Attachment 01a - Contractors Access to USPTO v4.1 Before Awarded 12-09-2019 Final.doc
DOC document 4 MB Posted
- Attached to
- Patent Data and Document Management (PDDM) Federal contract opportunity
- Solicitation number
- 1333BJ20R00151004
About this file
This document is a solicitation for the Patent Data and Document Management (PDDM) Request for Proposals from the United States Patent and Trademark Office. The solicitation seeks contractor support to manage the entire life cycle of patent application processing, from initial filing to final disposition. Contractors must thoroughly review the RFP, statement of work, references, attachments, and glossary to achieve a complete understanding of requirements. The attachments have been updated since the presolicitation notice. The attachment version dates can be found in the Section J crosswalk. The solicitation involves management of patent application processing for the Department of Commerce US Patent and Trademark Office. Interested parties must review provided materials to understand product, service, and administrative requirements fully.
View the file
Other files for this federal contract opportunity
Show all 50
Patent Data and Document Management (PDDM) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Infrastructure, Design, Engineering, Architecture, and Integration (IDEAI-2)
Contractor Access Engineering (CAE)
Contractors Access to USPTO
Version 4.1
For
U.S. Patent and Trademark Office
Dec 9, 2019 Record of Changes
| Version |
| Date |
| Pages Affected |
| Type of Change |
| 1.0 |
| 5/9/2012 |
| All |
| Original version. |
| 2.0 |
| 2/26/2013 |
| Chapter 4 |
Appendix A
Pg. 3-8 Add Chapter 4 – Processes
Add Role Definition table as Appendix A
Expand workstation definition (Section 3.2.4.1)
Help Desk reference changed to Service Desk
| 2.0 |
| 3/5/2013 |
| Pg. 2-1 |
| Incorporated an update to the COR Division Name in the POC table |
| 2.1 |
| 8/23/2013 |
| Pg. 2-1 |
Pgs. 3-1, 2, 3
Pg. 3-6 Adjust POC information to align with USPTO organizational changes
Update USPTO campus and Direct Connect graphics
Add Connectivity Options table
| 2.1 |
| 8/30/2013 |
| Pg. 2-1 |
| Change Critical Problem Notification (CPN) reference to Problem Management Notification (PMN) |
| 2.2 |
| 4/21/2014 |
| Pgs. 1-1,2,3 |
3-13 Add guidance for TIC 2.0 compliance and Enterprise Access Infrastructure Systems (EAIS)
| 2.3 |
| 12/8/2014 |
| All |
| Update with new USPTO polices for contractor access and scheduling procedures. |
| 2.4 |
| 02/19/2015 |
| All |
| Updated document with New Contractor Partner Zone for MTIPS connections |
| 2.5 |
| 05/12/2015 |
| Pgs. 2-1, 3-4,#5 |
Appendix H MOU Title Page Removed Linda Brinson, retired in Jan 2015.
Rephrased the sentence for TL to provide the CAE document. Correct CO to be in OCFO. Correct Project Manager or Program Manager
| 2.6 |
| 05/15/2015 |
| Page G-1 |
| Change to Revision 4 |
| 2.7 |
| 05/21/2015 |
| Appendix H, |
All Footer Replace Cover Page of MOU
Change to “Official Technical Use Only”
| 2.8 |
| 06/1/2015 |
| All Pages |
| Review and Updated all pages, PTO CEP Software list. |
| 2.9 |
| 11/6/2015 |
| All Pages |
| Review and Updated Contractor Responsibilities |
| 2.9 |
| 12/3/2015 |
| All Pages |
| Change 800-53 Revision 3 to 800-53 Revision 4 |
| 3.0 |
| 02/4/2016 |
| All Pages |
| Remove all TLS information and support , replaced COTR to COR |
| 3.1 |
| 08/29/2016 |
| All Pages |
| Updated VPN, SEAS, and Remote Access Information and MOU |
| 3.2 |
| 11/15/2016 |
| All Pages |
| Updated sections 3.2.2, 3.2.4, Workstations Item #19, Appendixes C, D, H, and Table of Content. |
| 3.3 |
| 12/01/2016 |
| All Pages |
| Updated Table of Content, Sections 2.1, 2.2, 3.2.4.2, 4.1, Appendix B |
| 3.4 |
| 02/21/2017 |
| Pgs. 3-7, #12, H-3 -#3 |
| Added - “USPTO has full admin rights to manage and control the GFEs or any network devices that are connected to PTONet.” |
| 3.5 |
| 10/15/2017 |
| All |
| Updated all pages |
| 3.6 |
| 03/30/2018 |
| All |
| Updated all pages - Final |
| 3.7 |
| 04/05/2018 |
| 3-15 to 3-17 |
| Updated security comments |
| 3.8 |
| 05/15/2018 |
| 3-4 |
| VPN to VPN (Standard) |
| 3.9 |
| 09/03/2018 |
| All Pages |
| Added – “FOR CAS TECHNICAL USE ONLY – NO USPTO CONTRACTUAL/LEGAL CHANGES” |
| 4.0 |
| 05/09/2019 |
| MOU page H-3, and 2-1 |
| Removed Jay Chalk name and email, Replaced Rami Dillon name and email with Don Watson name and email. |
| 4.1 |
| 12/09/2019 |
| 1-5 |
| Removed Windows 7, Modify: Microsoft Windows 7 or earlier is NOT allowed. USPTO supports only Windows 10 systems. |
TABLE OF CONTENTS
1-11 Introduction
1-11.1 Description of Function and Purpose
1-31.2 AIS Development Organization
1-31.3 AIS Sponsoring Organization
1-31.4 Security Impact Statement
1-41.5 Contractor Telework Support
2-12
POINTS OF CONTACT
2-12.1 Manager and Support Contacts
2-12.2 Major Incident Alert (MIA)
3-13
DETAILED SUPPORT SPECIFICATIONS
3-13.1 Contractor Access System (CAS) Overview
3-43.2 Direct Access
3-43.2.1 Selecting an Access Network
3-53.2.2 Direct Access Implementation Process
3-133.2.3 USPTO Responsibilities
3-143.2.4 Workstations
3-143.2.4.1 Hardware Connectivity Guidelines/Restrictions
3-153.2.4.2 USPTO – Contractor Enterprise Platform (CEP)
3-173.2.4.3 USPTO - Contractor Enterprise Development Platform (CEDP)
3-183.2.4.4 USPTO – Government Furnished Equipment (GFE)
3-183.2.5 Final Site Workstation Review and Audit:
3-183.2.6 USPTO Software Download/Support via SCCM:
3-183.2.7 Non USPTO Approved Software Requests:
3-183.3 EAIS Axway SecureTransport Requests:
3-183.4 Secure External Access System (SEAS)
3-183.4.1 SEAS System Overview
3-203.4.2 SEAS - Contractor Responsibilities
3-213.4.3 SEAS– USPTO Responsibilities
4-14 Processes
4-14.1 Service Desk
4-24.2 CAS Network Direct Access
4-34.3 USPTO User Requirements
4-34.4 SEAS – Additional Application Requests
A-1APPENDIX A:
Role Definition
B-1APPENDIX B:
Abbreviations and Acronyms
C-1APPENDIX C:
CAE Proposed Direct Connection Site Request to USPTO Form
D-4APPENDIX D:
New CAS Site Request Guidelines
E-1APPENDIX E:
USPTO Pre-production Firewall Request
F-1APPENDIX F:
SEAS Global Groups within Active Directory
G-1APPENDIX G:
NIST SP 800-53A - (Physical Security Controls)
H-1APPENDIX H:
Memorandum of Understanding (MOU) or Agreement
LIST OF FIGURES
3-1Figure 3‑1 Direct Connection Methods
3-2Figure 3‑2 USPTO Campus CAS Infrastructure
3-19Figure 3‑3 SEAS Logical Diagram
LIST OF TABLES
2-1Table 2‑1: CAS Manager and Contact Support
1 Introduction This document was prepared for the United States Patent and Trademark Office (USPTO) under the Contractor Access Engineering (CAE) Task Order, managed by USPTO CAE Task Order Manager (TOM), USPTO CAE Technical Lead.
This document provides pertinent information required for new contractors to access USPTO’s network from outside the USPTO main campus. Various types of access described within this document:
1. Direct Connect (Contractor Access System - CAS)
2. External Partners
3. Secure File Transfer (Enterprise Access Infrastructure Systems - EAIS)
4. Internet-based access (Secure External Access System – SEAS)
1.1 Description of Function and Purpose
Direct Connect through Contractor Access System (CAS) The CAS network provides remote government sites and contractors with limited, monitored, and secure access to the authorized USPTO network (PTONet) applications, resources, services, and the assorted test networks through the Enterprise Trusted User (ETU) firewall architecture. The ETU firewall filters and monitors all CAS traffic. Only USPTO-approved government and contractor sites, workstations and printers are allow connecting to the CAS network. CAS users may also access the Internet through the USPTO Internet proxy server.
CAS allows contractors to perform both operations maintenance activities for production systems and development efforts in a separate environment. Enforcement of separation of duties are enforce to ensure developers do not make changes to production systems in accordance with the System Development Lifecycle (SDLC) model.
External Partners Some projects require contractors to collaborate and work closely with USPTO government employees and resources; e.g. developing software applications for USPTO to process patent and trademark applications. This collaboration and close interworking relationship may require file and data transfer from the contractor’s network into the PTONet environment. Carefully evaluating the level of collaboration or interaction is critical to establish the appropriate access and security levels.
Contractors who require a deeper integration and are considered “external partners with a documented mission requirement and approval” may need to establish a service in compliant with the Office of Management and Budget's (OMB) Trusted Internet Connections (TIC) initiative. If contractors are required to exchange data from their local corporate network with PTONet, the exchanged must be perform in a secure manner. US General Services Administration (GSA) developed the Managed Trusted Internet Protocol Service (MTIPS) to allow US Federal agencies physically and logically connect to the public Internet and other external connections in compliance with the OMB’s TIC initiative. The MTIPS Security Operations Center monitors all information exchanged with external networks to protect agency traffic. The MTIPS transport serves as a collection network for the TIC portal, insulating an agency’s internal network from the Internet and other external networks. This may involve purchasing a TIC 2.0 service from one of the commercial carriers designated as a Managed Trusted IP Service (MTIPS) provider.
USPTO will not pay for any leased lines or leased line services.
Note: Contractors will pay for any of these types of TIC 2.0 services. For business relationships which require this type of file/data exchange, contact the COR to discuss.
Enterprise Access Infrastructure Systems (EAIS) Contractors whose only requirement is to transfer or exchange files with USPTO can perform this activity through their company’s Internet access (no CAS network required). File transfer to USPTO from approved contractor sites can be perform through the Internet using the Axway system USPTO already has established. This system enables both internal (USPTO) and external (contractors) users to perform secure file transfer by using multiple methods; server-to-server, user accounts, automated delivery to account shares, etc.
The bulleted content below highlights some of the strict requirements, which govern the approved methods for transferring files.
· Any file transfer activity must use only software approved by USPTO and meets the FIPS 140-2 compliance requirements. USPTO has approved Axway SecureTransport – Enhanced Managed File Transfer (MFT) servers and proxies which are FIPS 140-2 enabled.
· Any file content identified as “sensitive” that is transferred over the Internet via server-to-server transfers must use the AS2 protocol.
· Any internal files using server-to-server transfers from within the CAS network must transfer over the Internet using SFTP-SSH protocol 2 with FIPS 140-2 compliance enabled. Also, any external files (e.g. on the contractor’s network) may use the same exact setup for file transfer with USPTO. Axway software is a multi-protocol solution and all protocols are present on one system under the Axway SecureTransport software.
For all questions regarding future network design, connections, or Axway SecureTransport with USPTO, contact the procurement office and they will contact the appropriate person.
Contractors will pay for their server equipment, network equipment, and Axway SecureTransport software and licenses.
Note: For business relationships which require this type of file exchange, contact the COR to discuss how to establish these services.
Internet-Based Access through the Secure External Access System (SEAS)
The primary goal of SEAS is to enable authorized remote users to access USPTO applications, resources and services via the Internet. Contractors in remote contractor sites can connect to PTONet through the Internet. Secure Sockets Layer (SSL)/Transport Layer Security (TLS) encryption and strong two-factor authentication mechanisms (RSA SecurID) for remote users are included in the system. USPTO Virtual Private Network (VPN) appliances and Citrix servers provide a secure mechanism for contractors to access resources on PTONet via their workstations. Software application profiles can be associated with each user’s account access group(s) – see Appendix F. Contractors may request additional software beyond what is loaded per the user profile by submitting a request to the CAE Technical Lead.
1.2 AIS Development Organization
The SEAS and CAS development teams consist of representatives of the USPTO’s Office of the Chief Information Officer (OCIO) and General Dynamics Information Technology (GDIT).
1.3 AIS Sponsoring Organization
The OCIO sponsors the SEAS and CAS Automated Information Systems (AISs).
1.4 Security Impact Statement
Direct Connect through Contractor Access System (CAS) CAS connects to PTONet through the ETU firewall that monitors and filters all traffic between CAS and PTONet. Workstations and printers are allowed to connect to the CAS network provided they have been assigned Media Access Control (MAC) address entered into the CAS network switch at a CAS site. This procedure allows only the registered workstations and printers to access the CAS network. USPTO also requires all CAS sites must maintain an air-gapped network between PTONet and any other network, such as the contractor’s corporate network.
Laptop computers are very common in the CAS environment and special care needs to be observe due to their portability. In general, once a workstation has been approved CEP/CEDP compliant and approved for connectivity into the USPTO domain, the workstation is not allowed be disconnected and then reconnected into another domain. This disconnect/reconnect would be viewed as a serious security breach. These regulations and restrictions apply to desktop and laptop computers but emphasis is on the laptop style machines due to their ease of portability.
USPTO will provide patching to the Minimum Contractors Software Requirements in section 3.2.4.2 of this document. To insure USPTO has access to your CEP/CEDP workstations, your Local IT administrator must ensure that USPTO SCCM client is installed and functioning/communicating properly. The SCCM is USPTO system is use to push out security patches to all USPTO domain attached workstation. USPTO SCCM client and the CEP/CEDP workstation being updated and compliant are mandatory.
Currently USPTO scans all CEP (Contractor Enterprise Platform) workstations once the approved baseline image is install on the contractors purchased hardware. USPTO will scan all CEP workstations with the approved baseline image and any additional software that the contractor requires to perform their duties on USPTO. Scanning will be perform prior to PTONet connection in order to remediate any vulnerability and compliance issues. Once remediation efforts are completed, USPTO remediation team will notify USPTO security and arrange a rescan to ensure all critical, high and medium findings have been remediate. Lastly, on a quarterly basis, your systems will be rescan for vulnerability and compliance and USPTO will promptly remediate any findings that result from these scans.
Enterprise Access Infrastructure Systems (EAIS) EAIS is a group of file transport servers and proxies approved by USPTO to transfer and receive files within the USA. All EAIS accounts are approve by the task USPTO COR, the Technical Leader/Manager, and EAIS Technical Leader. File transfers are perform under approved USPTO certified software and transferred under FIPS 140-2 compliance. USPTO has approved Axway Secure Transport – Enhanced Managed File Transfer (MFT) servers and proxies for their file transfers with FIPS 140-2 compliance enable.
Internet-Based Access through Secure External Access System (SEAS)
SEAS connects to PTONet through the Enterprise Remote Access Juniper VPNs and the ETU firewall. The ETU firewall monitors and filters all traffic between SEAS and PTONet. Contractor access is limited prohibiting local upload/download of files and network printing. Printing to a direct attached local printer to a workstation is allowed.
1.5 Contractor Telework Support
USPTO Contractor Telework Support Service Levels Agreement
Access to USPTO is perform through various methods CAS, SEAS, and on site. USPTO does support government employee’s telework with USPTO government furnished equipment (GFE). Contractor Telework through the various workstations Contractor Enterprise Platform, Contractor Development Platform, and User Furnish Equipment all have very limited support. It is up to the contractors to support their own equipment, operating system, and software.
Users accessing contractors CEP/CEDP systems through USPTO VPN (Team portal) RDP or through SEAS (RDP) and/or the Published Desktop have inherited delays due to various, VPN’s, ISP’s, and networks.
The local company administrator is responsible for both CEP/CEDP workstation support and ISP connection.
The users are responsible for their user furnished equipment (UFE) and home ISP connection.
User access to various USPTO resources is the user’s responsibility.
Limitations:
· Not all Operating Systems are supported.
· Microsoft Windows 7 or earlier is NOT allowed.
· USPTO supports only Windows 10 systems.
· USPTO VPN and SEAS access is through users Internet Explorer 11 browser ONLY (USPTO Support).
· PTO does not allow MAC and Lenovo systems on the USPTO network.
· All RDP access to CEP/CEDP workstations will require a PIV Smart Card and reader.
· No downloading /uploading of files allowed.
· Only local printing allowed.
· No SLA for network performance or bandwidth availability is guarantee by USPTO.
Service Desk – USPTO will provide limited Service Desk support for Team Portal VPN, RSA SecurID FOB, and SEAS issues. PTO on User Furnished Equipment (UFE), CEP, and CEDP systems does not provide desktop services. For additional information, refer to the Team Portal VPN User Guide and the SEAS User Guide.
2 POINTS OF CONTACT
2.1 Manager and Support Contacts
Table 2‑1: CAS Manager and Contact Support
| Organization/Role |
| Name |
| Business Area/Office/Division |
| Office Phone Number |
CAE Technical Lead
I/CSB
Communication Services Branch
COR for CAS/SEAS/EAIS
I/VMD
Vendor Management Division
Client Software Services Division
I/CSSD
Client Software Services Division
Client Software Services Division
I/CSSD
Client Software Services Division
Desktop Services Division
I/DSD
Desktop Services Division
Symantec Endpoint Protection Server - Contact
I/OSAES
OS Administration and Engineering Section
Operation Support – Operations Section
I/OS-OS
OS-Operations Section
IT Cyber Security Director
I/CD
Cyber Security Division
IT Security Authorization
(A&A Government)(acting)
I/SAB
Security Authorization Branch
IT Security Officer
(Cyber Security)
I/CD
Cyber Security Division
IT Security Officer
(Cyber Security)
I/SAB
Security Authorization Branch
Service Desk / Service Desk Chief
I/SDB
Service Desk Branch
Network Operational Support
I/CSB
Service Desk
I/SDB
Service Desk Branch
Firewall
I/SSB2/Software Services Branch
USPTO leased line/communication Telco
I/CSB
2.2 Major Incident Alert (MIA)
When a problem results in an outage or major loss of functionality to multiple customers, the OCIO Service Desk will prepare and e-mail a Major Incident Alert (MIA) message to CAS and/or SEAS users. The Service Desk will update the MIA periodically until the problem is resolved.
3 DETAILED SUPPORT SPECIFICATIONS
3.1 Contractor Access System (CAS) Overview
CAS provides off-site contractors with secure network access to PTONet, the test environments, and a proxy Internet access via a direct connection between the contractor site and USPTO’s Contractors Access System (CAS). Figure 3-1 shows the two methods of establishing a direct connection, e.g. Single Mode Fiber and VPN-to-VPN. The CAS site Eisenhower Ave uses RF connectivity back to USPTO. Contractors connect to USPTO through the 1st. floor MDF room via single mode fiber from their location.
Figure 3‑1 Direct Connection Methods Figure 3-2 shows the USPTO Local Campus building connections where contractors can get CAS access. The network at the contractor site must be isolated from the contractor’s corporate network to meet Assessment & Authorization (A&A) security requirements.
Figure 3‑2 USPTO Campus CAS Infrastructure Contractor Access System Support Level Agreement
CAS SLA support for both direct connection (Carlyle Place, Carlyle Center) and Radio Frequency (RF) connectivity (Hoffman Building on Eisenhower Ave) are best effort. The 2034 Eisenhower Ave connectivity past history, has been very reliable, however, during extreme weather, the RF systems can be affected by heavy snow/storm or violent winds. The RF system is reliable 99.9% of the time.
CAS SLA support for VPN to VPN connection is within the boundaries of the CAS firewall, switch and UPS.
USPTO does not guarantee contractors connections to USPTO. All contractors are responsible for their own connection to USPTO at their own cost. The above mentioned locations with direct and RF connections are provided as a free service since those locations already have access to USPTO. Contractors requiring 100% guarantee are recommend to connect via VPN to VPN.
Support for the contractor network, ISP connection and CEP/CEDP workstation and printers are under the contractor local IT administrator.
3.2 Direct Access
3.2.1 Selecting an Access Network
Each contractor must carefully evaluate their specific data communication requirements between their site and the USPTO network. Consideration of factors such as capacity, costs, distance, etc. are reviewed in order to choose a service that best fits the type of work that is outlined in the details of the awarded contract.
Some of the main attributes of the available options are in the table below:
| Connection Option |
| Attributes/Characteristics |
VPN to VPN
(Standard) Preferred method of connecting contractor site, which is, located a long geographical distance away from the Alexandria main campus. Also suitable for contracting companies located near the Alexandria campus. This economical option leverages off the contracting company’s existing Internet service.
The Internet bandwidth capacity must be evaluated to ensure it will support the anticipated increased traffic demands resulting from the USPTO contract. It’s contractor responsibility to provide proper bandwidth enough to handle all the traffic demand to meet the contract requirements.
Since the Internet service already exists, there is no wait-time to establish a completely new service with an ISP.
A spike in USPTO Internet usage has the potential to affect the contracting company’s connection into PTONet.
| Fiber |
| Contractor sites located in buildings very near the Alexandria campus have pre-existing fiber connecting into the USPTO facilities and offer a direct connection into the USPTO network. |
Contractors are responsible to make the connection from their office area to the demarcation point in the building where the service terminates.
| RF |
| Available for 2034 Eisenhower Avenue, Alexandria, Virginia only. |
T1/T3 (Legacy Only) Supported for legacy contractors with an established service only.
The T1/T3 connections will be disconnected once the existing contractor’s contract is completed. T1/T3 connection will no longer be accepted for new contractors.
TLS
(Legacy Only) USPTO has an established connection into the Verizon Transparent LAN Service (TLS). This is a fiber optic; Ethernet based connection, which has been establish in the VA, DC, and PA metropolitan area. This connection is a Point-to-Multipoint service.
Contracting companies are required to purchase a 10 MB or 100 MB service of the TLS.
The TLS connections will be disconnected once the existing contractor’s contract is completed. TLS connection will no longer be accepted for new contractors.
VPN to VPN (Contractor Partner Zone) or (MTIPS) Available for approved External Partners using Contractor Partner Zone (CPZ) or Managed Trusted Internet Protocol Service (MTIPS) Providers.
3.2.2 Direct Access Implementation Process
The following seven steps outline the high-level process to establish a new, direct access network for a contractor’s site.
1. Written Request: Contractor provides written request (email) to the appropriate COR who will determine if the contractor is authorized to have direct network access via CAS. Once COR approval (estimated three business days) is attained, proceed to step 2.
2. Engage COR: Either the contractor forwards the COR approval, or the COR sends request to the USPTO CAS Technical Lead.
3. Form Completion: Within three business days from receiving request from COR, the CAS TL emails to the contractor, cc’d COR, the “Contractor Access to USPTO” document package, to read and fill out Appendix C (Proposed Direct Connection Site to USPTO Request Form), and MOU in Appendix H. The Contractor Access to USPTO document outlines the detailed responsibilities of USPTO and the contractor. Once all information is filled out and completed, with all required signatures on MOU, the company then returns the completed Appendix C and the signed Appendix H (MOU) to their COR and cc’d to CAS TL. In addition, the contractor provides a Point of Contact (POC) to work with the CAS Network Engineers, USPTO Desktop Services, Client Software Services Division, Service Desk staff, and USPTO Cyber Security (A&A) for the remainder of the process. Upon receiving the completed signed forms, CAS TL will proceed to step 4.
Note: USPTO and contractor execute their responsibilities as defined in the signed MOU
4. Initial Meeting (Kick-Off Meeting): Within five business days, after receiving the completed signed forms from the company, the CAS TL will forward the signed forms to Cyber Security Office, and will schedule a meeting with the following USPTO Organizations (see Section 2: Contacts) to detail each party’s responsibilities outlined in Section 5 of the Memorandum of Understanding (MOU):
a. COR and all TOMs
b. CAS Network Access team: Direct Local Access (Fiber, RF), VPN-to-VPN, and MTIPS.
c. Desktop Services: Hardware platforms
d. Service Desk team: User accounts
e. Client Software Services Division: CEP/CEDP and latest patches
f. Security team: A&A, other security-related interests
g. Leased line team (if applicable)
5. Post Kick-Off Meeting: The vendor will need to work with Cyber Security team first to get their approval for the site prior to a CAS site network setup and GFE delivered. In addition, the vendor will also need to work with all other teams (as specified in Kick-Off Meeting paragraph).
6. Network Design Meeting: Upon receiving approval from Cyber Security team, within five business days, the CAS team will schedule a network meeting with the requesting company, their associated COR, their Program Manager, and their IT POC to review the CAS site network requirements.
The “New CAS Site” process guideline overview is located in Appendix D. CAS sites installations are perform on a FIFO basis unless authorized by the USPTO CAS TL. The estimated installation schedule is dependent upon the CAS installation schedule.
During CAS site pre-installation, submit all issues or concerns through email to the USPTO CAS TL, with details describing the complaint. A meeting will be scheduled with the appropriate parties to evaluate, discuss for appropriate solution.
Contractor Responsibilities The contractor is typically responsible for the following areas. Note: This is a partial listing for illustrative purposes; review the Memorandum of Understanding (MOU) for the binding list of responsibilities.
Initial Preparation
1. Contact the USPTO COR and USPTO CAS TL, with your request for a direct connection with USPTO.
2. Provide a signed USPTO Memorandum of Understanding (MOU) or Agreement through your COR, who will forward it to USPTO CAS TL. Refer to Appendix H.
3. Provide completed USPTO security documents CAS Security Questionnaire and Security Physical Site Survey Checklist.
4. Obtain and fund the site connection to the nearest USPTO access point.
USPTO will not pay for any leased lines or leased line services.
5. Provide Primary and Alternate point of contact (POC) individuals to work with the CAS Technical Lead (TL) and CAS Network Engineers to develop a specific network design and configuration for the contractor; this will include a network diagram, network components (vendor, model name), and IP addresses.
6. To prepare for a connection into USPTO via T1 or T3, contact USPTO CAS TL, for approval and assistance in working with the USPTO side of the telco environment.
USPTO will not pay for any leased lines or leased line services.
7. If the decision is approve for a leased line (T1 or T3) connection between your site and USPTO, then contact USPTO Network Branch, for assistance.
USPTO will not pay for any leased lines or leased line services.
8. If access for your site will be a VPN to VPN connection, submit your required Public Internet IP Address through your USPTO COR to USPTO CAS TL, at least three weeks prior to the installation date.
9. If you request approval to become an External Partner using the Contractor Partner Zone or MTIPS access, contact USPTO COR and USPTO CAS TL, for approval and assistance in working with the USPTO side for your environment. All External Partners will be required to connect to USPTO through the Trusted Internet Connection (TIC). To review Homeland Security Trusted Internet Connections (TIC) Initiative and receive the full document of the Trusted Internet Connections (TIC), Reference Architecture Document, Version 2.0, go to http://www.dhs.gov/trusted-internet-connections and https://www.fedramp.gov/files/2015/04/TIC_Ref_Arch_v2-0_2013.pdf.
USPTO will not pay for any leased lines or leased line services.
10. Contractor company site Program Manager is responsible to notify the contract COR within 10 business days any PM or Local IT Administrators changes.
11. Contractor companies will contact their Local IT Administrator for all workstation and application support. (USPTO does not provide support for contractor’s workstations and applications).
12. Contractor companies will be responsible to verify all CEP/CEDP workstations are online and accessible for USPTO to push all supported software patches.
13. Contractor companies will be responsible to verify all CEP/CEDP workstations hardware and software patches up to date.
Network Preparation
14. Run/pull all network cabling within the contractor’s facility. This includes power cabling and an “access point” for USPTO to connect PTONet within the contractor’s facility.
15. Provide all network cabling to extend the Communication Service Provider (e.g. Verizon, AT&T) line termination points DMARC (T1, T3, and fiber) to the contractor secured network room and terminated.
16. Provide a secure locked network room or, if approved, a lockable network cabinet within the contractor’s facility where all the CAS network equipment will be located. All CAS network components must be segregate by a cabinet/rack installation from all other equipment. USPTO has full admin rights to manage and control the GFEs or any network devices connected to PTONet. It is permissible to allow the contractor’s corporate network and/or servers to reside in the same secured room (Additional requirements regarding the network closet/cabinet housing the USPTO equipment are listed in the Physical Site Survey requirements provided by the OPG Cyber Security Division).
Network closet: The Contractor's network closet must meet all Cybersecurity physical, environmental (HVAC), and security requirements. Cybersecurity approval is required before the site installation can begin. No exceptions.
Standard Network Rack Space Requirements: Space for a single Cisco 3750v2 switch (or Juniper EX4300 switch), Juniper SRX Firewall and an APC Smart UPS 1500 RT.
Additional Equipment Information:
· Rack Unit Space: 8U (add 3U for each additional network switch)
· Rack Weight: 71 lbs. (add 10lbs. for each additional network switch)
· Rack Space Depth: 30 inches (note UPS is 22” Deep, room is required behind the UPS to connect the power, management cables)
Network cabinet: The contractor's cabinet must meet all Cybersecurity physical and security requirements. Cybersecurity approval is required before the site installation can begin. No exceptions. All network cabinets will require the CAS TL to review and approval before installation.
Cabinet physical requirements:
· Minimum size 19"H*28"H*30"D that is securable and lockable
· Lockable doors and sides
· Well vented construction
· Lockable wheels or the cabinet must be bolted to a secure item
Cabinet Space Requirements: for a single Cisco 3750v2 switch (or Juniper EX4300 switch), Juniper SRX Firewall and an APC Smart UPS 1500 RT.
Cabinet Space Requirements:
· Unit Space: 8U (add 3U for each additional network switch)
· Weight: 71 lbs. (add 10lbs. for each additional network switch)
· Space Depth: 30 inches (note UPS is 22” Deep, room is required behind the UPS to connect the power, management cables)
17. Provide cabinet/rack power requirements including any utility company fees/any associated costs.
Standard Power Requirements:
A dedicated 20 amp. AC electric power circuit with an NEMA 5–20R T-slot receptacle within 3 feet of the future USPTO UPS location.
18. Provide Cat6 patch cables for the connections between the switch and patch panel.
19. Provide suitable heating, ventilation, and air conditioning (HVAC) environment for the network equipment.
Heat Distribution:
The average total heat output of the USPTO network equipment is approximately 2,442 BTU/hour:
· Cisco 3750v2 switch (or Juniper EX4300 switch) 1796 BTU/hour
· Juniper SRX Firewall 253 BTU/hour
· APC Smart UPS 1500 RT 393 BTU/hour
20. Notify the OPG Cyber Security Division to request the following documents and actions:
a. A copy of the CAS questionnaire document must be completed prior to performing the physical site survey.
b. Set up a Physical Site Survey (sites must be compliant and prepared to meet these specifications prior to conducting the Physical Site Survey)
c. Contact OPG Cyber Security Division, for a new CAS site survey.
21. Review and understand the Security requirements in Appendix G and the Physical Site Survey requirements provided by the OPG Cyber Security Division.
22. Remote Site Installation If a contractor’s site is located far enough away to warrant overnight travel from the USPTO Alexandria campus, “remote installation” may be a practical approach. Remote CAS site installations are performed without having a member of the CAS Network Team on-site; the site network support staff will perform the install of the pre-configured equipment and power up activities. In this approach, the CAS Network Team will engage via phone support to monitor and assist with instruction.
To set up for a remote site installation, the following items are required:
a. Windows 10, 64 bit laptop computer – This will be use as a backup in case the CAS Network Engineer loses connection to the primary console port.
b. Juniper compatible USB/serial console cable - USPTO will provide the serial console cable in support of assisting USPTO.
c. CAS Remote Site Installation Guide – Provides the necessary instruction Workstations
23. Unless USPTO will provide GFE, the contractor is responsible to purchase all employees’ workstations at their own cost (recommend to consult with USPTO Desktop Services Division prior to making any purchase). These workstations must be:
a. A certified vendor/model and configuration that USPTO uses which meets the USPTO’s A&A requirements. These workstations baselines are refer to as the USPTO Enterprise Desktop Platform (EDP). The EDP Platform is already A&A by USPTO. Please contact Desktop Services Division to obtain EDP hardware specifications.
b. Contractor’s hardware must be able to support and sustain all appropriate patches to the USPTO CEP/CEDP software platforms along with any USPTO Client software required by the task. Contact the Client Software Services Division identified in Section 3.2.4.3 for details. Both the CEP and CEDP Platforms are already A&A by USPTO.
c. Re-use of existing Contractor Furnished Equipment that is currently on the USPTO campus will require re-base lining to the new company approved CEP/CEDP image. The pre-existing USPTO images will not be provide or transfer for re-use.
d. For GFE, the contractor needs to work with Desktop Services Division and USPTO Cyber Security team for rules and regulations.
Note: The term workstation applies to both desktop and laptop computers. See section 3.2.4.1 Hardware Connectivity Guidelines/Restrictions for more details regarding how to properly manage and responsibly use USPTO connected workstations.
24. Designate two individuals who will be responsible for the service and maintenance of the workstations connecting into USPTO. Provide these POC names to the COR who will request they receive Local IT Administrator authorization.
25. Re-base line all workstations with a valid CEP or CEDP approved baseline, application software, and all latest patches. Make sure to contact the Client Software Service Division for latest information pertaining to the CEP/CEDP and USPTO task-required client applications.
26. The contractor company shall acquire all necessary CEP/CEDP software licenses identified in the Workstation section.
27. Contact I/CSSD-Client Software Services Division, for all required USPTO provided client software:
· SCCM (System Center Configuration Management)
· CISCO AnyConnect
· USPTO Tasks required application software
· And all latest patches
28. Contact I/CSSD-Client Software Services Division, for any additional software installations and approvals. Note: Local IT Site Admin are only authorized to install approved software.
29. Request the sponsored USPTO Task Order Manager/TL to identify a list of all USPTO software applications that are required to perform the task.
30. Ensure all workstations that access USPTO follow the PTO configuration guide and automatically perform updates.
31. Configure all workstations to continuously pull their Symantec Endpoint Protection definitions (SEP 12 or higher) from USPTO
32. Request USPTO network accounts for each employee after the employee receives a USPTO badge and fingerprinted by USPTO security. This includes working with the Contractor’s Program Manager, COR, and Service Desk for user account creation and/or association with access and software profile groups.
33. If required, obtain an initial A&A network site certification, including all associated costs. See Security Contact in section 2 for contact information of USPTO’s security representative.
Note: The USPTO Enterprise Desktop Platform (EDP), Contractor Enterprise Platform (CEP), and Contractor Enterprise Development Platform (CEDP) platforms are already assessed. They require no additional approval to be part of the site A&A process. Refer to number 15
34. Provide CAS TL with current point of contact information for network and patches update notification purposes.
35. Network Printers - All Service Desk tickets requesting connection of CAS Network Printers must include:
· Provide printer description
· Provide MAC address
· Request Static IP address
· Identify switch port number; refer to Section 4.2 for full details.
Notify the Service Desk to assign these requests to the Network Operation Services group for IP and printer assignments.
General
36. USPTO will provide common, basic access to their network. Contractor companies are responsible to contact ALL supporting TLs to determine if additional firewall rules are required to gain access to support any new USPTO responsibilities. Additional access may be acquired by going through the USPTO Service Desk (571 272-9000) and creating a Change Request which will be assigned to Firewall Administration (Refer to Appendix E)
37. All unauthorized switch ports are to be disabled. If additional ports are required, contact the Service Desk to open a CR (contractor name, switch port, purpose, destination host, and patch port number). These types of requests are assigned to the Network Operation Services group.
38. Once the site is in production (turned over to USPTO Operations), all CAS/SEAS requests are process through the USPTO Service Desk (571)-272-9000 by working with your Local IT Administrator.
39. The preceding items listed above are for emphasis purposes; the contractor company is fully responsible for the execution of all other items specified in the MOU.
IMPORTANT NOTE: It is the company’s responsibility to ensure that NO network servers connects to the local USPTO network expansion. In addition, the contractor’s CEP or CEDP workstations (both desktop and laptop) can only connect to USPTO and no other network. In addition, the use of virtual machines and servers are prohibit on the CEP or CEDPs connecting to the USPTO network.
3.2.3 USPTO Responsibilities
USPTO is typically responsible for the following areas.
Note: This is a partial listing for illustrative purposes only; the Memorandum of Understanding (MOU) has the list of binding responsibilities.
1. Within two weeks of notification from the COR, the CAS TL, will schedule a CAS meeting to review and discuss all CAS responsibilities, network options, Desktop Services, and security.
2. The contract COR will be responsible to notify the CAS TL, of any PM or Local IT Administrator changes for documentation and communication purposes.
3. No Service Level Agreement (SLA) for network performance or bandwidth availability is guarantee by USPTO.
4. USPTO equipment is maintained and operated by the USPTO
5. After the initial CAS meeting with the new contractor, the CAS TL, will contact the new contractor, COR and security to arrange for the completion of a signed MOU and Cyber Security checklist before the USPTO CAS site inspection.
6. Upon completion of the site network installation, the CAS TL, will notify the COR, Contractor Program Manager, and the OPG Cybersecurity Division that the site is ready for the USPTO Cybersecurity Physical Site Survey.
7. Once all site requirements are inspected and acceptable to USPTO Cyber Security, USPTO will provide approval for the Communication Service Provider’s line termination points DMARC (T1, T3, and fiber). The contractor will be responsible for extending the DMARC into the contractor’s network room.
8. USPTO provides all routers, switches, and UPSs necessary to provide a connection to USPTO.
9. USPTO will be responsible to provide the CEP software baseline requirements; latest patches, USPTO security GPOs, and monthly update patch notices to Program Managers for distribution to the responsible Local IT Administrators for action.
10. USPTO will be responsible to provide CEP/CEDP hardware and software patches through their SCCM system.
11. USPTO CSSD is responsible for requesting the initial security scan of the company CEP/CEDP systems.
12. USPTO will perform quarterly security scans and remediation on CEP/CEDP systems.
13. Service Desk – USPTO will provide limited contractor Service Desk support, e.g., domain problems, user accounts, resource access, and network support (USPTO extended subnets).
14. User Account Management – USPTO will create USPTO network user accounts and add contractor employees into USPTO’s Active Directory server.
15. Desktop Services – USPTO’s Desktop Services Division will work with the contractor’s POC to meet the specification requirements of USPTO’s A&A workstation hardware.
16. Client Software Services Division: Provide assistance with installing USPTO workstation baselines.
17. All USPTO Technical Leads will provide a list of any task-specific, USPTO required application software and coordinate with I/CSSD-Client Software Services Division, on software installation.
18. CAS will coordinate notification to the contractors regarding any changes to the USPTO CAS site requirements.
3.2.4 Workstations
Unless USPTO provides GFE to contractors, USPTO is not responsible for purchasing or licensing the contractor’s workstations. To be in compliance with the USPTO A&A, contracting companies must follow the following workstation platform guidelines.
The term “workstation” as used in this document refers to the computer hardware along with the software applications installed.
3.2.4.1 Hardware Connectivity Guidelines/Restrictions
The specific computer hardware specifications are govern by the CEP/CEDP definitions from the USPTO Desktop Services Division. Below are some guidelines, rules, restrictions, and recommendations for acceptable behavior and responsible use of USPTO connectivity privileges.
Laptop computers are very common in the CAS environment and special care needs to be observe due to their portability. In general, once a desktop/laptop has been approved CEP/CEDP compliant and for connectivity into the USPTO domain, it shall not be disconnected and then reconnected into another domain. This is view as a serious security breach.
Hardware Guidelines/Restrictions:
· All CEP/CEDP hardware and software must be approve by USPTO to be place under the USPTO A&A.
· USPTO recommends that the contractor use the same hardware make and model that USPTO has approved for use. Refer to 3.2.4.2 (Windows 10 CEP/CEDP Baseline Requirements)
· Lenovo and MAC computers are not permit on the USPTO network.
· Once a laptop has been approved CEP/CEDP compliant and connected to the USPTO network, it shall not be disconnected and then connected into any other network or domain such as the contractor’s corporate network.
· Once a laptop has been approved CEP/CEDP compliant and connected to the USPTO network, it should not be disconnected and reconnected into an unsecured, public Internet access, such as those found in the home, private use.
· The air-gapped requirement dictates a CEP/CEDP laptop is prohibit from connecting into the contractor’s corporate network; separate workstation machines must be maintain for the two different accesses.
· All computers connecting to the USPTO network MUST be both TAA and FIPS 140-2 compliant.
These regulations and restrictions also apply to desktop computers but emphasis is place on the laptop style machines due to their ease of portability.
3.2.4.2 USPTO – Contractor Enterprise Platform (CEP)
The contracting company CEP/CEDP workstation hardware/software must be approved by USPTO and allow the full USPTO security push (USPTO GPO), hardware and software security updates, and support a Windows 10, 64-bit Operating System.
All CEP/CEDP hardware and software must be approve by USPTO to be place under the USPTO A&A.
The following software has already been A&A approved for a basic, functional contractor workstation.
Minimum Contractors Software Requirement as of March 19, 2018:
· Windows 10, 64-bit (Follow the USPTO Windows 10 LSTSB 64-bit image foundation)
· Windows Media Feature Pack version 12 (1607)
· Internet Explorer Browser 11.0
· All Microsoft security and Adobe Critical\important patches up to current date.
· USPTO approved Google Chrome Enterprise version 64 or current deployed version.
· Oracle Java 8 Update 121 or current Enterprise release version
· Microsoft Office Professional Plus 2016 with Skype for Business with OneDrive for Business removed
· Symantec Endpoint Protection 12 RU6 MP6
· Symantec Management Agent (USPTO)
· Cisco AnyConnect (USPTO 4.4 approved version)
· Cisco WebEx Cloud (USPTO 5.0)
· Configuration Manager Client (SCCM Client) (USPTO)
· WinZip 20 Note: Mozilla Firefox is supported conditionally by USPTO.
Windows 10 CEP/CEDP Baseline Requirements: Contact I/CSSD-Client Software Services Division, or the COR to request the Windows 10 image preparation document to the Contracting companies. This document explains the Windows 10 build Hardware recommendation and Enterprise software for their Base images and requirement software and patches.
USPTO Recommended Optional Contractors Software:
· Putty (Latest) – File Transfers and server access
· WinSCP (Latest) – SSH, SCP, and SFTP File Transfers
· Microsoft Visio Professional 2016 (If appropriate) – Technical Drawings Tasks Required USPTO Software:
The sponsored USPTO TL or TOM needs to submit a request with the list of USPTO software to USPTO I/CSSD-Client Software Services Division team for approval and processing. The email request should contain the following:
· Contractor Company name
· Site POC and phone number
· Software, version
· USPTO TL name
· Department and phone number
· Justification
· System ID/User name requiring the installation USPTO Supplied Software for your CEP Software supplied by USPTO for implementation on your CEP
· Symantec Management Agent
· Cisco AnyConnect
· Configuration Manager Client (SCCM Client)
· Microsoft SSO 7.250.4556.0
· USPTO task required client software USPTO CEP/CEDP Patching Policy and Procedures The SCCM agent is the software application used within USPTO for software patch management for all workstations attached to USPTO.
USPTO will manage all CEP/CEDP systems through their SCCM patch management software once the CEP/CEDP systems have been approved by USPTO. Updates will include Windows Operating System, USPTO approve application software, and security patches.
The contractor company is required to build, patch and present their CEP/CEDP system (refer 3.2.4.2) for the initial security scan before USPTO accepts and approves the system.
All security patches must be current and completely installed prior to any CEP/CEDP system scan from cyber security. The Patches (critical\important only) can be install from the connection outside of USPTO, as the systems are not yet approved\authorized to be on USPTO.
When CEP/CEDP workstations are network attached to USPTO and cyber security certifies and approves the scan; the Local IT Site Admin can request for the SCCM agent installed, configured and start the SCCM patch management process.
To request the SCCM agent software, the Local IT Site Admin need to contact the CSSD (Client Software Services Division) SysAdmin team and Cc. I/CSSD-Client Software Services Division. Provide the system ID, MAC address and IP address of the systems.
Even after SCCM agent, software is install and configure; it is up to the Local IT Site Admin to verify that the CEP/CEDP system(s) all patches are current. The SCCM patch management is available for assistance of deploying the patches to the CEP/CEDP only, it is not the sole responsible to ensure systems are up to date on patches, it just and added tool to assist the Local IT Site Admin(s) USPTO Software (A&A) Software approved by the A&A for Window 10 can be review at http://ptoweb/ptointranet/cio/tef/index.htm. These are the sites listing USPTO approved software. However, for questions as to license responsibility, contact I/CSSD-Client Software Services Division.
Final CEP USPTO Approval before Configuration and Installation The Local IT Administrator is required to forward the completed CEP hardware and software lists to USPTO I/CSSD-Client Software Services Division team for approval before configuration and installation begins.
CEP software applications list must include the name, description, and version numbers.
3.2.4.3 USPTO - Contractor Enterprise Development Platform (CEDP)
The CEDP is a CEP workstation that also requires USPTO software development tools. These tools can be obtain by sending an email with the following information to I/CSSD-Client Software Services Division, before configuration and installation:
· Contracting company name
· Site POC name/phone number
· Software name/version
· Task Technical Lead name/phone number
· Department #
· Justification
· System ID
3.2.4.4 USPTO – Government Furnished…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .