grant publication involving conversion and composition of pending utility and plant applications; post-allowance processing such as conversion and composition of allowed applications and quality control of electronic file wrappers; and post-issuance activities including conversion and composition of various certificates and recapture of patents due to certificates of correction. The contractor must adhere to detailed production schedules, quality standards, and technical references provided in the solicitation attachments. Delivery timelines are defined in terms of prior workdays leading up to weekly publication Thursdays or issue Tuesdays. The solicitation seeks these services to meet statutory publication and patent issuance requirements.

View the file

Other files for this federal contract opportunity

Other files attached to Patent Data and Document Management, newest first.
File Type Posted
Attachment 38 - IT Security Requirements - 2018-09.docx DOCX document
Attachment 23 - DataEntryManual-NON-UTILITY-2019.doc DOC document
Attachment 03b - USPTO Enterprise Workstation Naming Convention.docx DOCX document
Attachment 10b - 9611604.pdf PDF
Attachment 31 - CofC_manual_PaDaCap_2019.docx DOCX document
Attachment 26 - DCB 2019-01 (11).docx DOCX document
Attachment 17a - DPMpgpub-2019.doc DOC document
Attachment 26 - DCB 2019-01 (22).docx DOCX document
Attachment 03a - USPTO_Computer_Specs.xlsx XLSX spreadsheet
Attachment 41 - Past Performance Questionnaire.docx DOCX document
Attachment 11 - Link to Public PAIR.docx DOCX document
Attachment 17b (jpg) - u-bibdat1.jpg JPG image
Attachment 35b - PE2E-eDRS-Navigation_QRG.pdf PDF
Attachment 35b - PE2E-eDRS-User-Preferences_QRG.pdf PDF
Attachment 26 - DCB 2019-01 (23).docx DOCX document
Attachment 17c (jpg) - u-suppub8-2012-12-04.jpg JPG image
Attachment 26 - DCB 2019-01 (2).docx DOCX document
Attachment 25b - Consolidated Listing of Official Gazette Notices, 2018-01-25.pdf PDF
Attachment 26 - DCB 2019-01 (17).docx DOCX document
Attachment 10b - 9591857 Lengthy Table.pdf PDF
Attachment 05d- Historical Volumes for PG Pubs, IDC Exports and Issue Sizes for FY-16-19.xls XLS spreadsheet
Attachment 39a -Transition Plan Framework.docx DOCX document
Attachment 26 - DCB 2019-01 (21).docx DOCX document
Attachment 05b- Weekly Serialized Filings.xls XLS spreadsheet
Attachment 26 - DCB 2019-01 (27).docx DOCX document
Attachment 13a - Final FEPIB No. 2019-3 Addition to Appendix Eight Supplemental Guidance.doc DOC document
Attachment 26 - DCB 2019-01 (13).docx DOCX document
Attachment 43 - Surveillance Plan.docx DOCX document
Attachment 36 - PE2E-OC OPESS Manual.pdf PDF
Attachment 32 - CofC Patent Term Adjustment SOP_Nov 13 2017.pptx PPTX presentation
Attachment 17e - (dtd) -ExportTOC1.txt TXT text file
Attachment 13 - Front End Processing (FEP) Manual for Indexing and Scanning.docx DOCX document
Attachment 04 - Crosswalk of CLINs to SOW and Historical Volumes.xlsx XLSX spreadsheet
Attachment 35b - PE2E-eDRS-IFW-Messages_QRG.pdf PDF
Attachment 01b - OCIO Personal Identity Verification (PIV) Card Authentication Policy, OCIO-POL-49.pdf PDF
Attachment 10b - 9611144.pdf PDF
Attachment 26 - DCB 2019-01 (15).docx DOCX document
Attachment 35b - PE2E-eDRS-Manual_Manual.pdf PDF
Attachment 26 - DCB 2019-01 (14).docx DOCX document
Attachment 27a - Link to USPTO PG Pub and Grant Red Book Instructions.docx DOCX document
Attachment 26 - DCB 2019-01 (3).docx DOCX document
Draft RFP 2.11.pdf PDF
Attachment 26 - DCB 2019-01 (8).docx DOCX document
Attachment 09 - Link to Patent Classifications and Definitions.docx DOCX document
Attachment 10b - 9613741.pdf PDF
Attachment 10b - 9474420 Utility Color Drawings.pdf PDF
Attachment 19b - PatentGrantXMLv4.3Documentation.doc DOC document
Attachment 19a - Link to USPTO PG Pub Red Book Instructions.docx DOCX document
Attachment 15 - CRF_Transfer_Participant_Manual_Final_Revision_2019-03-18.pdf PDF
Attachment 10b - PP27824.pdf PDF
Show all 50

Patent Data and Document Management has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

OFFICIAL TECHNICAL USE ONLY

Infrastructure, Design, Engineering, Architecture, and Integration (IDEAI-2)

Contractor Access Engineering (CAE)

Contractors Access to USPTO

Version 3.7 For

U.S. Patent and Trademark Office

April 5, 2018

Contractor Access to USPTO v3.7

OFFICIAL TECHNICAL USE ONLY i

Record of Changes

Version Date Pages Affected Type of Change

1.0 5/9/2012 All Original version.

2.0 2/26/2013 Chapter 4

Appendix A Pg. 3-8

Add Chapter 4 – Processes Add Role Definition table as Appendix A Expand workstation definition (Section 3.2.4.1) Help Desk reference changed to Service Desk

2.0 3/5/2013 Pg. 2-1 Incorporated an update to the COR Division Name in the POC table

2.1 8/23/2013 Pg. 2-1

Pgs. 3-1, 2, 3 Pg. 3-6

Adjust POC information to align with USPTO organizational changes Update USPTO campus and Direct Connect graphics Add Connectivity Options table

2.1 8/30/2013 Pg. 2-1 Change Critical Problem Notification (CPN) reference to Problem Management Notification (PMN)

2.2 4/21/2014 Pgs. 1-1,2,3 3-13

Add guidance for TIC 2.0 compliance and Enterprise Access Infrastructure Systems (EAIS)

2.3 12/8/2014 All Update with new USPTO polices for contractor access and scheduling procedures.

2.4 02/19/2015 All Updated document with New Contractor Partner Zone for MTIPS connections

2.5 05/12/2015 Pgs. 2-1, 3-4,#5 Appendix H MOU Title Page

Removed Linda Brinson, retired in Jan 2015.

Rephrased the sentence for TL to provide the CAE document.

Correct CO to be in OCFO.

Correct Project Manager or Program Manager

2.6 05/15/2015 Page G-1 Change to Revision 4

2.7 05/21/2015 Appendix H, All Footer

Replace Cover Page of MOU Change to “Official Technical Use Only”

2.8 06/1/2015 All Pages Review and Updated all pages, PTO CEP Software list.

2.9 11/6/2015 All Pages Review and Updated Contractor Responsibilities

2.9 12/3/2015 All Pages Change 800-53 Revision 3 to 800-53 Revision 4

3.0 02/4/2016 All Pages Remove all TLS information and support , replaced COTR to COR

3.1 08/29/2016 All Pages Updated VPN, SEAS, and Remote Access Information and MOU

3.2 11/15/2016 All Pages Updated sections 3.2.2, 3.2.4, Workstations Item #19, Appendixes C, D, H, and Table of Content.

3.3 12/01/2016 All Pages Updated Table of Content, Sections 2.1, 2.2, 3.2.4.2, 4.1, Appendix B

3.4 02/21/2017 Pgs. 3-7, #12, H-3 -#3

Added - “USPTO has full admin rights to manage and control the GFEs or any network devices that are connected to PTONet.”

3.5 10/15/2017 All Updated all pages

3.6 03/30/2018 All Updated all pages - Final

3.7 04/05/2018 3-15 to 3-17 Updated security comments

OFFICIAL TECHNICAL USE ONLY ii

TABLE OF CONTENTS

1 INTRODUCTION...................................................................................................... 1-1

1.1 Description of Function and Purpose ............................................................. 1-1

1.2 AIS Development Organization ...................................................................... 1-3

1.3 AIS Sponsoring Organization ......................................................................... 1-3

1.4 Security Impact Statement ............................................................................. 1-3

1.5 Contractor Telework Support ........................................................................ 1-4

2 POINTS OF CONTACT ............................................................................................. 2-1

2.1 Manager and Support Contacts ...................................................................... 2-1

2.2 Major Incident Alert (MIA) ............................................................................ 2-1

3 DETAILED SUPPORT SPECIFICATIONS .................................................................. 3-1

3.1 Contractor Access System (CAS) Overview ..................................................... 3-1

3.2 Direct Access ................................................................................................. 3-4

3.2.1 Selecting an Access Network .................................................................... 3-4

3.2.2 Direct Access Implementation Process ..................................................... 3-5

3.2.3 USPTO Responsibilities .......................................................................... 3-13

3.2.4 Workstations ......................................................................................... 3-14

3.2.4.1 Hardware Connectivity Guidelines/Restrictions ............................. 3-14

3.2.4.2 USPTO – Contractor Enterprise Platform (CEP) .............................. 3-15

3.2.4.3 USPTO - Contractor Enterprise Development Platform (CEDP) ....... 3-17

3.2.4.4 USPTO – Government Furnished Equipment (GFE) ......................... 3-18

3.2.5 Final Site Workstation Review and Audit: ............................................... 3-18

3.2.6 USPTO Software Download/Support via SCCM: ...................................... 3-18

3.2.7 Non USPTO Approved Software Requests: .............................................. 3-18

3.3 EAIS Axway SecureTransport Requests: ....................................................... 3-18

3.4 Secure External Access System (SEAS) ......................................................... 3-18

3.4.1 SEAS System Overview ........................................................................... 3-18

3.4.2 SEAS - Contractor Responsibilities .......................................................... 3-20

3.4.3 SEAS– USPTO Responsibilities ................................................................ 3-20

4 PROCESSES ............................................................................................................. 4-1

4.1 Service Desk .................................................................................................. 4-1

4.2 CAS Network Direct Access ............................................................................ 4-2

4.3 USPTO User Requirements ............................................................................ 4-3

4.4 SEAS – Additional Application Requests ......................................................... 4-3

OFFICIAL TECHNICAL USE ONLY iii

APPENDIX A: Role Definition .............................................................................................. A-1

APPENDIX B: Abbreviations and Acronyms ...................................................................... B-1

APPENDIX C: CAE Proposed Direct Connection Site Request to USPTO Form .............. C-1

APPENDIX D: New CAS Site Request Guidelines ............................................................... D-4

APPENDIX E: USPTO Pre-production Firewall Request ................................................... E-1

APPENDIX F: SEAS Global Groups within Active Directory ............................................. F-1

APPENDIX G: NIST SP 800-53A - (Physical Security Controls) ........................................ G-1

APPENDIX H: Memorandum of Understanding (MOU) or Agreement ............................... H-1

LIST OF FIGURES

Figure 3-1 Direct Connection Methods ........................................................................... 3-1

Figure 3-2 USPTO Campus CAS Infrastructure ................................................................ 3-2

Figure 3-3 SEAS Logical Diagram ................................................................................. 3-19

LIST OF TABLES

Table 2-1: CAS Manager and Contact Support ................................................................. 2-1

1-1 OFFICIAL USE ONLY

1 INTRODUCTION

This document was prepared for the United States Patent and Trademark Office (USPTO) under the Contractor Access Engineering (CAE) Task Order, managed by USPTO CAE Task Order Manager (TOM), USPTO CAE Technical Lead.

This document provides pertinent information required for new contractors to access USPTO’s network from outside the USPTO main campus. Various types of access described within this document:

1. Direct Connect (Contractor Access System - CAS)

2. External Partners

3. Secure File Transfer (Enterprise Access Infrastructure Systems - EAIS)

4. Internet-based access (Secure External Access System – SEAS)

1.1 Description of Function and Purpose

Direct Connect through Contractor Access System (CAS)

The CAS network provides remote government sites and contractors with limited, monitored, and secure access to the authorized USPTO network (PTONet) applications, resources, services, and the assorted test networks through the Enterprise Trusted User (ETU) firewall architecture. The ETU firewall filters and monitors all CAS traffic. Only USPTO-approved government and contractor sites, workstations and printers are allow connecting to the CAS network. CAS users may also access the Internet through the USPTO Internet proxy server.

CAS allows contractors to perform both operations maintenance activities for production systems and development efforts in a separate environment. Enforcement of separation of duties are enforce to ensure developers do not make changes to production systems in accordance with the System Development Lifecycle (SDLC) model.

External Partners

Some projects require contractors to collaborate and work closely with USPTO government employees and resources; e.g. developing software applications for USPTO to process patent and trademark applications. This collaboration and close interworking relationship may require file and data transfer from the contractor’s network into the PTONet environment. Carefully evaluating the level of collaboration or interaction is critical to establish the appropriate access and security levels.

Contractors who require a deeper integration and are considered “external partners with a documented mission requirement and approval” may need to establish a service in compliant with the Office of Management and Budget's (OMB) Trusted Internet Connections (TIC) initiative. If contractors are required to exchange data from their local corporate network with PTONet, the exchanged must be perform in a secure manner. US General Services Administration (GSA) developed the Managed Trusted Internet Protocol

1-2 OFFICIAL USE ONLY

Service (MTIPS) to allow US Federal agencies physically and logically connect to the public Internet and other external connections in compliance with the OMB’s TIC initiative. The MTIPS Security Operations Center monitors all information exchanged with external networks to protect agency traffic. The MTIPS transport serves as a collection network for the TIC portal, insulating an agency’s internal network from the Internet and other external networks. This may involve purchasing a TIC 2.0 service from one of the commercial carriers designated as a Managed Trusted IP Service (MTIPS) provider.

USPTO will not pay for any leased lines or leased line services.

Note: Contractors will pay for any of these types of TIC 2.0 services. For business relationships which require this type of file/data exchange, contact the COR to discuss.

Enterprise Access Infrastructure Systems (EAIS)

Contractors whose only requirement is to transfer or exchange files with USPTO can perform this activity through their company’s Internet access (no CAS network required).

File transfer to USPTO from approved contractor sites can be perform through the Internet using the Axway system USPTO already has established. This system enables both internal (USPTO) and external (contractors) users to perform secure file transfer by using multiple methods; server-to-server, user accounts, automated delivery to account shares, etc.

The bulleted content below highlights some of the strict requirements, which govern the approved methods for transferring files.

• Any file transfer activity must use only software approved by USPTO and meets the FIPS 140-2 compliance requirements. USPTO has approved Axway SecureTransport

– Enhanced Managed File Transfer (MFT) servers and proxies which are FIPS 140-2 enabled.

• Any file content identified as “sensitive” that is transferred over the Internet via server-to-server transfers must use the AS2 protocol.

• Any internal files using server-to-server transfers from within the CAS network must transfer over the Internet using SFTP-SSH protocol 2 with FIPS 140-2 compliance enabled. Also, any external files (e.g. on the contractor’s network) may use the same exact setup for file transfer with USPTO. Axway software is a multi-protocol solution and all protocols are present on one system under the Axway SecureTransport software.

For all questions regarding future network design, connections, or Axway SecureTransport with USPTO, contact the procurement office and they will contact the appropriate person.

Contractors will pay for their server equipment, network equipment, and Axway SecureTransport software and licenses.

Note: For business relationships which require this type of file exchange, contact the COR to discuss how to establish these services.

http://www.dhs.gov/files/programs/gc_1279308101027.shtm

1-3 OFFICIAL USE ONLY

Internet-Based Access through the Secure External Access System (SEAS)

The primary goal of SEAS is to enable authorized remote users to access USPTO applications, resources and services via the Internet. Contractors in remote contractor sites can connect to PTONet through the Internet. Secure Sockets Layer (SSL)/Transport Layer Security (TLS) encryption and strong two-factor authentication mechanisms (RSA SecurID) for remote users are included in the system. USPTO Virtual Private Network (VPN) appliances and Citrix servers provide a secure mechanism for contractors to access resources on PTONet via their workstations. Software application profiles can be associated with each user’s account access group(s) – see Appendix F. Contractors may request additional software beyond what is loaded per the user profile by submitting a request to the CAE Technical Lead.

1.2 AIS Development Organization

The SEAS and CAS development teams consist of representatives of the USPTO’s Office of the Chief Information Officer (OCIO) and General Dynamics Information Technology

(GDIT).

1.3 AIS Sponsoring Organization

The OCIO sponsors the SEAS and CAS Automated Information Systems (AISs).

1.4 Security Impact Statement

Direct Connect through Contractor Access System (CAS)

CAS connects to PTONet through the ETU firewall that monitors and filters all traffic between CAS and PTONet. Workstations and printers are allowed to connect to the CAS network provided they have been assigned Media Access Control (MAC) address entered into the CAS network switch at a CAS site. This procedure allows only the registered workstations and printers to access the CAS network. USPTO also requires all CAS sites must maintain an air-gapped network between PTONet and any other network, such as the contractor’s corporate network.

Laptop computers are very common in the CAS environment and special care needs to be observe due to their portability. In general, once a workstation has been approved CEP/CEDP compliant and approved for connectivity into the USPTO domain, the workstation is not allowed be disconnected and then reconnected into another domain. This disconnect/reconnect would be viewed as a serious security breach. These regulations and restrictions apply to desktop and laptop computers but emphasis is on the laptop style machines due to their ease of portability.

USPTO will provide patching to the Minimum Contractors Software Requirements in section 3.2.4.2 of this document. To insure USPTO has access to your CEP/CEDP workstations, your Local IT administrator must ensure that USPTO SCCM client is installed and functioning/communicating properly. The SCCM is USPTO system is use to push out

1-4 OFFICIAL USE ONLY

security patches to all USPTO domain attached workstation. USPTO SCCM client and the CEP/CEDP workstation being updated and compliant are mandatory.

Currently USPTO scans all CEP (Contractor Enterprise Platform) workstations once the approved baseline image is install on the contractors purchased hardware. USPTO will scan all CEP workstations with the approved baseline image and any additional software that the contractor requires to perform their duties on USPTO. Scanning will be perform prior to PTONet connection in order to remediate any vulnerability and compliance issues. Once remediation efforts are completed, USPTO remediation team will notify USPTO security and arrange a rescan to ensure all critical, high and medium findings have been remediate.

Lastly, on a quarterly basis, your systems will be rescan for vulnerability and compliance and USPTO will promptly remediate any findings that result from these scans.

Enterprise Access Infrastructure Systems (EAIS)

EAIS is a group of file transport servers and proxies approved by USPTO to transfer and receive files within the USA. All EAIS accounts are approve by the task USPTO COR, the Technical Leader/Manager, and EAIS Technical Leader. File transfers are perform under approved USPTO certified software and transferred under FIPS 140-2 compliance. USPTO has approved Axway Secure Transport – Enhanced Managed File Transfer (MFT) servers and proxies for their file transfers with FIPS 140-2 compliance enable.

Internet-Based Access through Secure External Access System (SEAS)

SEAS connects to PTONet through the Enterprise Remote Access Juniper VPNs and the ETU firewall. The ETU firewall monitors and filters all traffic between SEAS and PTONet.

Contractor access is limited prohibiting local upload/download of files and network printing. Printing to a direct attached local printer to a workstation is allowed.

1.5 Contractor Telework Support

USPTO Contractor Telework Support Service Levels Agreement

Access to USPTO is perform through various methods CAS, SEAS, and on site. USPTO does support government employee’s telework with USPTO government furnished equipment (GFE). Contractor Telework through the various workstations Contractor Enterprise Platform, Contractor Development Platform, and User Furnish Equipment all have very limited support. It is up to the contractors to support their own equipment, operating system, and software.

Users accessing contractors CEP/CEDP systems through USPTO VPN (Team portal) RDP or through SEAS (RDP) and/or the Published Desktop have inherited delays due to various, VPN’s, ISP’s, and networks.

The local company administrator is responsible for both CEP/CEDP workstation support and ISP connection.

The users are responsible for their user furnished equipment (UFE) and home ISP connection.

1-5 OFFICIAL USE ONLY

User access to various USPTO resources is the user’s responsibility.

Limitations:

• Not all Operating Systems are supported.

• Microsoft Windows XP or earlier is NOT allowed.

• USPTO supports only Windows 7 (existing contractors only) and 10 systems.

• USPTO VPN and SEAS access is through users Internet Explorer 11 browser ONLY

(USPTO Support).

• PTO does not allow MAC and Lenovo systems on the USPTO network.

• All RDP access to CEP/CEDP workstations will require a PIV Smart Card and reader.

• No downloading /uploading of files allowed.

• Only local printing allowed.

• No SLA for network performance or bandwidth availability is guarantee by USPTO.

Service Desk – USPTO will provide limited Service Desk support for Team Portal VPN, RSA SecurID FOB, and SEAS issues. PTO on User Furnished Equipment (UFE), CEP, and CEDP systems does not provide desktop services. For additional information, refer to the Team Portal VPN User Guide and the SEAS User Guide.

OFFICIAL USE ONLY 2-1

2 POINTS OF CONTACT

2.1 Manager and Support Contacts

Table 2-1: CAS Manager and Contact Support Organization/Role Name Business Area/Office/Division Office Phone

Number CAE Technical Lead I/CSB

Communication Services Branch

COR for CAS/SEAS/EAIS I/VMD Vendor Management Division

Client Software Services Division

I/CSSD

Client Software Services Division

Client Software Services Division

I/CSSD

Client Software Services Division

Desktop Services Division I/DSD Desktop Services Division

Symantec Endpoint Protection Server - Contact

I/OSAES

OS Administration and Engineering Section

Operation Support – Operations Section

I/OS-OS

OS-Operations Section

IT Cyber Security Director I/CD Cyber Security Division

IT Security Authorization (A&A Government)(acting)

I/SAB

Security Authorization Branch

IT Security Officer (Cyber Security)

I/CD

Cyber Security Division

IT Security Officer (Cyber Security)

I/SAB

Security Authorization Branch

Service Desk / Service Desk Chief

I/SDB

Service Desk Branch

Network Operational Support

I/CSB

Service Desk I/SDB Service Desk Branch

Firewall I/SSB2/Software Services Branch USPTO leased line/communication Telco

I/CSB

2.2 Major Incident Alert (MIA)

When a problem results in an outage or major loss of functionality to multiple customers, the OCIO Service Desk will prepare and e-mail a Major Incident Alert (MIA) message to CAS and/or SEAS users. The Service Desk will update the MIA periodically until the problem is resolved.

OFFICIAL USE ONLY 3-1

3 DETAILED SUPPORT SPECIFICATIONS

3.1 Contractor Access System (CAS) Overview

CAS provides off-site contractors with secure network access to PTONet, the test environments, and a proxy Internet access via a direct connection between the contractor site and USPTO’s Contractors Access System (CAS). Figure 3-1 shows the two methods of establishing a direct connection, e.g. Single Mode Fiber and VPN-to-VPN. The CAS site Eisenhower Ave uses RF connectivity back to USPTO. Contractors connect to USPTO through the 1st. floor MDF room via single mode fiber from their location.

Figure 3-1 Direct Connection Methods

OFFICIAL USE ONLY 3-2

Figure 3-2 shows the USPTO Local Campus building connections where contractors can get CAS access. The network at the contractor site must be isolated from the contractor’s corporate network to meet Assessment & Authorization (A&A) security requirements.

Figure 3-2 USPTO Campus CAS Infrastructure

Contractor Access System Support Level Agreement

CAS SLA support for both direct connection (Carlyle Place, Carlyle Center) and Radio Frequency (RF) connectivity (Hoffman Building on Eisenhower Ave) are best effort. The 2034 Eisenhower Ave connectivity past history, has been very reliable, however, during extreme weather, the RF systems can be affected by heavy snow/storm or violent winds.

The RF system is reliable 99.9% of the time.

CAS SLA support for VPN to VPN connection is within the boundaries of the CAS firewall, switch and UPS.

OFFICIAL USE ONLY 3-3

USPTO does not guarantee contractors connections to USPTO. All contractors are responsible for their own connection to USPTO at their own cost. The above mentioned locations with direct and RF connections are provided as a free service since those locations already have access to USPTO. Contractors requiring 100% guarantee are recommend to connect via VPN to VPN.

Support for the contractor network, ISP connection and CEP/CEDP workstation and printers are under the contractor local IT administrator.

OFFICIAL USE ONLY 3-4

3.2 Direct Access

3.2.1 Selecting an Access Network

Each contractor must carefully evaluate their specific data communication requirements between their site and the USPTO network. Consideration of factors such as capacity, costs, distance, etc. are reviewed in order to choose a service that best fits the type of work that is outlined in the details of the awarded contract.

Some of the main attributes of the available options are in the table below:

Connection Option Attributes/Characteristics

VPN to VPN

(Standard)

Preferred method of connecting contractor site, which is, located a long geographical distance away from the Alexandria main campus. Also suitable for contracting companies located near the Alexandria campus. This economical option leverages off the contracting company’s existing Internet service.

The Internet bandwidth capacity must be evaluate to ensure it will support the anticipated increased traffic demands resulting from the USPTO contract.

Since the Internet service already exists, there is no wait-time to establish a completely new service with an ISP.

A spike in USPTO Internet usage has the potential to affect the contracting company’s connection into PTONet.

Fiber

Contractor sites located in buildings very near the Alexandria campus have pre-existing fiber connecting into the USPTO facilities and offer a direct connection into the USPTO network.

Contractors are responsible to make the connection from their office area to the demarcation point in the building where the service terminates.

RF Available for 2034 Eisenhower Avenue, Alexandria, Virginia only.

T1/T3 (Legacy Only)

Supported for legacy contractors with an established service only.

The T1/T3 connections will be disconnected once the existing contractor’s contract is completed.

T1/T3 connection will no longer be accepted for new contractors.

TLS

(Legacy Only)

USPTO has an established connection into the Verizon Transparent LAN Service (TLS).

This is a fiber optic; Ethernet based connection, which has been establish in the VA, DC, and PA metropolitan area. This connection is a Point-to-Multipoint service.

Contracting companies are required to purchase a 10 MB or 100 MB service of the TLS.

The TLS connections will be disconnected once the existing contractor’s contract is completed.

TLS connection will no longer be accepted for new contractors.

VPN to VPN (Contractor Partner

Zone) or (MTIPS)

Available for approved External Partners using Contractor Partner Zone (CPZ) or Managed Trusted Internet Protocol Service (MTIPS) Providers.

OFFICIAL USE ONLY 3-5

3.2.2 Direct Access Implementation Process

The following seven steps outline the high-level process to establish a new, direct access network for a contractor’s site.

1. Written Request: Contractor provides written request (email) to the appropriate COR who will determine if the contractor is authorized to have direct network access via CAS. Once COR approval (estimated three business days) is attained, proceed to step 2.

2. Engage COR: Either the contractor forwards the COR approval, or the COR sends request to the USPTO CAS Technical Lead.

3. Form Completion: Within three business days from receiving request from COR, the CAS TL emails to the contractor, cc’d COR, the “Contractor Access to USPTO” document package, to read and fill out Appendix C (Proposed Direct Connection Site to USPTO Request Form), and MOU in Appendix H. The Contractor Access to USPTO document outlines the detailed responsibilities of USPTO and the contractor. Once all information is filled out and completed, with all required signatures on MOU, the company then returns the completed Appendix C and the signed Appendix H (MOU) to their COR and cc’d to CAS TL. In addition, the contractor provides a Point of Contact (POC) to work with the CAS Network Engineers, USPTO Desktop Services, Client Software Services Division, Service Desk staff, and USPTO Cyber Security (A&A) for the remainder of the process. Upon receiving the completed signed forms, CAS TL will proceed to step 4.

Note: USPTO and contractor execute their responsibilities as defined in the signed MOU

4. Initial Meeting (Kick-Off Meeting): Within five business days, after receiving the completed signed forms from the company, the CAS TL will forward the signed forms to Cyber Security Office, and will schedule a meeting with the following USPTO Organizations (see Section 2: Contacts) to detail each party’s responsibilities outlined in Section 5 of the Memorandum of Understanding (MOU):

a. COR and all TOMs

b. CAS Network Access team: Direct Local Access (Fiber, RF), VPN-to-VPN, and

MTIPS.

c. Desktop Services: Hardware platforms

d. Service Desk team: User accounts

e. Client Software Services Division: CEP/CEDP and latest patches

f. Security team: A&A, other security-related interests

g. Leased line team (if applicable)

5. Post Kick-Off Meeting: The vendor will need to work with Cyber Security team first to get their approval for the site prior to a CAS site network setup and GFE delivered. In addition, the vendor will also need to work with all other teams (as specified in Kick-Off Meeting paragraph).

OFFICIAL USE ONLY 3-6

6. Network Design Meeting: Upon receiving approval from Cyber Security team, within five business days, the CAS team will schedule a network meeting with the requesting company, their associated COR, their Program Manager, and their IT POC to review the CAS site network requirements.

The “New CAS Site” process guideline overview is located in Appendix D. CAS sites installations are perform on a FIFO basis unless authorized by the USPTO CAS TL. The estimated installation schedule is dependent upon the CAS installation schedule.

During CAS site pre-installation, submit all issues or concerns through email to the USPTO CAS TL, with details describing the complaint. A meeting will be scheduled with the appropriate parties to evaluate, discuss for appropriate solution.

OFFICIAL USE ONLY 3-7

Contractor Responsibilities

The contractor is typically responsible for the following areas. Note: This is a partial listing for illustrative purposes; review the Memorandum of Understanding (MOU) for the binding list of responsibilities.

Initial Preparation

1. Contact the USPTO COR and USPTO CAS TL, with your request for a direct connection with USPTO.

2. Provide a signed USPTO Memorandum of Understanding (MOU) or Agreement through your COR, who will forward it to USPTO CAS TL. Refer to Appendix H.

3. Provide completed USPTO security documents CAS Security Questionnaire and Security Physical Site Survey Checklist.

4. Obtain and fund the site connection to the nearest USPTO access point.

USPTO will not pay for any leased lines or leased line services.

5. Provide Primary and Alternate point of contact (POC) individuals to work with the CAS Technical Lead (TL) and CAS Network Engineers to develop a specific network design and configuration for the contractor; this will include a network diagram, network components (vendor, model name), and IP addresses.

6. To prepare for a connection into USPTO via T1 or T3, contact USPTO CAS TL, for approval and assistance in working with the USPTO side of the telco environment.

USPTO will not pay for any leased lines or leased line services.

7. If the decision is approve for a leased line (T1 or T3) connection between your site and USPTO, then contact USPTO Network Branch, for assistance.

USPTO will not pay for any leased lines or leased line services.

8. If access for your site will be a VPN to VPN connection, submit your required Public Internet IP Address through your USPTO COR to USPTO CAS TL, at least three weeks prior to the installation date.

9. If you request approval to become an External Partner using the Contractor Partner Zone or MTIPS access, contact USPTO COR and USPTO CAS TL, for approval and assistance in working with the USPTO side for your environment. All External Partners will be required to connect to USPTO through the Trusted Internet Connection (TIC). To review Homeland Security Trusted Internet Connections (TIC) Initiative and receive the full document of the Trusted Internet Connections (TIC), Reference Architecture Document, Version 2.0, go to http://www.dhs.gov/trusted-internet-connections and https://www.fedramp.gov/files/2015/04/TIC_Ref_Arch_v2-0_2013.pdf.

http://www.dhs.gov/trusted-internet-connections http://www.dhs.gov/trusted-internet-connections https://www.fedramp.gov/files/2015/04/TIC_Ref_Arch_v2-0_2013.pdf

OFFICIAL USE ONLY 3-8

USPTO will not pay for any leased lines or leased line services.

10. Contractor company site Program Manager is responsible to notify the contract COR within 10 business days any PM or Local IT Administrators changes.

11. Contractor companies will contact their Local IT Administrator for all workstation and application support. (USPTO does not provide support for contractor’s workstations and applications).

12. Contractor companies will be responsible to verify all CEP/CEDP workstations are online and accessible for USPTO to push all supported software patches.

13. Contractor companies will be responsible to verify all CEP/CEDP workstations hardware and software patches up to date.

Network Preparation

14. Run/pull all network cabling within the contractor’s facility. This includes power cabling and an “access point” for USPTO to connect PTONet within the contractor’s facility.

15. Provide all network cabling to extend the Communication Service Provider (e.g.

Verizon, AT&T) line termination points DMARC (T1, T3, and fiber) to the contractor secured network room and terminated.

16. Provide a secure locked network room or, if approved, a lockable network cabinet within the contractor’s facility where all the CAS network equipment will be located.

All CAS network components must be segregate by a cabinet/rack installation from all other equipment. USPTO has full admin rights to manage and control the GFEs or any network devices connected to PTONet. It is permissible to allow the contractor’s corporate network and/or servers to reside in the same secured room (Additional requirements regarding the network closet/cabinet housing the USPTO equipment are listed in the Physical Site Survey requirements provided by the OPG Cyber Security Division).

Network closet: The Contractor's network closet must meet all Cybersecurity physical, environmental (HVAC), and security requirements. Cybersecurity approval is required before the site installation can begin. No exceptions.

Standard Network Rack Space Requirements: Space for a single Cisco 3750v2 switch (or Juniper EX4300 switch), Juniper SRX Firewall and an APC Smart UPS 1500 RT.

Additional Equipment Information:

Rack Unit Space: 8U (add 3U for each additional network switch) Rack Weight: 71 lbs. (add 10lbs. for each additional network switch) Rack Space Depth: 30 inches (note UPS is 22” Deep, room is required behind the UPS to connect the power, management cables)

OFFICIAL USE ONLY 3-9

Network cabinet: The contractor's cabinet must meet all Cybersecurity physical and security requirements. Cybersecurity approval is required before the site installation can begin. No exceptions. All network cabinets will require the CAS TL to review and approval before installation.

Cabinet physical requirements:

Minimum size 19"H*28"H*30"D that is securable and lockable Lockable doors and sides Well vented construction Lockable wheels or the cabinet must be bolted to a secure item

Cabinet Space Requirements: for a single Cisco 3750v2 switch (or Juniper EX4300 switch), Juniper SRX Firewall and an APC Smart UPS 1500 RT.

Cabinet Space Requirements:

Unit Space: 8U (add 3U for each additional network switch) Weight: 71 lbs. (add 10lbs. for each additional network switch) Space Depth: 30 inches (note UPS is 22” Deep, room is required behind the

UPS to connect the power, management cables)

17. Provide cabinet/rack power requirements including any utility company fees/any associated costs.

Standard Power Requirements:

A dedicated 20 amp. AC electric power circuit with an NEMA 5–20R T-slot receptacle within 3 feet of the future USPTO UPS location.

18. Provide Cat6 patch cables for the connections between the switch and patch panel.

19. Provide suitable heating, ventilation, and air conditioning (HVAC) environment for the network equipment.

Heat Distribution:

The average total heat output of the USPTO network equipment is approximately 2,442 BTU/hour:

Cisco 3750v2 switch (or Juniper EX4300 switch) 1796 BTU/hour Juniper SRX Firewall 253 BTU/hour APC Smart UPS 1500 RT 393 BTU/hour

20. Notify the OPG Cyber Security Division to request the following documents and actions:

a. A copy of the CAS questionnaire document must be completed prior to performing the physical site survey.

OFFICIAL USE ONLY 3-10

b. Set up a Physical Site Survey (sites must be compliant and prepared to meet these specifications prior to conducting the Physical Site Survey)

c. Contact OPG Cyber Security Division, for a new CAS site survey.

21. Review and understand the Security requirements in Appendix G and the Physical Site Survey requirements provided by the OPG Cyber Security Division.

22. Remote Site Installation

If a contractor’s site is located far enough away to warrant overnight travel from the USPTO Alexandria campus, “remote installation” may be a practical approach.

Remote CAS site installations are performed without having a member of the CAS Network Team on-site; the site network support staff will perform the install of the pre-configured equipment and power up activities. In this approach, the CAS Network Team will engage via phone support to monitor and assist with instruction.

To set up for a remote site installation, the following items are required:

a. Windows 10, 64 bit laptop computer – This will be use as a backup in case the CAS Network Engineer loses connection to the primary console port.

b. Juniper compatible USB/serial console cable - USPTO will provide the serial console cable in support of assisting USPTO.

c. CAS Remote Site Installation Guide – Provides the necessary instruction

Workstations

23. Unless USPTO will provide GFE, the contractor is responsible to purchase all employees’ workstations at their own cost (recommend to consult with USPTO Desktop Services Division prior to making any purchase). These workstations must be:

a. A certified vendor/model and configuration that USPTO uses which meets the USPTO’s A&A requirements. These workstations baselines are refer to as the USPTO Enterprise Desktop Platform (EDP). The EDP Platform is already A&A by USPTO. Please contact Desktop Services Division to obtain EDP hardware specifications.

b. Contractor’s hardware must be able to support and sustain all appropriate patches to the USPTO CEP/CEDP software platforms along with any USPTO Client software required by the task. Contact the Client Software Services Division identified in Section 3.2.4.3 for details. Both the CEP and CEDP Platforms are already A&A by USPTO.

c. Re-use of existing Contractor Furnished Equipment that is currently on the USPTO campus will require re-base lining to the new company approved CEP/CEDP image. The pre-existing USPTO images will not be provide or transfer for re-use.

OFFICIAL USE ONLY 3-11

d. For GFE, the contractor needs to work with Desktop Services Division and USPTO Cyber Security team for rules and regulations.

Note: The term workstation applies to both desktop and laptop computers. See section 3.2.4.1 Hardware Connectivity Guidelines/Restrictions for more details regarding how to properly manage and responsibly use USPTO connected workstations.

24. Designate two individuals who will be responsible for the service and maintenance of the workstations connecting into USPTO. Provide these POC names to the COR who will request they receive Local IT Administrator authorization.

25. Re-base line all workstations with a valid CEP or CEDP approved baseline, application software, and all latest patches. Make sure to contact the Client Software Service Division for latest information pertaining to the CEP/CEDP and USPTO task-required client applications.

26. The contractor company shall acquire all necessary CEP/CEDP software licenses identified in the Workstation section.

27. Contact I/CSSD-Client Software Services Division, for all required USPTO provided client software:

• SCCM (System Center Configuration Management)

• CISCO AnyConnect

• USPTO Tasks required application software

• And all latest patches

28. Contact I/CSSD-Client Software Services Division, for any additional software installations and approvals. Note: Local IT Site Admin are only authorized to install approved software.

29. Request the sponsored USPTO Task Order Manager/TL to identify a list of all USPTO software applications that are required to perform the task.

30. Ensure all workstations that access USPTO follow the PTO configuration guide and automatically perform updates.

31. Configure all workstations to continuously pull their Symantec Endpoint Protection definitions (SEP 12 or higher) from USPTO

32. Request USPTO network accounts for each employee after the employee receives a USPTO badge and fingerprinted by USPTO security. This includes working with the Contractor’s Program Manager, COR, and Service Desk for user account creation and/or association with access and software profile groups.

33. If required, obtain an initial A&A network site certification, including all associated costs. See Security Contact in section 2 for contact information of USPTO’s security representative.

Note: The USPTO Enterprise Desktop Platform (EDP), Contractor Enterprise

OFFICIAL USE ONLY 3-12

Platform (CEP), and Contractor Enterprise Development Platform (CEDP) platforms are already assessed. They require no additional approval to be part of the site A&A process. Refer to number 15

34. Provide CAS TL with current point of contact information for network and patches update notification purposes.

35. Network Printers - All Service Desk tickets requesting connection of CAS Network Printers must include:

• Provide printer description

• Provide MAC address

• Request Static IP address

• Identify switch port number; refer to Section 4.2 for full details.

Notify the Service Desk to assign these requests to the Network Operation Services group for IP and printer assignments.

General

36. USPTO will provide common, basic access to their network. Contractor companies are responsible to contact ALL supporting TLs to determine if additional firewall rules are required to gain access to support any new USPTO responsibilities.

Additional access may be acquired by going through the USPTO Service Desk (571 272-9000) and creating a Change Request which will be assigned to Firewall Administration (Refer to Appendix E)

37. All unauthorized switch ports are to be disabled. If additional ports are required, contact the Service Desk to open a CR (contractor name, switch port, purpose, destination host, and patch port number). These types of requests are assigned to the Network Operation Services group.

38. Once the site is in production (turned over to USPTO Operations), all CAS/SEAS requests are process through the USPTO Service Desk (571)-272-9000 by working with your Local IT Administrator.

39. The preceding items listed above are for emphasis purposes; the contractor company is fully responsible for the execution of all other items specified in the MOU.

IMPORTANT NOTE: It is the company’s responsibility to ensure that NO network servers connects to the local USPTO network expansion. In addition, the contractor’s CEP or CEDP workstations (both desktop and laptop) can only connect to USPTO and no other network. In addition, the use of virtual machines and servers are prohibit on the CEP or CEDPs connecting to the USPTO network.

OFFICIAL USE ONLY 3-13

3.2.3 USPTO Responsibilities

USPTO is typically responsible for the following areas.

Note: This is a partial listing for illustrative purposes only; the Memorandum of Understanding (MOU) has the list of binding responsibilities.

1. Within two weeks of notification from the COR, the CAS TL, will schedule a CAS meeting to review and discuss all CAS responsibilities, network options, Desktop Services, and security.

2. The contract COR will be responsible to notify the CAS TL, of any PM or Local IT Administrator changes for documentation and communication purposes.

3. No Service Level Agreement (SLA) for network performance or bandwidth availability is guarantee by USPTO.

4. USPTO equipment is maintained and operated by the USPTO

5. After the initial CAS meeting with the new contractor, the CAS TL, will contact the new contractor, COR and security to arrange for the completion of a signed MOU and Cyber Security checklist before the USPTO CAS site inspection.

6. Upon completion of the site network installation, the CAS TL, will notify the COR, Contractor Program Manager, and the OPG Cybersecurity Division that the site is ready for the USPTO Cybersecurity Physical Site Survey.

7. Once all site requirements are inspected and acceptable to USPTO Cyber Security, USPTO will provide approval for the Communication Service Provider’s line termination points DMARC (T1, T3, and fiber). The contractor will be responsible for extending the DMARC into the contractor’s network room.

8. USPTO provides all routers, switches, and UPSs necessary to provide a connection to

USPTO.

9. USPTO will be responsible to provide the CEP software baseline requirements;

latest patches, USPTO security GPOs, and monthly update patch notices to Program Managers for distribution to the responsible Local IT Administrators for action.

10. USPTO will be responsible to provide CEP/CEDP hardware and software patches through their SCCM system.

11. USPTO CSSD is responsible for requesting the initial security scan of the company CEP/CEDP systems.

12. USPTO will perform quarterly security scans and remediation on CEP/CEDP systems.

13. Service Desk – USPTO will provide limited contractor Service Desk support, e.g., domain problems, user accounts, resource access, and network support (USPTO extended subnets).

OFFICIAL USE ONLY 3-14

14. User Account Management – USPTO will create USPTO network user accounts and add contractor employees into USPTO’s Active Directory server.

15. Desktop Services – USPTO’s Desktop Services Division will work with the contractor’s POC to meet the specification requirements of USPTO’s A&A workstation hardware.

16. Client Software Services Division: Provide assistance with installing USPTO workstation baselines.

17. All USPTO Technical Leads will provide a list of any task-specific, USPTO required application software and coordinate with I/CSSD-Client Software Services Division, on software installation.

18. CAS will coordinate notification to the contractors regarding any changes to the USPTO CAS site requirements.

3.2.4 Workstations

Unless USPTO provides GFE to contractors, USPTO is not responsible for purchasing or licensing the contractor’s workstations. To be in compliance with the USPTO A&A, contracting companies must follow the following workstation platform guidelines.

The term “workstation” as used in this document refers to the computer hardware along with the software applications installed.

3.2.4.1 Hardware Connectivity Guidelines/Restrictions

The specific computer hardware specifications are govern by the CEP/CEDP definitions from the USPTO Desktop Services Division. Below are some guidelines, rules, restrictions, and recommendations for acceptable behavior and responsible use of USPTO connectivity privileges.

Laptop computers are very common in the CAS environment and special care needs to be observe due to their portability. In general, once a desktop/laptop has been approved CEP/CEDP compliant and for connectivity into the USPTO domain, it shall not be disconnected and then reconnected into another domain. This is view as a serious security breach.

Hardware Guidelines/Restrictions:

• All CEP/CEDP hardware and software must be approve by USPTO to be place under the

USPTO A&A.

• USPTO recommends that the contractor use the same hardware make and model that USPTO has approved for use. Refer to 3.2.4.2 (Windows 10 CEP/CEDP Baseline Requirements)

• Lenovo and MAC computers are not permit on the USPTO network.

OFFICIAL USE ONLY 3-15

• Once a laptop has been approved CEP/CEDP compliant and connected to the USPTO network, it shall not be disconnected and then connected into any other network or domain such as the contractor’s corporate network.

• Once a laptop has been approved CEP/CEDP compliant and connected to the USPTO network, it should not be disconnected and reconnected into an unsecured, public Internet access, such as those found in the home, private use.

• The air-gapped requirement dictates a CEP/CEDP laptop is prohibit from connecting into the contractor’s corporate network; separate workstation machines must be maintain for the two different accesses.

• All computers connecting to the USPTO network MUST be both TAA and FIPS 140-2 compliant.

These regulations and restrictions also apply to desktop computers but emphasis is place on the laptop style machines due to their ease of portability.

3.2.4.2 USPTO – Contractor Enterprise Platform (CEP)

The contracting company CEP/CEDP workstation hardware/software must be approved by USPTO and allow the full USPTO security push (USPTO GPO), hardware and software security updates, and support a Windows 10, 64-bit Operating System.

All CEP/CEDP hardware and software must be approve by USPTO to be place under the

USPTO A&A.

The following software has already been A&A approved for a basic, functional contractor workstation.

Minimum Contractors Software Requirement as of March 19, 2018:

• Windows 10, 64-bit (Follow the USPTO Windows 10 LSTSB 64-bit image foundation)

• Windows Media Feature Pack version 12 (1607)

• Internet Explorer Browser 11.0

• All Microsoft security and Adobe Critical\important patches up to current date.

• USPTO approved Google Chrome Enterprise version 64 or current deployed version.

• Oracle Java 8 Update 121 or current Enterprise release version

• Microsoft Office Professional Plus 2016 with Skype for Business with OneDrive for

Business removed

• Symantec Endpoint Protection 12 RU6 MP6

• Symantec Management Agent (USPTO)

• Cisco AnyConnect (USPTO 4.4 approved version)

• Cisco WebEx Cloud (USPTO 5.0)

• Configuration Manager Client (SCCM Client) (USPTO)

OFFICIAL USE ONLY 3-16

• WinZip 20

Note: Mozilla Firefox is supported conditionally by USPTO.

Windows 10 CEP/CEDP Baseline Requirements: Contact I/CSSD-Client Software Services Division, or the COR to request the Windows 10 image preparation document to the Contracting companies. This document explains the Windows 10 build Hardware recommendation and Enterprise software for their Base images and requirement software and patches.

USPTO Recommended Optional Contractors Software:

• Putty (Latest) – File Transfers and server access

• WinSCP (Latest) – SSH, SCP, and SFTP File Transfers

• Microsoft Visio Professional 2016 (If appropriate) – Technical Drawings

Tasks Required USPTO Software:

The sponsored USPTO TL or TOM needs to submit a request with the list of USPTO software to USPTO I/CSSD-Client Software Services Division team for approval and processing. The email request should contain the following:

• Contractor…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .