Attachment 1-PWS-ESS Maint Svcs-DDPW.pdf

PDF 340 KB Posted

Attached to
ESS Puget Sound Federal contract opportunity
Solicitation number
SP3300-21-Q-5024
Issued by
Defense Logistics Agency Distribution

View the file

Other files for this federal contract opportunity

Other files attached to ESS Puget Sound, newest first.
File Type Posted
SF30 Amendment 0002.pdf PDF
SF30 Amendment 0002 Questions.pdf PDF
Schedule of Supplies.pdf PDF
SF30 Page 2 Questions.pdf PDF
SF30 Amendment 0001.pdf PDF
Attachment 2 -Equipment List_Redacted-ESS Mntc Svcs-DDPW.pdf PDF
Tab 10 Combined Synopsis.pdf PDF
Attachment 3 - MntcTaskLists-ESS Mntc Svcs-DDPW_.pdf PDF
Attachment 4 - Wage Determination.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

COMPLETE MAINTENANCE SUPPORT SERVICES FOR

LENEL ELECTRONIC SECURITY SYSTEM (ESS), CLOSED CIRCUIT TV SYSTEMS

(CCTV), MASS NOTIFICATION SYSTEMS (MNS), AND MORSE WATCHMAN KEYPRO

SYSTEM

AT DEFENSE LOGISTICS AGENCY (DLA) DISTRIBUTION

PUGET SOUND, WA (DDPW)

SECTION 1 INTRODUCTION

1.0.1 Background. The Defense Logistics Agency (DLA) is a United States (U.S.) Department of Defense (DoD) agency that provides worldwide logistics support for the missions of the Military Departments and the United combatant Commands under conditions of peace and war.

Physical security measures are necessary at all DLA Distribution sites to protect personnel, real and personal property, resources, and information. DLA Distribution Puget Sound WA (DDPW)

– Bremerton WA is a tenant activity on the Naval Base Kitsap-Bremerton WA.

1.0.2 DDPW has a requirement for a Contractor to provide maintenance and repair services (including in kind upgrades) on the site Lenel Electronic Security System (ESS), Closed Circuit Television Systems (CCTV), Mass Notification Systems (MNS), and Morse Watchman Keypro System.

SECTION 2 GENERAL CONDITIONS AND REQUIREMENTS

2.0.1 This Section provides general information relating to the conditions of operation and general requirements relating to the upgrade, maintenance, and repair services for the Lenel ESS, CCTV systems, MNS, and Morse Watchman Keypro System at DDPW.

2.0.2 The software and hardware maintenance service shall include two types of maintenance services: Preventive Maintenance (PM) (scheduled) and On-Call or Corrective Maintenance (CM) (unscheduled.) The DDPW Equipment List is provided to identify each piece of equipment and software that requires maintenance services and the PM schedule requirements. The DDPW Equipment List is subject to change by the Government when equipment addition(s) and/or deletion(s) are required due to the needs of the site.

2.0.3 With the ongoing effort of building consolidation and expansion, the Government reserves the right at its discretion to add to or delete equipment from the ESS upgrade, maintenance, repair, and support services contract anytime during the performance periods of the contract as needs arise without explanation, with proper notification.

2.0.4 This is a non-personal services contract to provide system upgrade, maintenance, repair, and support services for the ESS, CCTV, MNS, and Morse Watchman Keypro systems at

DDPW. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government. The Government and the Contractor understand that the services to be provided under this contract by the Contractor are non-personal services and that no employer-employee relationship exists between the Government and the Contractor. The Government may provide technical direction which will assist the Contractor in accomplishing the PWS; however, the Government will not control the methods used by the Contractor to perform the service requirements set forth in the PWS.

2.0.5 The Contractor shall furnish all labor, supervision, tools, materials, equipment, transportation, and management necessary to perform a system upgrade, provide preventive maintenance services, service calls (as needed), and all repair and or replacement of parts necessary to keep all portions of the ESS, CCTV, MNS, and Morse Watchman Keypro systems covered by this requirement in perfect operating condition during the contract period.

2.0.6 The contractor shall perform a system upgrade of any ESS system running an operating system older than Windows 10 or Windows Server 2008R2. This upgrade is to be considered a priority and shall be accomplished before extended support is terminated.

2.0.7 The Contractor shall be responsible for ensuring that all ESS, MNS, and Key Control systems are and remain in compliance with all DoD, DLA and DISA cybersecurity guidance throughout the POP. The contractor must provide and maintain all current required cybersecurity artifacts and deliverables, including but not limited to: data flow diagrams, network diagrams, ports, protocols, and services management (PPSM), current and annual Security Technical Implementation Guides (STIG) maintenance, Federal Information Processing Standards (FIPS) 199 assessment, System Concept of Operations (CONOPS), hardware and software lists, Assured Compliance Assessment Solution (ACAS) Scan remediations, Systems Security Plan (SSP), any immediate patch management as identified by vulnerability management, and any other requested documentation.

2.1 GENERAL OPERATING CONDITIONS

This Section provides general information relating to the conditions of operation and general requirements relating to the maintenance and repair of the ESS, CCTV, MNS, and Morse Watchman Keypro systems at DLA Distribution Puget Sound WA (DDPW) – Bremerton WA.

2.2 PLACE OF PERFORMANCE

2.2.1 Work will be performed at DDPW- Bremerton WA site.

2.2.2 The ESS, CCTV, MNS, and Morse Watchman Keypro systems, to include all components, are located within the DDPW facilities which are currently in 4 buildings on the installation. DDPW Equipment List provides the location of all equipment that supports ESS, CCTV, MNS, and Morse Watchman Keypro systems.

2.2.3 Connectivity between buildings consists of underground communication lines/fiber.

2.3 PERIOD OF PERFORMANCE

The period of performance for this contract will be for a one (1) year base performance period with two (2) one- year optional performance periods.

2.4 CORE DUTY HOURS AND INSTALLATION ACCESS

2.4.1 Core Duty Hours The Contractor shall perform services required under this PWS during the operating hours of the Government activity. The core hours for on-site maintenance activities are from 0630 to 1500 HRS (3:00 PM) PST (local time) Monday through Friday, local time, except Federal holidays. The Contracting Officer’s Representative (COR) will provide the Contractor a 48-hour notice for any alternative working hours changes different from core hours.

Maintenance and repairs will be performed during these hours.

2.4.2 Due to changing traffic requirements brought on by construction, changing missions, and security concerns within the installation, access to the installation is subject to change, sometimes with little or no warning. Inbound and outbound traffic restrictions may exist.

2.4.3 The Contractor or any representative of the Contractor entering DoD locations to perform contract requirements shall abide by all security regulations and may be subject to security checks. Contractor personnel and property shall be subject to inspection upon entering, while on, and upon leaving the DoD locations pursuant to installation regulations.

2.4.4 Installation Access The Contractor shall have each employee who is performing contract work complete and submit a Form DDPW 5512-2 (See Attachment) to receive a Cardkey for installation access prior to full contract performance. Site access credentials shall be issued prior to any Contractor employee performing any contract work.

2.4.5 Any new Contractor requesting base access will also be required to obtain a Defense Biometric Identification System (DBIDS) identification and access credential. The Contractor shall go to https://bavr.cnic.navy.mil/ and submit requested information for each employee working this contract. The COR will supply any necessary DLA form information.

2.5 FEDERAL HOLIDAYS

2.5.1 Federal holidays generally observed by government personnel include:

Observed Federal Holidays New Year’s Day Martin Luther King Day Presidents Day Memorial Day Independence Day Labor Day Columbus Day Veterans Day Thanksgiving Day Christmas Day

2.5.2 If the holiday falls on a Saturday, it will be observed on the preceding Friday. If the holiday falls on a Sunday, it will be observed on the following Monday. The Contractor shall not be required to perform services on these days.

2.5.3 In the event an Executive Order issued by the President of the United States declares Agencies of the Federal Government closed on a Contractor-scheduled service date, the COR will advise the Contractor on whether services should be performed for that day or services should be rescheduled.

2.6 TERMS AND ACRONYMS: DoD DICTIONARY

The DoD Dictionary of definitions and terms is available on the Internet at:

http://www.jcs.mil/Doctrine/dod_dictionary/.

2.7 RESOURCE REQUIREMENTS

2.7.1 AUTHORIZED PERSONNEL

2.7.1.1 GOVERNMENT PERSONNEL

a. Contracting Officer Representative (COR) - A DLA employee shall be appointed to serve as COR. Contact information will be provided to the Contractor upon contract award.

b. Technical Point of Contact (TPOC) - A DLA employee shall be appointed to serve as TPOC and primary contact for all physical and J6 cyber security related requirements of the contract. Contact information will be provided to the Contractor upon contract award.

c. J6 Contracting Officer’s Technical Representative (J6 COTR) - A J6 (IT) DLA employee shall be appointed to serve as J6 COTR and primary contact for all J6 cyber security-related requirements of the contract. Contact information will be provided to the Contractor upon contract award.

d. Changes to authorized personnel will be provided to the Contractor via a modification issued by the Contracting Officer (KO).

2.7.1.2 CONTRACTOR PERSONNEL

a. Contract Manager - The Contractor shall designate a Contract Manager who will have full authority to act for the Contractor on all matters relating to Contractor performance under this contract. The name of this person and an alternate person who shall act for the Contractor when the manager is unavailable shall be designated and submitted in writing to the KO or COR. The Contractor shall provide telephone numbers of the Contract Manager and alternate(s) who shall be available by telephone during regular working hours and shall be available within four (4) hours before and after normal working hours at the request of the KO or COR. This availability pertains to emergency repairs.

b. The Contract Manager or alternate shall be available Monday through Friday, excluding federal holidays, during regular working hours to meet on the installation as required by the COR. The Contract Manager shall be available while work is being performed for the duration of the contract. The Contract Manager has the authority to resolve problems, allocate resources, manage personnel, and monitor operation performance taking direction from the Government to ensure complete satisfaction. In the performance of these duties, the Contractor shall possess the basic knowledge and skills required to plan, control, manage, and be responsible for the successful completion of the work and shall be qualified to be the Contractor’s on-site supervisor and POC for Government representatives.

2.7.2 GOVERNMENT-FURNISHED FACILITIES AND SUPPORT SERVICES

2.7.2.1 WORK AREA

The Government will make available during performance of this contract inside workspaces close to equipment location. The Contractor shall be responsible for the orderliness and cleanliness of all areas utilized in the performance of this contract. These areas will be neat and clean, free from fire and safety hazards and unsanitary conditions.

2.7.2.2 UTILITIES

2.7.2.2.1 The Government will make available at no cost to the Contractor water and electricity for Contractor connection at Government provided work areas. The Contractor shall instruct employees in utilities conservation practices. The Contractor shall be responsible for operating under conditions which preclude the waste of utilities and shall include the following:

2.7.2.2.2 Lights shall be used only in areas where and when work is being performed.

2.7.2.2.3 Mechanical equipment controls for heating, ventilation, and air conditioning systems shall not be adjusted by the Contractor or by Contractor personnel in any Government areas unless authorized.

2.7.2.2.4 Water faucets or valves shall be turned off after use.

2.7.2.2.5 Government telephones shall not be used for personal reasons nor for any toll/long distance calls unless authorized by the COR. Telephone access will be made available for the Contractor’s use for local calls only. Long distance and toll calls require prior authorization by the COR and will be limited to credit cards only. Unauthorized calls by the Contractor will be reported to the KO for resolution.

2.7.2.2.6 The Contractor shall be liable for loss or damage to Government furnished property.

Compensation shall be affected either by reduced amounts owed to the Contractor or by direct payment by the Contractor. The specific method will be determined by the Government. In the case of damaged property, the amount of compensation due the Government by the Contractor shall be the actual cost of the repair, provided such amount does not exceed the economic repair value. In the case of loss or damage beyond economic repair of equipment, the amount of the Contractor’s liability shall be the depreciated replacement value of the item as determined by the Government.

2.7.2.3 EMERGENCY MEDICAL SERVICES

The Government will provide emergency medical treatment and emergency patient transportation service for Contractor personnel. The Contractor shall reimburse the Government the cost of medical treatment and patient transportation service at the current inpatient or outpatient treatment rate as appropriate.

Telephone number for Urgent Care is: 911.

2.7.3 CONTRACTOR FURNISHED EQUIPMENT, MATERIALS AND SERVICES

2.7.3.1 The Contractor shall provide all equipment, materials, and services to perform the requirements of this contract. Equipment provided will be used for preventative and corrective maintenance, and not to upgrade or augment the entire system.

2.7.3.2 The Contractor shall provide new parts and components when providing the services described herein. The government will not accept factory reconditioned parts. All replacement units, parts, components, and materials to be used shall be compatible with that existing equipment on which it is to be used; shall be of equal or better quality than original equipment specifications; shall comply with applicable Government, commercial, or industrial standards such as National Board of Underwriters or Underwriters' Laboratories, Inc., National Electrical Manufacturer's Association, etc.; and used in accordance with original design and manufacturer’s intent. If the original manufacturer has updated the quality of parts for current production, parts supplied under this contract shall equal or exceed the updated quality when life cycle replacement is necessary.

2.7.3.3 The KO requires that the Contractor submit manufacturer's descriptive data and certifications for materials and equipment used where there are questions concerning their performance and quality. This applies to all equipment and software installed by the Contractor or current existing equipment and software. Such submittals shall be delivered to the KO within 15 calendar days of request to be reviewed by J6. Manufacturer's descriptive data and certificates shall include the name of the manufacturer, model number or other identifying information, catalog cut, and other identifying data and information describing the performance, capacity, rating, and application/installation instructions which clearly illustrate that the proposed item meets all applicable standards.

2.7.3.4 The government will not be responsible for Contractor-supplied equipment.

2.7.4 CONTRACTOR PERSONNEL QUALIFICATIONS AND CERTIFICATIONS

2.7.4.1 Contractor personnel must be proficient in reading and capable of communicating effectively in English.

2.7.4.2 All work shall be performed by Contractor personnel specifically qualified and trained to work on the Lenel OnGuard ESS system, CCTVs, and Morse Watchman Keypro systems.

2.7.4.3 Contractor personnel performing work on the Lenel OnGuard ESS shall be certified by Lenel as a Certified Professional.

2.7.4.4 The Contractor shall be an authorized, licensed service representative or a Value-Added Reseller (VAR) in good standing with Lenel OnGuard ESS System. The Contractor will be responsible for obtaining all necessary licenses and certifications required to perform maintenance and repair services on Lenel OnGuard ESS, CCTVs, MNS and Morse Watchman Keypro systems, and for complying with all applicable Federal, State, and local laws. The Contractor shall maintain updated copies of any applicable licenses and certifications for all employees and make them available to the Government upon request.

2.7.4.5 All contractor personnel requiring elevated/privileged access to any system or network components, either during provisioning or post award, shall obtain an IT-II clearance and meet DoD 8570.1-M IA Technical (IAT) II baseline and Computing Environment (CE) certifications, provide a copy of all current certifications to the KO, the COR, and the TPOC at time of award and remain in good standing during the contract periods of performance. All contract personnel/technicians connecting, administering and/or requiring privileged (non-standard) access to devices, systems or applications that reside on the DLA network require 8570.01-M certification.

2.7.4.6 Contractor personnel shall wear required Government furnished badge and be easily recognized. This may be accomplished by Contractor personnel wearing distinctive clothing bearing the name of the company and/or by wearing appropriate badges which contain the company name and employee’s name. During performance of the service requirements set forth in this PWS, all Contractor personnel shall introduce themselves or shall ensure they are introduced as Contractor employees. Contractor personnel shall also appropriately identify themselves as contractor employees in telephone conversations and in formal and informal written correspondence.

2.7.4.7 Contractor personnel shall comply with directives pertaining to operation of privately owned vehicles at the DLA Distribution site.

2.7.4.8 The Contractor shall assure that Contractor technical personnel completely understand the requirements of this PWS. All Contractor service technicians must have sound mechanical aptitude and ability; basic understanding of machinery, both mechanical and electrical; basic understanding of the specific software and hardware utilized by the ESS and associated systems;

and the ability to understand and comprehend technical manuals, drawings, diagrams, and any other technical data supplied by the original equipment manufacturers (OEMs).

2.7.4.9 All Contractor service technicians must have working knowledge specific to the diagnosis and repair for the types of equipment included in this PWS and be capable of diagnosis and repair. In this case, where manufacturer’s certifications are available, recognized industry standard certifications may not be substituted. All Contractor service technicians must be OEM-certified to provide comprehensive installation and maintenance services to all ESS systems and equipment. The Contractor shall maintain a file containing all service technicians’ training and certifications and shall make this information available to the COR upon request.

2.7.5 REMOVAL OF EMPLOYEES

DLA reserves the right to direct the removal of an employee, whose actions, while assigned to this contract, clearly conflict with the interests of the Government, regardless of prior clearance or adjudication status. DLA also reserves the right to direct the removal of an employee for misconduct, security violations or performance reasons. The reason for removal shall be fully documented in writing by the KO. When and if such removal occurs, the contractor shall assign qualified personnel to perform the duties of this contract. This action does not relieve the contractor from total performance of the contract tasks specified herein.

SECTION 3 SECURITY

3.0.1 This section information addresses Security requirements.

3.0.2 Work under this contract requires access to government electronic security systems (ESSs). All contractor personnel shall be US Citizens; therefore, US Citizenship is a requirement. A security clearance is not required to perform work under this contract. The contractor shall comply with all applicable DOD security regulations and procedures during the performance of this contract. Contractor employees providing services are required to have a National Agency Check with Local Agency Check and Credit Check (NACLC) as required in accordance with DoD 5220.22-M, “National Industrial Security Program Operating Manual” (NISPOM) and DoD 5200.2-R. The results must be received prior to commencement of any contract work.

* A NEGATIVE NACLC DETERMINATION WILL RESULT IN IMMEDIATE

TERMINATION OF ACCESS TO THE WORKSPACE AND EQUIPMENT.

3.1 PHYSICAL SECURITY

To be compliant with DoD and DLA regulatory guidance, the Contractor shall ensure the physical security of all Government property to assure that any accountable inventory or information in this contract is secured and protected against theft, sabotage or other acts constituting illegal destruction. The Government will not be responsible in any way for damage to the Contractor’s supplies, materials, equipment, and property or to Contractor employees’ personal belongings that are damaged or destroyed by fire, theft, accident, or other disaster.

3.2 AUTHORIZED VISITOR CONTROL

3.2.1 Authorized visitors on official business related to the contract shall obtain approval from the KO or COR for entrance to the host installation. The Contractor shall submit a DL1818 Visit Notification Form (See Attachment) to the KO or COR at least one (1) week in advance for all planned off-base visitors and at least 24 hours in advance for all unscheduled visitors.

3.2.2 The Contractor shall NOT allow visits from foreign nationals to the host installation without written approval from the KO or COR. A foreign national is defined as a person who is not a citizen or national of the United States. If approval is obtained, the Contractor shall follow the instructions for coordinating the visit IAW DLAI 5230.01 Foreign Visit and Foreign Disclosure Program. (See Attachment)

3.3 PERSONNEL CLEARANCE

3.3.1 The Homeland Security Presidential Directive 12 (HSPD-12) dated 27 September 2012 has established criteria for Contractors who require physical access to an Installation or access to Government information technology (IT) systems. The Government requires Personnel Security Investigations (PSI) to establish that applicants or incumbents either employed by the Government or working for the Government under contract are suitable for the job and are eligible for a public trust or sensitive position. Upon favorable review and initiation of the PSI, Contractor personnel may be granted temporary access pending final adjudication of the PSI.

The Contractor shall request personnel clearances in accordance with (IAW) instructions found in Contractor Personnel Security. (See Attachment).

3.3.2 A Contractor Investigative Request (CIR) form annotating the appropriate designation shall be submitted for each contract employee.

3.3.3 Not later than 15 calendar days prior to contract full performance start date, the Contractor shall provide the KO or COR access rosters of all personnel requiring access to restricted or controlled access areas. The roster shall include each employee’s full name, identification card number (if assigned), branch or section (if applicable), and security clearance (level of clearance and last investigation date, if applicable). The Contractor shall update the roster and provide to the KO or COR no later than (NLT) five (5) workings days prior to the date of required access. The Contractor shall make all modifications to the rosters and provide an update to the KO or COR within 12 hours for employees whose employment has been terminated and for employees who no longer require access to restricted or controlled access areas.

3.4 ACCESS IDENTIFICATION (ID) BADGE

3.4.1 Every Contractor employee shall obtain and possess an Access ID Badge, as required by HSPD-12 and Directed-Type Memorandums (DTM) 08-003.

3.4.2 The Contractor shall safeguard all ID Badges. Contractor personnel shall not share ID Badges. Each Contractor employee shall always wear the ID Card(s) conspicuously on his or her outer clothing above the waist while working on the Installation. Personnel may be challenged and removed from the work area or denied access to the host Installation if the ID Card(s) are not worn. The Contractor shall not display or use any badge as a means of personal identification outside the Installation.

3.4.3 In the event that a Contractor employee damages his or her ID Card, the Contractor shall report the damaged ID Badge within two (2) working hours after discovery of damage to the KO or COR. The Contractor shall arrange for a replacement ID Card. The Contractor shall return all

Government-furnished ID Card(s) to the Government. Contractor personnel failing to return their Government ID Card are subject to criminal charges under United States Code (USC) Title 18, Chapter 1, Section 499 and 701.

3.5 INFORMATION, NETWORK, AND CYBER SYSTEM SECURITY

3.5.1 Information System Security Requirements

3.5.1.2 Upon favorable review and initiation of the PSI to establish the suitability of an employee for the job and the approval for temporary IT access pending final adjudication, but not less than fourteen (14) working days prior to the employee’s start date, the Contractor shall request Information Technology (IT) eligibility for an employee requiring privileged/elevated access and passwords to the Government data systems. Section 3.3 states the requirements for Contractor personnel that require privileged access.

3.5.1.3 All Contractor personnel provided with access to Government computers and systems shall observe IT security policies and procedures as provided by the KO, COR, or J6 COTR. The Contractor shall notify the KO or COR within 12 hours when, for reasons of personnel resignation, reassignment, termination, or completion of portions of the contract, Contractor personnel no longer require access to Government systems.

3.5.1.4 The Contractor shall observe all copyright agreements. In the interest of protecting Government systems from computer viruses, the Contractor shall not use public domain software nor shall Contractor personnel download software from public bulletin boards or Internet websites. The Contractor shall use only Government software and approved application software in performance of the contract requirements. The contractor shall purchase software support agreements as needed after approval from the J6 COTR, COR, or KO.

3.5.1.5 The Contractor will be responsible for all hardware and software-related maintenance/support activities in this PWS for the ESS, CCTV, MNS, and Keypro systems including, but not limited to: operating systems, firmware updates, software patching, database, hardware, and software, etc., to keep the system DoD compliant for the duration of the contract performance period(s). The solution must be upgradeable and remain compliant to cyber security specifications during the life of the solution. Any hardware or software required by the vendor should operate on the following system specifications: Workstations: Windows 10 Operating System, with minimum system requirements not to exceed: processor: Intel i5 -6200u @ 2.3 GHZ, 2 Cores, Ram: 8GB, Hard Drive: 256 GB. Servers: Windows Server 2016, Redhat Linux Enterprise v7 (or higher versions) in those instances that require a LINUX OS.

3.5.1.6 The Contractor is responsible for hardening the systems listed in the Equipment List (See Attachment), (ESS, CCTV, MNS, and Morse Keypro systems) and keeping all Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGS) up to date and remain in compliance with NIST Special Publication 800-82. The Contractor will submit all modifications to the COR, the TPOC and J6 COTR for approval prior to implementing any changes.

3.5.1.7 All control systems shall be considered low-moderate-low (Confidentiality-Integrity- Availability) unless otherwise notified in writing. The solution shall comply with the security control requirements documented in National Institute of Standards and Technology (NIST) Special Publication (SP) 800- 53r4, “Security and Privacy Controls for Federal Information Systems and Organizations” and NIST 800-82r2, “Guide to Industrial Control Systems (ICS) Security as specified in this PWS. The vendor shall provide details of any alternative but equally effective security measures used to compensate for the inability to satisfy a particular derived security requirement (mitigation to control compliance findings). Guidance on the applicability and enforcement of controls by Purdue Enterprise Reference Architecture (PERA) level can be found in the United Facilities Criteria (UFC) 4-010-06, Cybersecurity of Facilities-Related Control Systems. The NIST SP 800-82 R2 overlay for Industrial Control Systems (ICSs) shall be used as appropriate for the system.

3.5.2 Network System Security Requirements

3.5.2.1 All network components and applications shall be compatible with all applicable Defense Information System Agency (DISA) Security Technical Implementation Guides (STIGs). Any STIG exceptions must be identified as part of the Contractor’s proposal. Exceptions incurring risk found unacceptable to the DLA Authorizing Official (AO) are not permitted.

3.5.2.2 All network components and applications shall be Internet Protocol (IP)v4 and IPv6 compatible.

3.5.2.3 All wiring and cabling shall be in Electric Metal Tubing (EMT) type conduit.

3.5.2.4 All network components shall be connected using copper 10/100/1000 or fiber optic Small Form Factor Pluggable (SFP)-based Gigabit Ethernet ports.

3.5.2.5 Network components shall allow configuration of Institute of Electrical and Electronics Engineers (IEEE) 802.1x or port security for authentication.

3.5.2.6 Web servers, human-machine interface (HMI) and controller systems must be on separate Virtual Local Area Network (VLAN)s.

3.5.2.7 Any external network connections must be permanently disconnected.

3.5.2.8 The Contractor shall provide a complete list of all ports, protocols, and services (PPS) required for any computer system running control system applications or required to interface the control system applications. The listing shall include all ports and services required for normal operation as well as any other ports and services required for emergency operation. The listing shall also include an explanation or cross reference to justify why each service is necessary for operation.

3.5.2.9 The Contractor shall identify any system enabled or disabled.

3.5.2.10 All wireless communications shall meet applicable STIG requirements.

3.5.2.11 The Contractor shall provide Bill of Materials (BOM) and other network documentation to the COR in support of these requirements.

3.5.2.12 Any removable flash media required for system operation must be reviewed and accepted by the DLA Flash Media Approval Program.

3.5.3 Cyber Security Requirements

3.5.3.1 The Contractor shall not permit user credentials to be transmitted in clear text. Encryption shall at a minimum meet Advanced Encryption Standard (AES) 256 and comply with Federal Information Processing Standard (FIPS) 140-2. If this is not technically feasible, the Contractor shall provide the strongest encryption method commensurate with the technology platform and response time constraints and document the encryption used. The Contractor shall not allow multiple concurrent logins, applications to retain login information between sessions, provide any auto-fill functionality during login, or allow anonymous logins. The Contractor shall provide user account-based logout and timeout settings.

3.5.3.2 The Contractor shall provide cybersecurity that is in accordance with current policies, procedures, and statutes, to include (but not limited to) the following (most current):

a. The Federal Information Security Management Act (FISMA)

b. Committee on National Security Systems, Policy No. 11

c. Federal Information Processing Standards

d. Defense Information Systems Agency (DISA) Secure Technical Implementation Guides

(STIGs)

e. DOD Instruction 8510.01, Risk Management Framework (RMF) for DOD Information

Technology (IT)

f. DOD Directive 8140.01, Cyberspace Workforce Management

g. IA policies and DOD Directive 8500.1, Information Assurance

h. Global Information Grid (GIG) Concept of Operations (CONOPS)

3.5.3.3 The Contractor shall recommend which accounts need to be active and those that can be disabled, removed, or modified. The DLA KO or COR shall approve in writing the Contractor’s recommendation. The Contractor shall disable, remove, or modify all the accounts pursuant to the approved recommendation. The Contractor shall disable or remove all default and guest accounts. Once changed, new accounts will not be published except that new account information and passwords will be provided by the Contractor via protected media. At delivery, the Contractor shall disable, remove, or modify all Contractor-owned accounts or negotiate account ownership with the DLA KO and COR. Contractor updates shall not re-enable or re-install any of these accounts.

3.5.3.4 The Contractor shall implement two-factor authentication using DoD Common Access Card where technically feasible, with exceptions noted in the proposal. The Contractor shall provide a configurable account password management system that allows for selection of password length, frequency of change, setting of required password complexity, number of login attempts, inactive session logout, screen lock by application, and denial of repeated or recycled use of the same password. The Contractor shall not store passwords electronically or in Contractor-supplied hardcopy documentation in clear text unless the media is physically protected.

3.5.3.5 The Contractor shall provide physical and cyber security features for end devices (i.e. the source or destination of network traffic) including, but not limited to, authentication, encryption, access control, event and communication logging, monitoring, and alarming to protect the device and configuration computer from unauthorized modification or use. The Contractor shall clearly identify the physical and cyber security features and provide the methodology for maintaining the features including the methods to change settings from the Contractor-configured or manufacturer default conditions. The Contractor shall verify that the addition of security features does not adversely affect connectivity, latency, bandwidth, response time, and throughput. The Contractor shall remove or disable all software components that are not required for the operation and maintenance of the device prior to delivery. The Contractor shall provide documentation on what is removed and/or disabled. The Contractor shall provide, within a pre-negotiated period, appropriate software, and service updates and/or workarounds to mitigate all vulnerabilities associated with the product and to maintain the established level of system security.

3.5.3.6 The Contractor shall provide a detailed plan for physical security mechanisms appropriate for the type of devices being installed (enclosures, etc.).

3.5.3.7 The Contractor shall provide a System Security Plan with the following requirements:

a. Enterprise Configuration Management Plan

b. System Supplemental Implementation Guide

c. System Configuration Control Working Group Charter

d. Continuity of Operation Plan (COOP) or Contingency and Business Continuity Plan

(BCP)

e. COOP Exercise Evidence

f. Logical and Data Flow Diagrams

g. Disaster Recovery Plan (DRP)

h. Formal Agreement (e.g. Service Level Agreement (SLA), Memorandum of

Understanding/Association (MOU/MOA), Letter of Agreement LOA))

j. Security Personnel Appointment Memorandum(s)

k. Hardware Baseline Inventory

l. Software Baseline Inventory

m. Incident Response Plan (IRP)

n. System Key Management Standard Operating Procedure (SOP)

o. System Media Protection and Sanitization SOP

p. System Access Control and Account Creation SOP

q. System Audit and Accountability SOP

r. System Maintenance SOP

s. System Security Concept of Operations

t. System Design Document

u. Ports, Protocols, and Services

3.5.3.8 The Contractor shall adhere to all existing authorities and policies of the Director of National Intelligence regarding the protection of sensitive compartmented information (SCI), as directed by Executive Order 12333 and other laws and regulations.

3.5.3.9 The Contractor shall satisfy the RMF requirements of subchapter II & III of chapter 35 of Title 44, United States Code (U.S.C.), also known as the “Federal Information Security Management Act (FISMA) of 2014”

3.5.3.10 The Contractor shall enable DLA to meet the standards required by the Office of Management and Budget (OMB) and the Secretary of Commerce, pursuant to FISMA and section 11331 of Title 40, U.S.C.

a. FIPS 199 / FIPS 200 / FIPS 201/ Committee on National Security Systems Instruction

(CNSSI) 1253 Security Categorization: The Contractor shall participate in categorization discussions with the DLA program manager / User Technical and the ISSM, and as requested to support security categorization.

b. The Contractor shall in coordination with the prescribed System Owner (SO) and

Authorizing Official (AO) support categorization IAW FIPS 199, FIPS 200, FIPS 201 and CNSSI 1253 of the CS and document the results of the security categorization in the security plan.

c. The Contractor shall ensure that a written subsection of the security plan covers FIPS 199

/ FIPS 200 / FIPS 201 CNSSI 1253 Security Categorization and Threat Assessment. DLA and or the SO will provide a C-I-A concurrence memorandum from SO respective AO agreeing with their determination of controls (Confidentiality, Integrity, and Availability with any overlays and tailoring).

3.5.3.11 The contractor shall provide cybersecurity (CS) in accordance with all current policies, procedures, and statutes, to include (but not restricted to) the following as applicable to specific task orders mentioned in this PWS:

a. 44 U.S.C. § 3542, January 2012.

b. Committee on National Security Systems Instruction 1253, Security Categorization and

Control Selection for National Security Systems, March 15, 2012, as amended.

c. Federal Information Processing Standards Publication 199, Standards for Security

Categorization of Federal Information and Information Systems, February 2004.

d. Federal Information Processing Standards Publication 200, Minimum Security

Requirements for Federal Information and Information Systems, March 2006

e. Federal Information Security Management Act (P.L. 107-347, Title III), December 2002.

f. Department of Defense Instruction 5000.02, Operation of the Defense Acquisition

System, January 7, 2015

g. Department of Defense Instruction 5200.39, Critical Program Information (CPI)

Identification and Protection within the Research, Development, Test, and Evaluation

(RDT&E)

h. Department of Defense Instruction 5200.44, Protection of Mission Critical Functions to

Achieve Trusted Systems & Networks, July 27, 2017

j. Department of Defense Directive 8140.01, Cyberspace Workforce Management, August

11, 2015.

k. Department of Defense Instruction 8330.01, Interoperability of Information Technology

(IT), Including National Security Systems (NSS), May 21, 2014

m. Department of Defense Instruction 8500.01, Cybersecurity, dated 14 March 14.

n. Department of Defense Instruction 8510.01, Risk Management Framework (RMF) for

DoD Information Technology, dated 12 Mar 14.

o. Department of Defense 8570.01-M, Information Assurance Workforce Improvement

Program, Change 3 dated 24 Jan 2012

p. Department of Defense Instruction 8580.1, Information Assurance (IA) in the Defense

Acquisition System, July 9, 2004

q. DoD Program Manager’s Guidebook for Integrating the Cybersecurity Risk Management

Framework (RMF) into the System Acquisition Lifecycle

r. Defense Acquisition Guidebook (DAG)

s. Deputy Under Secretary of Defense (Installations and Environment) Memo dated 19 Mar

14, subject: Real Property Related ICS Cybersecurity.

t. Defense Information Systems Agency (DISA) Secure Technical Implementation Guides

(STIGs)

u. National Institute of Standards and Technology Special Publication 800-30, Guide for

Conducting Risk Assessments, September 2012.

v. National Institute of Standards and Technology Special Publication 800-37, Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach, February 2010.

x. National Institute of Standards and Technology Special Publication 800-39, Managing

Information Security Risk: Organization, Mission, and Information System View, March 2011.

y. National Institute of Standards and Technology Special Publication 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, April 2013.

z. National Institute of Standards and Technology Special Publication 800-82 Revision 2, Guide to Industrial Control Systems (ICS) Security, February 2015

aa. UFGS-25 50 00.00 20 Cybersecurity of Facility-Related Control Systems

bb. United Facilities Criteria (UFC) 4-010-06, Cybersecurity of Facilities-Related Control

Systems

cc. All replacement parts must be new and in compliance with NDAA John S. McCain

National Defense Authorization Act for Fiscal Year 2019.

3.6 GOVERNMENT-ISSUED BADGES

Contractor shall return all government issued identification and access badges to DLA Distribution Site Security Specialist upon termination of contract maintenance services.

SECTION 4 WORK PERFORMANCE PHASE-IN PERIOD REQUIREMENTS

4.0 CONTRACTOR PHASE-IN CERTIFICATIONS

4.0.1 A phase-in period shall be established to allow the Contractor sufficient time to complete all hiring actions for required maintenance personnel to perform the contract requirements.

4.0.2 The phase-in period shall begin at the effective date of the contract and shall not exceed one (1) month, at which time full performance shall begin.

4.0.3 Contractor personnel shall have authorized, approved site access credentials prior to full contract performance. See Section 2.4 and 3.4 for guidance and instructions.

4.0.4 The Contractor shall ensure that all Contractor personnel are ready to begin working on the first day of full performance.

4.0.5 During the one-month phase-in period, Contractor personnel shall complete security and safety training on site. Training will be scheduled through the DLA Distribution site training office and will at a minimum include the following classes. Estimated in class time is 3 hours.

a. Active Shooter Briefing

b. Safety Briefing

c. Shelter in Place/Evacuation Awareness Briefing

4.0.6 During the one month phased-in period to ensure all Contractor personnel know and understand regulations and policy pertaining to physical, information, operations and personnel security, the Contractor shall provide security and antiterrorism training to all employees in accordance with applicable DOD regulatory requirements. At a minimum, security training requirements as required by the DLA Issuances and other applicable DOD guidance will be completed annually for the following on-line training. Estimated in class time is 8 hours.

a. Cyber Awareness Challenge

b. Antiterrorism (AT) Level 1

c. Operations Security (OPSEC)

d. Counterintelligence Awareness Training

e. Personal Identifiable Information Awareness

f. Trafficking in Persons

The security training is web-based, and access will be provided by the Government. The Contractor shall ensure Contractor personnel have taken the required security training to meet DoD guidance and that the personnel continue to maintain their certifications.

4.0.7 The contractor will access ESS system components via Government Furnished Equipment (GFE). All specialized software required by the contractor must be provided to the government by the contractor at the time of the contract award. All contractor provided software that will be required to be installed on GFE or vendor provided hardware will be evaluated and will require J6 COTR, TPOC and COR approvals prior to installation. This includes any utilities required to develop, communicate, and make configuration updates to a system.

SECTION 5 WORK – TASKS AND REQUIREMENTS

5.0 WORK - GENERAL REQUIREMENTS AND PROCEDURES

This Section provides general information relating to the general requirements and procedures relating to the contract services to be performed by the Contractor.

5.0.1 WORK STANDARDS

5.0.1.1 All workmanship shall meet the standards specified herein and shall be accomplished in conformance with approved and accepted standards of the industry; OEMs; all applicable DoD, DLA, USN, DDAA, local, state, and federal standards; and all applicable building and safety codes.

5.0.1.2 When the Contractor completes work on a system or piece of equipment, that system or piece of equipment shall be free of missing components or defects which would prevent it from functioning as originally intended and/or designed. Corrective or repair/replacement work shall be carried to completion including operational checks and cleanup of the job site. Except where otherwise noted, replacements shall match existing in dimensions, finish, color, and design.

5.0.1.3 During and at completion of work, debris shall not be allowed to spread unnecessarily into adjacent areas nor accumulate in the work area itself. All such debris, excess material, and parts shall be cleaned up and removed at the completion of the job and/or at the end of each day work is in progress.

5.0.1.4 Upon completion of all work, the Contractor shall contact the COR to report the status of the system and document details of the service in the on-site service request log.

5.0.1.5 All work relating to incidents and will be managed and tracked through the ITSM Remedy service ticketing system. The Contractor shall provide service ticket support. As instructed by the COR, the contractor may be required to participate in meetings and conference calls with users, the functional community and the PMO to discuss requirements and trouble tickets; review and analyze production trouble tickets; and recommend and implement fixes as directed by the Government. Service tickets are used for all work including break/fix production issues, project support and development, research, planning, onboarding, and technical efforts such as upgrades, migrations, or technical refreshes. Problems or potential problems discovered in basic maintenance are resolved by various service ticket types including Incidents, (Break Fix), General Work Orders (GWO), Project Work Orders (PWO), Break/Fix CRQs and normal project CRQs. Service tickets will be created by the Government and/or may be initiated as requested by the Contractor’s Project Manager.

5.0.2 WORK – EQUIPMENT REPLACEMENT, MODERNIZATION, RENOVATION

During the term of the contract, the Government may replace, renovate, or improve systems and equipment at the Government's expense and by means not associated with this contract. All replaced, improved, updated, modernized, or renovated systems and equipment shall be maintained and/or repaired by the Contractor at no additional cost to the Government unless such changes result in an increase or decrease in contract requirements. Changes, replacements, or deletions which result in an increase or decrease in contract requirements will result in adjustments to the contract price IAW any contract changes and adjustments clauses. They shall be executed by a contract modification(s) issued by the Contract Specialist and the KO.

5.0.3 WORK - MANUFACTURER’S OR INSTALLER’S WARRANTY

Equipment, components, and parts, other than that installed under this contract, shall not be removed, or replaced or deficiencies corrected by any service technicians while still under OEM warranty(s) without prior written approval of the COR. All defects in material or workmanship, defective parts, or improper installation and adjustments found by the Contractor shall be reported to the COR so that necessary corrective action(s) may be taken. The Contractor shall be knowledgeable of the equipment, parts, and components that are covered by warranty and the duration of such in-force warranties. Available warranty information will be furnished to the Contractor by the COR.

5.0.4 WORK - AS-BUILT DRAWINGS

5.0.4.1 Existing as-built drawings will be available to the Contractor onsite for information only.

The Government makes no representation as to the completeness or accuracy of these drawings.

5.0.4.1 All changes to or additions to security systems and equipment made by the Contractor shall be recorded by the Contractor and provided to the COR and the J6 COTR within fourteen

(14) calendar days of the completed work. This data shall include, but is not limited to, dimensioned drawings and sketches.

5.0.5 WORK - SOFTWARE UPDATES, APPLICATION UPGRADES, AND PASSWORDS

5.0.5.1 The Contractor shall provide all software updates when an upgrade/patch is released from the OEM. The Contractor shall maintain an accurate software configuration and coordinate through the appropriate supplier for all equipment. Any software updates will need to be coordinated directly with the COR and the J6 COTR. All contractor provided software required to be installed will be evaluated and will require approval from the COR and the J6 COTR prior to procuring and installation. This includes any utilities required to develop, communicate, and make configuration updates to a system. Any existing hardware or hardware purchased by the vendor will be turned over to the government.

5.0.5.2 The Contractor shall recommend which accounts need to be active and those that can be disabled, removed, or modified.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .