Attachment 1 - PWS ESS Maint Corpus Christi.pdf

PDF 382 KB Posted

Attached to
ESS Maintenance Corpus Christi Federal contract opportunity
Solicitation number
SP330022Q5024
Issued by
Defense Logistics Agency Distribution

About this file

This performance work statement outlines requirements for electronic security system and electronic key control system maintenance services at the Defense Logistics Agency distribution site in Corpus Christi, Texas. The contractor shall provide preventative maintenance, corrective maintenance, operations support, and sustainment services for access control, intrusion detection, video surveillance, and key control systems. The contractor must have experience with the Lenel OnGuard and AMAG Symmetry systems installed at this location. The performance work statement specifies requirements for project management, operations and maintenance, network support, cybersecurity assurance, and service call response. The contractor must demonstrate compliance with Defense Department and National Institute of Standards and Technology cybersecurity policies and regulations. The contract term is for one base year with four optional one-year extensions.

View the file

Other files for this federal contract opportunity

Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement (PWS) ESS/EKC Maintenance Contract

DLA Distribution Corpus Christi, Texas (DDCT)

1.0 BACKGROUND

The Defense Logistics Agency (DLA) is a United States (U.S.) Department of Defense (DoD) agency providing worldwide logistics support to the missions of the Military Departments and the Combatant Commands.

In support of these missions, DLA Installation Management (DM) maintains a presence at each DLA locations for the life, health and safety systems including Electronic Security Systems (ESS) and Electronic Key System (EKC). In support of DM, DLA Information Operations Enterprise Capabilities Portfolio (J62B) DM serves as the functional proponent for all ESS requirements, policy and procedures.

ESS encompasses Intrusion Detection Systems (IDS), Access Control Systems (ACS), Closed Circuit Television (CCTV) systems, Electronic Key Systems (EKC), Federal Signal Mass Warning Notification Systems (MWNS) and other alert type systems for DLA facilities and personnel.

DLA Distribution Corpus Christi, Texas (DDCT) is a tenant at the Naval Air Station Corpus Christi, TX. The compound covers a combined area of approximately 20 acres and includes eight (8) warehouse buildings, one of which is the DDCT Main warehouse and administration building 1846 which contains the Security/Emergency Management office.

2.0 SCOPE

This Performance Work Statement (PWS) outlines requirements for the preventative maintenance, repair, operations and maintenance sustainment support for DLA Distribution Corpus Christi ESS for the Lenel and AMAG (Symmetry), CCTV system, AWID Card Readers, Aiphone system, Mechanical Gate System and Key Control System. These ESS systems include various subcomponents, such as card readers, intercom devices, security controllers, video recorders, security cameras, sensors, central monitoring equipment, duress alarms and key containers.

Specifically, for this effort the Contractor will provide the personnel, hardware, software/firmware and technical services for DLA Distribution Corpus Christi. At DLA Distribution Corpus Christi, the Contractor shall provide services for the Lenel, AMAG (Symmetry), CCTV system Aiphone System, HySecurity Mechanical Gate System and Matrix Key Control System (EKC). The Contractor shall provide maintenance support services, to include but not limited to daily operations support in support of achieving, at a minimum, of a 99.6% uptime and system availability metric, providing routine testing, inspection and maintenance of all physical hardware and mechanical items, providing Information Technology (IT) support including cybersecurity, accreditation documentation, upgrades, patches, migrations, enhancements and technology road map planning. The Contractor shall assist with developing information protection needs, defining system security requirements for Commercial Off The Shelf (COTS) of ESS solutions.

This PWS contains task requirements for Project Management, Operations, Sustainment and Maintenance, Network and Infrastructure, Cybersecurity and Service Call Requirements and Procedures support for a fully functioning site integrated system.

3.0 TASK REQUIREMENTS

The Contractor shall adhere to the following requirements and definitions for all Tasks within this PWS:

3.1 TASK 1 – PROJECT MANAGEMENT

The Contractor shall provide sufficient management to ensure that these tasks are performed efficiently, accurately, on time and in compliance with the requirements of this document. The Contractor shall support the following:

3.1.1 CONTRACT PROJECT MANAGER (CPM)

The Contractor shall provide a Contract Project Manager who shall be responsible for the performance of the work. The Contractor shall provide project management support for all items detailed in this PWS. This support includes providing planning, direction, coordination and control necessary for effective and efficient accomplishment of all requirements. The Contractor shall be the senior subject matter expert and monitor, control and report status, cost, schedule and performance; coordinate with Contracting Officer (KO), Contracting Officer Representative (COR), J6 Technical Point of Contact (TPOC), Project Management Office (PMO), users and other representatives. The Contractor shall attend meetings and provide other support as needed. The Contract Project Manager or alternate shall have full authority to act for the Contractor on all contract matters relating to the operations of this contract. The Contract Project Manager or alternate shall be available Monday through Friday, excluding Federal holidays, between the hours of 0600 and 1500 hours local time and within four hours after normal working hours (emergency repairs) upon request of the KO or COR as required to discuss problem areas.

3.1.2 WORK EFFORT

The Contractor shall manage the total work effort associated with the PWS herein to assure fully adequate and timely completion of all Tasks included in this function are a full range of management duties including, but not limited to, planning, developing and implementing project plans, scheduling, report preparation, communication and coordinating with stakeholders, incident management and escalation procedures, establishing and maintaining records, monitoring and reporting outages and quality control. The Contractor shall provide an adequate staff of personnel with the necessary management expertise to assure the performance of the work in accordance with sound and efficient management practices.

3.1.3 WORK CONTROL

The Contractor shall implement all necessary work control procedures to ensure timely accomplishment of work requirements, as well as to permit tracking of work in progress. The Contractor shall plan and schedule work to assure material, labor and equipment of all contracted items are available to complete work requirements within the specified time limits and in conformance with the quality standards established herein.

3.1.4 ENTERPRISE CONFIGURATION MANAGEMENT (ECM)

The Contractor shall adopt DLA ECM plans ensuring all hardware and software changes are approved by the COR in coordination with the J6 TPOC. The Contractor shall use the DLA IT Service Management Ticketing Systems (ITSM) currently ServiceNow, Change Implementation Plans (CIPs) and provide technical expertise in Enterprise Change Requests (ECRs) that addresses product management and version control for software (changes) and hardware.

The Contractor shall support business processes documentation such as Scheduled Maintenance Requests and Information Technology Operations Center (ITOC) notice (Infospot) and all other control items such as customer notifications. The Contractor shall evaluate all changes to the approved system requirements baseline for risk to security and for schedule and cost impact, provide evaluations in writing and with sufficient detail to allow for review and approval by the configuration governance structure as required. CIPs and ECRs are normally required 21 business days in advance of required change.

3.1.5 CONFIGURATION AUDIT

A configuration audit is an inventory of all existing hardware, software, drawings and technical documentation and is a function of configuration management. The Contractor shall perform an initial configuration audit, provide to the COR within ten (10) business days of contract start and updated in the Monthly Status Report (MSR).

3.1.6 WORK SCHEDULE

The Contractor shall schedule and arrange work to cause the least interference with the normal occurrence of Government business and mission. In those cases where some interference may be essentially unavoidable, the Contractor shall make every effort to minimize the impact of the interference, inconvenience, equipment downtime, interrupted service, customer discomfort, Non-scheduled visits will be coordinated with the COR at least five (5) working days in advance and notify the COR if the work being performed may cause interference. Notification shall include the type of work to be done and the estimated completion date. The Contractor shall reschedule any work that the KO/COR deems necessary to avoid unacceptable disruptions in the Government's business.

3.1.7 WORK RECORDS/REPORTS

The Contractor shall maintain management, maintenance, repair records and reports as set forth herein.

All final records and copies of reports shall be turned over to the COR ten (10) calendar days prior contract completion.

3.1.8 STAFFING

The Contractor shall continuously maintain an adequate staff with expertise to assure work is scheduled and completed in accordance with these specifications. The Contractor shall maintain a certified work force to complete work in accordance with the time and quality standards specified.

3.1.9 PROJECT SCHEDULE/PLAN

The Contractor shall create, maintain and submit project plans and schedules. Initial plans and schedules due within five (5) business days after award and shall be updated at least monthly, within the Monthly Status Report (MSR), until contract completion. The Government shall return unacceptable plans and schedules for re-work, then the Contractor shall update and re-submit project plans and schedules within five (5) business day of request. This includes any plans or scheduled required for upgrades, network or data migrations, installation or replacement of device(s) and or application(s).

(Microsoft Project is the preferred software). Project plans/schedules shall include Task ID, Task Name, Actual Start, Actual Finish, Baseline Start, Baseline Finish, % complete, resource name/title, with the critical path defined utilizing predecessors and/or successors.

3.1.10 MEETINGS

The Contractor shall coordinate a post award Kickoff meeting prior to the initiation of work and thereafter conduct monthly In Process Review (IPR) meetings. These meetings will be held with the Contractor, CPM, KO, Contract Specialist (KS), COR and the J6 TPOC to discuss an overview of Contractor’s plans to manage scope, schedule and resources. The Contractor will discuss stakeholders’ expectations, details of contract execution including incident management, triage support, technology road map plans including current and future software/hardware landscape general conditions, project schedule/plan, work schedules, coordination, security, safety, deliverables, permits and other matters pertinent to work accomplishments shall be discussed in this meeting. Contractor shall attend other meetings as required in support of contract tasks.

3.1.11 ON-BOARDING AND PHASE IN TRAINING

A phase-in period shall be established to allow the Contractor sufficient time to integrate personnel and transition into duties required to perform the requirements of the contract and ensure employees who will require access to the Installation and Government Information Technology (IT) systems obtain a Common Access Card (CAC) In Accordance With (IAW) this PWS. Instructions for all Phase In Training are available upon request.

1. The Contractor will submit to the COR all required on boarding documentation to obtain CAC, network access and administrative tokens no later than fifteen calendar days prior to contract full start date.

2. The phase-in period shall begin at the effective date of the contract and shall not exceed one (1) month, at which time full performance shall commence.

3. The Contractor shall ensure that all Contractor personnel are ready to begin working on the first day of full performance including obtaining any account access, permissions and/or roles required to administer the application software/hardware. Training and documentation such as rules of behavior and cyber awareness may be required for accesses.

4. During the phase-in period, Contractor personnel shall complete security and safety training on site. Training will be scheduled through the DLA Distribution site training office and will at a minimum include the following classes. Estimated in class time is three (3) hours.

a. Active Shooter Briefing

b. Safety Briefing

c. Shelter in Place/Evacuation Awareness Briefing

5. During the one month phased-in period to ensure all Contractor personnel know and understand regulations and policy pertaining to physical, information, operations and personnel security. The Contractor shall provide security and antiterrorism training to all employees in accordance with applicable DOD regulatory requirements. At a minimum, estimated in class time is eight (8) hours, security training requirements as required by the DLA Issuances and other applicable DOD guidance will be completed annually for the following on-line training. If the Contractor has previously taken this training valid copies of certification of completion training completion is allowed. The following training is normally required:

a. Cyber Awareness Challenge

b. Antiterrorism (AT) Level 1

c. Operations Security (OPSEC)

d. Counterintelligence Awareness Training

e. Personally, Identifiable Information Awareness

f. Trafficking in Persons

The security training is web-based and access will be provided by the Government. The Contractor shall ensure Contractor personnel have taken the required security training to meet DoD guidance and that the personnel continue to maintain their certifications.

3.1.12 TRANSITION SUPPORT

The Contractor shall provide knowledge transfer and training to any follow-on provider to include all the necessary documentation orientation, collaboration and training to facilitate the comprehensive understanding and execution of tasks, processes, procedures, schedules and deliverables in a timely and orderly fashion. All transition activities shall be coordinated with and approved by the COR. This task may start up to 90 days before the end of a base or option period.

The support services provided under this contract are critical to the DLA mission. It is vital that to ensure continuation of services without interruption or dramatic effort be provided. To maintain continuity of services the following requirements will be provided by the Contractor:

1. Continue to perform all services as prescribed within the PWS and existing Task Items without reduction of manpower, quality of services and interruption to customers.

2. Provide a transition plan to include risks and costs associated with the transition of Contractor support within fifteen business days of request for a transition plan from the COR. The transition plan shall address impacts including:

a. Provide current active project transition services associated with any break/fix, upgrade, migration and/or enhancements planned or in-process.

b. Assist secure required permission, roles, account accesses required for administration of software/hardware.

c. Provide landscape and asset documentation, data dictionaries or other system documentation for DLA equipment, hardware, software, processes and overall environment

d. Provide transition cost analysis, propose schedules and document risks associated with such transition.

3. The Contractor shall provide a written Transition Plan for the transition of services to perform all services required. The Transition Plan shall be provided withing fifteen days of the Governments request and shall describe all training requirements/personnel that will be provided by the Contractor to execute the transfer of knowledge as well as processes and schedule.

During the transition phase the Contractor shall provide weekly transition progress reports. The Contractor shall submit all written plans, updates and progress reports electronically to the KO, COR in coordination with the J6 TPOC.

3.2 TASK 2 – OPERATIONS, SUSTAINMENT AND MAINTENANCE

The Contractor shall provide operations, sustainment and maintenance support including mechanical Preventative Maintenance (PM), Corrective Maintenance (CM) and technical services support of software and hardware. Specifically, the Contractor shall provide the personnel, equipment, replacement spares, mechanical hardware, software/firmware including licensing required for fully operational ESS/EKC systems including, but not limited to, testing, inspection, maintenance, services, patching, upgrading, migrating and/or enhancing ESS/EKC systems.

Preventative Maintenance (PM) includes a recurring set of scheduled services and actions which the Contractor shall provide to keep systems fully operational and compliant.

Corrective Maintenance (CM) is the non-recurring unscheduled repairs or services required to make the systems fully operational.

Technical services support includes daily operations support, version upgrades, patching, security updates, enhancements, data migrations and/or network migrations required for ESS/EKC systems and subsystems. All required cyber updates and patches shall be done through Preventative Maintenance including Information Assurance Vulnerability Alert (IAVMs), Cyber Task Order (CTO), Assured Compliance Assessment Solution (ACAS) scan remediations or any other cyber requirements to include updating or creating any supporting cybersecurity documentation required for accreditation.

3.2.1 Operations

The Contractor shall support operations of systems including system monitoring, break/fix triage support, incident management, project management, configuration management and PM/CM.

3.2.2 Sustainment

The Contractor shall develop and implement a Sustainment Plan for all systems, subsystems and equipment IAW with original equipment manufacturer and/or Federal/DoD/DLA policies and procedures. The Sustainment Plan shall include the periodic maintenance, repair, replacement and overhaul of existing systems, hardware and software including planned version upgrades to supported versions of the application and Operating System (OS). The Contractor shall sustain software at latest version (N) minus one version (N-1) unless Cyber requires higher version. The Contractor shall provide the Sustainment Plan which includes the technology road map for N-1 support, the PM schedule and CM approach to the COR for approval within 30 days of contract award. The CM approach should include:

1. Positions, qualifications and certifications of personnel, test equipment and other pertinent information needed to quickly diagnose and make repairs.

2. Plans and documentation for systems testing and/or diagnoses.

3. Identify critical system operations, threats and implement strategies to prevent potential failures or administrative downtime from creating a critical system outage.

4. Analyze fault histories and fault trends to proactively predict and mitigate repetitive issues.

5. Plan to respond to and take corrective action to resolve cybersecurity vulnerabilities and mechanical emergency repairs identified by the Contractor or the Government both during normal hours and after hours.

The Contractor will work all version upgrades, patching, device enhancements, device replacements that reach end of life/support and for device replacements of hardware equipment that does not meet cyber standards/requirements including migrations required for ESS/EKC systems and subsystems compliance. As a software upgrade becomes available, the Contractor shall develop a plan for the upgrade and present that plan to the COR in coordination with the J6 TPOC for approval. Once approved the Contractor shall execute their plan to install the upgrade(s) and return the ESS/EKC system(s) to an operational state.

3.2.3 PREVENTATIVE MAINTENANCE (PM) AND QUARTERLY TESTING

The Contractor shall perform Preventive Maintenance (PM) services on all equipment which includes, but is not limited to, inspection, positioning (height, angle, racking), testing, cleaning, lubrication, adjustment and calibration to verify proper system operation. The Contractor shall minimize malfunction, breakdown and deterioration of systems and equipment following industry original Equipment Manufacturer (OEM) and Government best practices. The Contractor shall perform PM in accordance with agreed upon schedule (item 1 below). The Contractor shall submit and keep up to date a schedule for all PM tasks. Any modifications, changes, add-ons or deletions shall be submitted to the J6 TPOC for approval and once approved and implemented, documented in as-built drawings and provided to the site.

1. The Contractor will provide for approval an Annual Preventative Maintenance (PM) Schedule in Microsoft Project at Kickoff meeting and annually within five (5) days of exercised Option Year dates each calendar year and perform PM in accordance to approved schedule.

2. Any modifications, changes, add-ons or deletions shall be documented in as-built drawings and provided to the COR.

3. All replacement parts, materials, environmental compliance and Contractor personnel transportation used for PM shall be included in the contract unit price for PM services.

4. Battery voltage and charge levels will be checked during the quarterly testing. Any battery incapable of maintaining a 75% charge will be replaced within 8 business hours.

5. All quarterly testing shall be scheduled to be performed during normal working hours.

3.3 TASK 3 – NETWORK AND INFRASTRUCTURE SUPPORT

The Contractor shall plan and support a network and data migration for ESS/EKC which is anticipated during the base year of the period of performance. This includes re-IPing all ESS/EKC devices from the current network domain to a secure domain meant for Operational Technology (OT) applications and devices. The Contractor shall support the Government network and infrastructure requirements as needed. The Contractor shall support application-level items including:

3.3.1 APPLICATION SYSTEM AND NETWORK REQUIREMENTS

The Government provides system administration support for most Operating Systems (OS) at both the application server, the database server and the client workstations. The Contractor shall receive a network assignment and provide the Government system administration support as required.

The Contractor shall support the following system and network requirements including, but not limited to:

1. All system/network components and applications shall be compatible with all applicable Defense Information System Agency (DISA) Security Technical Implementation Guides (STIGs). Any STIG exceptions must be identified as part of the Contractor’s proposal to the Government and approved by J6 Cybersecurity. Exceptions incurring risk found unacceptable to the DLA Authorizing Official are not permitted.

2. All network components and applications shall be IPv4 and IPv6 compatible.

3. Network components shall allow configuration of IEEE 802.1x or port security for authentication.

4. The Contractor shall provide a complete list of all ports, protocols and services required for any computer system running control system applications or required to interface the control system applications. The listing shall include all ports and services required for normal operation as well as any other ports and services required for emergency operation. The listing shall also include an explanation or cross reference to justify why each service is necessary for operation. When standard Ports, Protocols and Services (PPS) are not utilized for any computer system running control system applications or required to interface the control system applications, then the Contractor shall provide a written justification for deviation from standard PPS.

5. Wireless communications are normally not permitted. The Contractor shall identify any system wireless communication capability, enabled or disabled. If any wireless communications are approved, then they shall meet applicable STIG requirements to include Federal Information Processing Standard (FIPS) 140-2 certification.

6. All wiring and/or cabling shall be in Electric Metal Tubing (EMT) type conduit.

7. The Contractor shall provide any patch cabling required.

8. All application network components shall be connected using copper 100/1000 or fiber optic

Small Form Factor Pluggable (SFP)-based Gigabit Ethernet ports.

9. Hardware and controller systems must be capable of operating on separate Virtual Local Area

Network (VLAN)s if required.

10. The Contractor shall provide a Bill of Materials (BOM) and other network documentation to the

COR in coordination with the J6 TPOC in support of these requirements.

3.3.2 INFORMATION AND OPERATIONAL TECHNOLOGY INFRASTRUCTURE

REQUIREMENTS

DLA expects to furnish the IT Infrastructure to host ESS system(s) (including VLANs and Virtual Machines [VMs]) unless there is a hardware, compatibility or mission issue preventing it. As such, the Contractor must clearly identify “what” anticipated Government IT Infrastructure is required to host and operate the ESS system(s) within the design documentation submitted for Government approval at time of award. These anticipated designs will be incorporated into the system CONOPs. The Contractor will be responsible for all installation, configuration and deployment of the ESS and/or system(s), including but not limited to, system subsystem(s), application(s) and patch cabling, as required.

Any requirement for the Contractor to provide their own IT Infrastructure, standalone server or management workstation hardware due to compatibility issues must be documented in the Contractor’s proposal and approved by the COR in coordination with the J6 TPOC prior to purchase or implementation. All Contractor provided IT Infrastructure must meet DoD STIG requirements. If the Contractor provides their own IT Infrastructure for the ESS and/or system(s), upon Authorizing Official (AO) approval of the security authorization package (and prior to final ESS and/or system(s) acceptance or go-live), all Contractor provided IT Infrastructure will become the property of the Government.

All specialized software provided by the Contractor to the Government must have the applicable license key(s) as well as sales/transaction records, ownership control(s), manuals, technical publications, documentation and any other information supporting ownership accompanying it. At the time of Contractor hand-off of Contractor owned IT Infrastructure to the Government, all design information for the “as built” ESS and/or system(s) will be provided. Any Contractor provided operating system (OS), software and firmware throughout the duration of the contract will be upgraded by the Contractor prior to the Contractor’s end of mainstream support for the OS, software or firmware.

DLA’s preference is for maximized virtual IT infrastructure. As such, the Government will provide the virtual infrastructure to support deployment of Contractor supplied virtual servers or virtual appliance (OVA files). DLA will provide a virtual server with the specifications listed below. The Contractor shall note any exceptions to these specifications in their proposal:

1. CPU: 4 Cores

2. RAM: 12 GB

3. Disk 1 (OS Drive): 150 GB

4. Disk 2 (Data Drive): 150 GB

Any requirements exceeding these specifications shall be submitted in writing and approved by the DLA COR in coordination with the J6 TPOC with supporting documentation prior to contract award. The Contractor will be responsible for the implementation including meeting all required STIG compliance.

The Contractor shall be responsible for all configuration and deployment which meet DoD, NIST and USG regulatory and cybersecurity policy requirements.

Contractor supplied systems must meet DoD STIG requirements, with any exceptions noted in the design documentation.

The Contractor shall be responsible for all software maintenance activities for any/all appliances including but not limited to, firmware updates, OS patching, software patches etc. for the duration of the contract period.

The Contractor will be responsible for all physical maintenance activities for any/all appliances including but not limited to, replacement of defective components such as hard drives (to be destroyed onsite per DoD policy, guidance), motherboards, daughter cards etc. for the duration of the contract period.

System(s) shall operate using a fully supported OS, software and firmware throughout the duration of the contract. All OS, software and firmware shall be upgraded prior to the Contractor’s end of mainstream support for the operating system, software or firmware. The solution must be upgradeable and remain compliant to DoD cybersecurity specifications during the lifecycle of the solution.

Any removable flash media required for system operation must be reviewed and approved by COR in coordination with the J6 TPOC and the DLA J6 Flash Media Approval Program prior to implementation.

All ESS and/or system(s) must use the Purdue Enterprise Reference Architecture (PERA) Model for Control Hierarchy (reference International Standard Book Number ((ISBN) 1-55617-265-6) to provide logical and/or physical architecture for networking, security hardware, software and methods. The PERA Model is an industry standard for manufacturing and/or industrial control systems that segments hardware, devices and equipment into a hierarchical based design.

The Contractor shall support the following application infrastructure requirements to include, but not limited to:

1. DLA shall furnish all application and database servers and laptop/workstation hardware as required. Any requirement for the Contractor to provide their own server or laptop/workstation hardware due to compatibility issues shall be documented in the proposal and approved by the COR in coordination with the J6 TPOC and the DLA Information System Security Manager (ISSM) prior to any procurements and/or network installations. Contractor supplied systems must meet DoD STIG requirements, with any exceptions noted in their proposal.

2. The application software shall be capable of operating on DLA’s approved operating systems, virtual environments and databases listed below:

3. Workstations/laptops shall operate on Windows 10 64-bit OS, x64-based processor or higher OS, with minimum system requirements of: processor: Intel i5 -8350u @ 1.7GHz, 1.9GHz, 2 Cores, RAM: 8GB, Hard Drive: 256 GB.

a. Windows Server 2016 Operating System (OS) (or higher versions).

b. For virtualized appliances or virtualized servers, the system shall be capable of running on VMware ESXi hosts v6.0 or VMware vSphere v6.0 virtual server environment (or higher versions).

c. Database shall operate using SQL Server 2016 or Oracle Database v19c (12.2.0.3) (or higher versions).

d. System must be capable of operating with McAfee ePolicy Orchestrator enabled.

4. Any removable flash media required for system operation must be reviewed and accepted by the DLA Flash Media Approval Program in advance. Coordination for approval shall be processed through the COR in coordination with the J6 TPOC and the ISSM.

5. Application video appliance(s) and network recording requirements:

a. In some instances (such as video surveillance) where there is a requirement for a large amount of storage, the preferred solution will be available as an appliance that includes computer/storage in one physical appliance that meets DoD, National Institute of Standards and Technology (NIST) regulatory and cybersecurity policy requirements.

b. The appliance will not be used as a combined server and shall be sized adequately to store video feed data for up to 30 calendar days.

c. All videos will be stored under DLA doctrinal requirements.

6. The Contractor shall be responsible for configuration and deployment.

7. The Contractor shall be responsible for all software maintenance activities for the appliance including, but not limited to, firmware updates, OS patching support, software patches, security updates and other enhancements throughout the duration of the contract.

8. The Contractor will be responsible for all physical maintenance activities for the appliance including, but not limited to, replacement of defective components such as hard drives (to be destroyed onsite), motherboards, daughter cards and other related system components for the duration of the contract period.

3.4 TASK 4 - CYBERSECURITY REQUIREMENTS

The Contractor shall provide the following cybersecurity support including, but not limited to the following:

1. The Contractor shall provide cybersecurity (CS) that is in accordance with current policies, procedures and statutes, to include, but not limited to, the following or most current version:

a. 44 U.S.C. § 3542, January 2012

b. Committee on National Security Systems Instruction 1253, Security Categorization and

Control Selection for National Security Systems, March 15, 2012, as amended

c. Federal Information Processing Standards Publication 199, Standards for Security

Categorization of Federal Information and Information Systems, February 2004

d. Federal Information Processing Standards Publication 200, Minimum Security

Requirements for Federal Information and Information Systems, March 2006

e. Federal Information Security Management Act (P.L. 107-347, Title III), December 2002

f. Department of Defense Instruction 5000.02, Operation of the Defense Acquisition

System, January 7, 2015

g. Department of Defense Instruction 5200.39, Critical Program Information (CPI)

Identification and Protection within the Research, Development, Test and Evaluation

(RDT&E)

h. Department of Defense Instruction 5200.44, Protection of Mission Critical Functions to Achieve Trusted Systems & Networks, July 27, 2017

i. Department of Defense Directive 8140.01, Cyberspace Workforce Management, August 11, 2015

j. Department of Defense Instruction 8330.01, Interoperability of Information Technology (IT), Including National Security Systems (NSS), May 21, 2014

k. Department of Defense Instruction 8500.01, Cybersecurity, dated 14 March 14

l. Department of Defense Instruction 8510.01, Risk Management Framework (RMF) for

DoD Information Technology, dated 12 Mar 14

m. Department of Defense DoD 8570.01-M, Information Assurance Workforce

Improvement Program, Change 3 dated 24 Jan 2012

n. Department of Defense Instruction 8580.1, Information Assurance (IA) in the Defense

Acquisition System, July 9, 2004

o. DoD Program Manager’s Guidebook for Integrating the Cybersecurity Risk Management

Framework (RMF) into the System Acquisition Lifecycle

p. Defense Acquisition Guidebook (DAG)

q. Deputy Under Secretary of Defense (Installations and Environment) Memo dated 19 Mar

14, subject: Real Property Related ICS Cybersecurity

r. Defense Information Systems Agency (DISA) Secure Technical Implementation Guides

(STIGs)

s. National Institute of Standards and Technology Special Publication 800-30, Guide for

Conducting Risk Assessments, September 2012

t. National Institute of Standards and Technology Special Publication 800-37, Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach, February 2010

u. National Institute of Standards and Technology Special Publication 800-39, Managing Information Security Risk: Organization, Mission and Information System View, March

v. National Institute of Standards and Technology Special Publication 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, April

w. National Institute of Standards and Technology Special Publication 800-82 Revision 2, Guide to Industrial Control Systems (ICS) Security, February 2015

x. National Institute of Standards and Technology Special Publication (SP) 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations, January 2021

y. UFGS-25 50 00.00 20 Cybersecurity of Facility-Related Control Systems

z. United Facilities Criteria (UFC) 4-010-06, Cybersecurity of Facilities-Related Control

Systems

aa. Defense Logistics Agency Risk Management Framework Standard Operating Procedures, April 2021

bb. Office of the Assistant Secretary of Defense Facility Related Control Systems (FRCS)

Master List Memo, October 2020

cc. Defense Logistics Agency Approved Cybersecurity Computing Environment List, October 2021

dd. Department of Defense Control Systems Security Requirements Guide Version 1, Release 1, July 14, 2021

2. The Contractor shall not permit user credentials to be transmitted in clear text. Encryption shall at a minimum meet Advanced Encryption Standard (AES) 256 and comply with Federal Information Processing Standard (FIPS) 140-2. If this is not technically feasible, the Contractor shall provide the COR in coordination with the J6 TPOC and the ISSM a recommendation for the strongest encryption method commensurate with the technology platform and response time constraints and document the encryption used in a Plan of Actions and Milestones (POAM).

3. The Contractor shall identify heartbeat signals or protocols and recommend whether any should be included in application network monitoring. The Contractor shall provide packet definitions of the heartbeat signals and examples of the heartbeat traffic if the signals are included in the application network monitoring.

4. The Contractor shall recommend which accounts need to be active and those that can be disabled, removed or modified. The COR in coordination with the J6 TPOC shall approve in writing the Contractor’s recommendation. The Contractor shall disable, remove or modify all the accounts pursuant to the approved recommendation. The Contractor shall disable or remove all default and guest accounts. Once changed, new accounts will not be published except that new account information and passwords will be provided by the Contractor via protected media. At delivery, the Contractor shall disable, remove or modify all Contractor-owned accounts or negotiate account ownership with the COR. Contractor updates shall not re-enable or re-install any of these accounts.

5. The Contractor shall manage sessions and not allow multiple concurrent logins, applications to retain login information between sessions, provide any auto-fill functionality during login or allow anonymous logins. The Contractor shall provide user account-based logout and timeout settings.

6. The Contractor shall implement two-factor authentication using DoD Common Access Card where technically feasible, with exceptions noted in the proposal for approval by the COR in coordination with the J6 TPOC and the ISSM. The Contractor shall provide a configurable account password management system that allows for selection of password length, frequency of change, setting of required password complexity, number of login attempts, inactive session logout, screen lock by application and denial of repeated or recycled use of the same password.

The Contractor shall not store passwords electronically or in Contractor-supplied hardcopy documentation in clear text unless the media is physically protected.

7. The Contractor shall provide physical and cyber security features for end devices (i.e., the source or destination of network traffic) including, but not limited to, authentication, encryption, access control, event and communication logging, monitoring and alarming to protect the device and configuration computer from unauthorized modification or use. The Contractor shall clearly identify the physical and cybersecurity features and provide the methodology for maintaining the features including the methods to change settings from the Contractor-configured or manufacturer default conditions. The Contractor shall verify that the addition of security features does not adversely affect connectivity, latency, bandwidth, response time and throughput. The Contractor shall remove or disable all software components that are not required for the operation and maintenance of the device prior to delivery. The Contractor shall provide documentation on what is removed and/or disabled.

The Contractor shall provide appropriate supported software, service updates, security updates and/or implement workarounds to mitigate all vulnerabilities associated with the product to maintain the established level of system security.

8. The Contractor shall utilize standard ports, protocols and services listed in the DISA Common Access List (CAL) to the greatest extent possible. When standard PPS are not used, then the Contractor shall provide a justification statement in Ports, Protocols and Services Management (PPSM) submissions for J6 TPOC in coordination with the ISSM approval.

9. The Contractor shall provide a detailed plan for physical security mechanisms appropriate for the type of devices being installed (enclosures, etc.).

10. The Contractor shall provide the following accreditation artifacts:

1. System Diagrams:

a. Architecture Network Diagram

b. Authorization Boundary Diagram

c. Data Flow Diagram

d. Purdue Diagram

2. Comprehensive Hardware/Software List (DLA provided template)

3. Concept of Operations (CONOPS)

4. Plan of Actions and Milestones (POAM)

5. Ports, Protocols and Services Management (PPSM) Documentation for Registration

6. Security Technical Implementation Guides (STIGs) and Security Requirement Guides

(SRGs) Mitigations

7. Federal Information Processing Standard 199 (FIPS-199) Cybersecurity Strength

Requirements

8. Personal Identifiable Information (PII) Confidentiality Impact Level (PCIL)

Categorization Worksheet

3.4.1 CYBERSECURITY STRENGTH REQUIREMENTS

The Contractor shall provide the following cybersecurity strength requirements including, but not limited to the following:

1. The Contractor shall adhere to all existing authorities and policies of the Director of National Intelligence regarding the protection of sensitive compartmented information (SCI), as directed by Executive Order 12333 and other laws and regulations.

2. The Contractor shall satisfy the Risk Management Framework (RMF) requirements of subchapter III of chapter 35 of Title 44, United States Code (U.S.C.), also known as the “Federal Information Security Management Act (FISMA) of 2002”.

3. The Contractor shall enable DLA to meet the standards required by the Office of Management and Budget (OMB) and the Secretary of Commerce, pursuant to FISMA and section 11331 of Title 40, U.S.C.

4. FIPS 199 / CNSSI 1253 Security Categorization: The Contractor shall participate in categorization discussions with the DLA J6 PM, functional lead, J6 TPOC and the DLA Information System Security Manager (ISSM) and provide all required FIPS 199 documentation as requested to support security categorization.

5. The Contractor shall provide a recommendation on system categorization based on sound technical expertise in accordance with FIPS 199 then work in coordination with the prescribed DLA System Owner (SO), J6 TPOC and ISSM to support the categorization IAW FIPS 199, CNSSI 1253 and OSD Facility Related Control Systems (FRCS) Master List including DLA specific systems, then document the results of the security categorization in the System DLA FIPS 199 document and the Concept of Operations (CONOPs).

6. DLA J6 PM will coordinate with the Contractor to identify and document Confidentiality, Integrity and Availability (CIA) of the system in a DLA FIPS 199 document for approval by the J6 TPOC in coordination with the ISSM personnel.

7. The Contractor shall in coordination with the prescribed System Owner (SO) and Authorizing Official (AO) support categorization IAW FIPS 199, FIPS 200, FIPS 201 and National Security Systems Instruction (CNSSI) 1253 of the Cyber Security (CS) and document the results of the security categorization in the security plan.

8. The Contractor shall ensure that a written subsection of the security plan covers FIPS 199 / FIPS 200 / FIPS 201 Committee on National Security Systems Instruction CNSSI 1253 Security Categorization and Threat Assessment. DLA and or the SO will provide a C-I-A concurrence memorandum from SO respective AO agreeing with their determination of controls (Confidentiality, Integrity and Availability with any overlays and tailoring).

3.4.2 COMPLETION OF SYSTEM HARDENING (SCAN/FIX/SCAN) TESTING AND

ANALYSIS

The Contractor shall harden systems using a scan, fix, scan methodology remediating findings IAW current DOD, DLA and Defense Information Systems Agency (DISA) standards. This includes automated and manual STIG application, Assured Compliance Assessment Solution (ACAS) scanning and any other hardening efforts required to make the system ready to connect to a DOD network.

Whenever findings occur, as required periodically and/or following any major system change, the Contractor shall scan/fix/scan until all issues have been fixed and/or properly and acceptably mitigated.

Any Critical or High impact level findings that cannot be fixed are to be reported to the J6 TPOC in coordination with the ISSM immediately along with a valid reason the vulnerability cannot be fixed and a POAM. Once the Contractor has completed hardening efforts, system monitoring and audits shall occur to ensure STIG compliance is maintained.

Upon connection to the production network, the Contractor is expected to maintain the current approved settings. The Contractor is expected to notify the J6 TPOC in coordination with the ISSM of any known published system patches and OS updates that will negatively impact the cybersecurity posture of the system. Any identified issues should be documented in advance to the J6 TPOC in coordination with the ISSM with a valid reason the system patch or OS update cannot be applied and a mitigation plan to fix the pending vulnerability with the date to be fixed.

3.4.3 CYBERSECURITY ASSURANCE REQUIREMENTS

The Contractor shall design, develop and integrate cybersecurity solutions supporting the Department of Defense and all other applicable Government agencies which reduce threats and attack vectors.

This will be achieved through abiding by all applicable cybersecurity policies, regulations and directives to ensure a favorable Assessment and Authorization (A&A), Assessment and Incorporate (A&I) or FRCS Assess Only Risk Assessment (FRCS AORA) decision, as well as obtaining an Authority to Connect (ATC) to DLA’s network. The Contractor shall mitigate risk identified through the RMF authorization process down to a level acceptable to the DLA Authorizing Official (AO).

Coding for Security. The Contractor shall provide documentation of development practices and standards applied to Government approved Contractor-written control system software, including firmware, used to ensure a high level of defense against unauthorized access.

The solution shall comply with the security control requirements documented in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53r4, “Security and Privacy Controls for Federal Information Systems and Organizations” and NIST 800-82r2, “Guide to Industrial Control Systems (ICS) Security”. The Contractor shall provide details of any alternative but equally effective security measures used to compensate for the inability to satisfy a particular derived security requirement (mitigation to control compliance findings). This information shall be submitted in writing to the DLA J6 PM for cybersecurity approval as soon as the alternative is identified. Guidance on the applicability and enforcement of controls by Purdue Enterprise Reference Architecture (PERA) level can be found in the United Facilities Criteria (UFC) 4-010-06, Cybersecurity of Facilities-Related Control Systems.

The DoD Control Systems Security Requirements Guide (SRG) shall be used as appropriate for the system.

The Contractor shall protect unclassified DoD data from unauthorized access or disclosure in accordance with DoDI 8582.01, “Security of Unclassified Information on Non-DoD Information Systems.” Controlled Unclassified Information: All Government controlled unclassified information obtained by the Contractor shall be protected in accordance with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations”.

Agencies or Military Services providing external information system services must comply with DLA information security requirements and employ overlayed security controls in accordance with applicable federal laws, Executive Orders, directives, instructions, policies, regulations, standards and guidance.

3.5 TASK 5 – SERVICE CALL REQUIREMENT AND PROCEDURES

Service calls are defined as maintenance and repair work requirements which are identified by building occupants or generated by the COR or On-Site Representative. All tickets will be input, updated and tracked within the DLA ticketing system currently ITSM ServiceNow by the Contractor.

3.5.1 SERVICE CALL REQUEST

The Contractor shall perform service call work as required to determine the cause of system and equipment malfunctions, eliminate the cause(s) and restore the system or equipment to satisfactory working condition including:

1. The COR will advise the Contractor by phone or email of all service call requests received during and after regular working hours. A description of the problem or requested work, date and time received, location, classification and other appropriate information will be placed on a ticket within the DLA ticketing system by the Contractor.

2. The Contractor shall have procedures for receiving and responding to service calls 24 hours per day, seven (7) days a week, including weekends and holidays. A single local or toll-free telephone number shall be provided by the Contractor for receipt of all service calls. All telephone calls shall be answered within 30 minutes by an individual fully familiar with the Contractor’s work control procedures and the terms and conditions of this contract. Service calls shall be considered received by the Contractor at the time and date the telephone call is placed or email is sent by the COR. The Contractor shall respond immediately and must be on the job site and working within four (4) hours after receipt of a service call. The Contractor shall work continuously without interruption and shall resolve the issued before departing the job site unless they have written permission to continue the issue on the next business day from the COR or On Site Representative.

3. All service call tickets…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .