Attachment 1 SOW.pdf

PDF 248 KB Posted

Attached to
Update/Replace Physical Access Control System (PACS) Federal contract opportunity
Solicitation number
HQ042322Q0060
Issued by
Defense Finance and Accounting Service

View the file

Other files for this federal contract opportunity

Other files attached to Update/Replace Physical Access Control System (PACS), newest first.
File Type Posted
Vendor Questions and Responses 2.pdf PDF
Synopsis Solicitation Amendment.pdf PDF
Vendor Questions and Responses.pdf PDF
Synopsis Solicitation Instructions.pdf PDF
Attachment 3 Technical Cert Form.docx DOCX document
Attachment 2 Schedule of Items.docx DOCX document
Attachment 4 Clause Fill-Ins.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 1 Statement of Work (SOW)

Defense Finance and Accounting Service (DFAS) Texarkana Update/Replace Physical Access Control System (PACS)

Solicitation # HQ042322Q0060

1. INTRODUCTION: This Statement of Work (SOW) outlines specific service and support requirements for the physical access control system (PACS). This project is to upgrade or replace the current physical access control system (PACS) at building 735 on Red River Army Depot, near Texarkana, Texas. After installation, subsequent periods of warranty, maintenance and telephone support for the upgraded or replaced system will be required.

1.1 Background: The current system in place is Softwarehouse C Cure 9000

2.60.4972.0414. This system was accepted by the Government in 2016 and has not incurred any upgrades. Currently installed serviceable components and infrastructure may be re-utilized. Any current equipment not re-utilized shall be returned to the Contracting Officer Representative (COR). The current system consists of the following:

• Fourteen (14) card readers. They are Innometriks Cheetah Core+Contact Reader part #’s INN-CHTA-CT and INN-CHTA-CTO.

• No cameras or video requirement.

• All door contacts and electric locks in good working condition.

• Existing cabling that may be reused.

• Limited mounting space. Existing equipment will need to be removed to make room for new equipment.

• One enrollment station.

• 100 preconfigured and printed visitor credentials.

2. SCOPE: The upgraded or replaced PACS shall meet all requirements of FIPS-201, HSPD-12, and be listed on the GSA Approved Products List (APL) https://www.idmanagement.gov/approved-products-list/ and be FISCAM (Federal Information System Controls Audit Manual) compliant. The contractor shall provide warranty and maintenance as outlined in this SOW. The Contractor shall provide telephone support for system operation from 0700 - 1600 Monday – Friday for the duration of the contract.

3. TASKS: The following tasks shall be performed:

3.1 Contractor shall provide and install a PACS that meets all requirements of FIPS- 201, HSPD-12 and be a GSA approved product. The system shall comply with standards for entry to Controlled and Limited designated areas. The system shall comply with all relevant NIST SP800-116 requirements for card & cardholder authentication and standards for entry to Controlled and Limited designated areas. The system shall be commissioned as a new system and shall come with a minimum warranty of one year that covers all components, updates, related infrastructure and bi-annual site visits to perform preventive maintenance, tests, and updates (all licensing cost for software and hardware https://www.idmanagement.gov/approved-products-list/

Defense Finance and Accounting Service (DFAS) Texarkana shall be included). Warranty period shall begin after the system has been accepted by the Government.

3.2 The Contractor shall ensure all construction for this project is completed within 29 CFR (Code of Federal Regulation) 1910, OSHA General Standards and 29 CFR 1926, to include OSHA Construction Standards, Unified Facilities Criteria (UFC) 3-580-01 Telecommunications Building Cabling Systems Planning and Design, Unified Facilities Criteria (UFC) 3-600-01 Fire Protection Engineering for Facilities, UFC 4-010-01 Minimum Antiterrorism Standards for Buildings, International Building Code, and Uniform Mechanical Code, and DA Technical Guide for Installation Information Infrastructure Architecture (I3A) July 2008. Furthermore, all electrical work shall comply with NFPA Life Safety Code 101, the latest edition of NFPA 70, (National Electric Code) and NFPA standards for communications.

3.3 Contractor shall respond to repair requests within 24-hours, 5 days per week (Monday – Friday). The contractor shall be responsive to different aspects of service interruption to include the following:

3.3.1 Full Outage or system failure/non-responsive software/hardware that causes non-operation of the PACS and/or CCTV.

3.3.2 Partial Outage, where one or more access doors are affected with complete or partial non-operational status.

3.3.3 Equipment Specific, where singular points of failure in equipment are identified, thus rendering the node in question inoperable and in need of replacement/remediation before fully operational service can be restored.

3.3.4 All covered equipment shall be repaired within three business days. If repair of equipment is expected to exceed the three-business day response time, the contractor shall provide written justification as to the nature of the delay in repair/replacement of identified equipment within 24 hours of system evaluation. The contractor shall notify the customer of all projected downtime and estimated time for repair. The contractor shall provide written report via email of all services rendered at time of repairs, services, and preventive maintenance.

3.4 Maintenance Schedule Quality Assurance Plan: Contractor shall propose maintenance schedule and life-cycle replacement for systems and equipment. The government will approve the plan.

3.5 Contractor shall provide one year of extended warranty coverage and maintenance with each additional option year exercised. This will include bi-annual site visits to

Defense Finance and Accounting Service (DFAS) Texarkana perform preventive maintenance, tests and updates (all licensing cost for software and hardware shall be included).

3.6 PACS system shall include 14 readers and 100 compliant visitor cards which can be used with the system. All visitor cards shall be preprinted with local simple design and serially numbered. Final design of visitor cards shall be approved by the DFAS-TX government representative prior to printing.

3.7 Contractor shall furnish an electronic version and hard copy print in three ring binders, one full set of the system manufacturer’s system training manual, system maintenance manual, and one training video (in format provided by the system manufacturer), with system installation. The authorized manufacturer’s representative shall provide system user/administrator level training on site for all system functions.

Hands on training shall be provided for system admins/operators up to three sessions limited to two employees per session. Training shall be provided regarding Administration, Registration, Provisioning/De-provisioning, Alarm processing and Event Log generation. Contractor shall demonstrate that registration, provisioning and subsequent use of an employee's PIV/PIV-I/CAC Credential is completed. Training is considered successful when Government personnel have gained sufficient knowledge to properly perform their assigned duties regarding the PACS system.

3.8 System shall include a minimum of 8-hour battery backup, with batteries located outside of the system IAW DFAS 5200.8-I (9).

4. TASKS: Government Support

4.1 The Government will provide PDF floor plans upon request. No readers are being moved or added.

4.2 The PACS shall be installed with all equipment as listed on the GSA Approved Products List (APL). The system will be configured to operate as a stand-alone system with no connectivity to a network at this time.

5. SYSTEM ACCEPTANCE:

5.1 The contractor shall demonstrate that registration, provisioning and subsequent use of an employee's PIV/PIV-I/CAC Credential is completed.

5.2 The contractor shall demonstrate that each alarm is processed, annunciated on the Alarm monitor in text for New Alarm and Acknowledged Alarm, Cleared Alarm

5.3 The contractor shall provide complete set of “As-Built" system drawings at each site. System drawings shall clearly show each cable, PACS component, server, Defense Finance and Accounting Service (DFAS) Texarkana workstation (Client) and other equipment installed- The system shall pass a predefined Quality Control test.

5.4 The contractor shall demonstrate that the system run without off-line errors, reader errors, and alarm errors for a period of 15 business days after the installation work is completed. System acceptance requires that this test is fully and successfully completed. Any equipment made deficient through contractor negligence, the contractor shall be financially responsible and shall be responsible for replacement.

5.5 The contractor shall provide written certification from a current System Engineer ICAM PACS, CSEIP that verifies the system has been configured and installed in accordance with the same standards used for acceptance to be listed on the GSA APL. This certification may be provided from the manufacturer.

6. REPORTING REQUIREMENTS:

6.1 Verbal briefings/reports to discuss the status of instruction, may be requested by the COR anytime on an as needed basis.

6.2 Written status reports identifying the accomplishments, issues, or problems, shall be submitted to the government within ten days of maintenance events and the installation Quality Control test.

6.3 Monthly status reports describing previous month system performance, previous month maintenance events, and events regarding the Maintenance Schedule Quality Assurance Plan shall be provided to the COR every month.

7. QUALIFICATION REQUIREMENTS: The consultant/analyst/project manager/task manager/functional specialist selected for the purpose of this contract shall have, at a minimum:

7.1 SPECIAL QUALIFICATIONS: Technicians completing the work on site shall have valid PACS manufacturer training & certification for the system being installed.

7.2 COVID-19 –REQUIREMENTS: All individuals on DoD property, installations, and facilities shall comply with site-related requirements to prevent the spread of COVID-19. Examples include, but are not limited to, wearing cloth face coverings in public areas, work centers, as well as when entering the building;

maintaining social distancing; and not come on site when displaying symptoms of

COVID-19.

8. PLACE OF PERFORMANCE, PERIOD OF PERFORMANCE, AND WORK

DAYS:

Defense Finance and Accounting Service (DFAS) Texarkana

8.1 PLACE OF PERFORMANCE: All work shall be accomplished at building 735 on Red River Army Depot, near Texarkana, Texas.

8.2 PERIOD OF PERFORMANCE: This contract will be established for a one-year base period that includes the initial system and one (1) year warranty with preventive care. The contract will contain four one-year option periods that may be exercised by the Government. Each option period shall extend the warranty period for an additional year. Preventive care consists of two (2) onsite visits per year (semi-annual).

8.3 WORK DAYS: The Contractor shall perform services required under this SOW during the operating hours of the Government activity. Normal operating hours for DFAS Texarkana is from 0700 to 1600 hours; Monday through Friday except Federal Holidays.

Specific dates for federal holidays can be found at http://www.opm.gov/.

9. RESTRICTIONS: There are no known existing or potential conflicts of interest associated with this task.

10. CRITICAL POINTS OF CONTACT: The below critical points of contact are subject to change. The Contractor will be notified in writing of any changes.

10.1 Alice Hendrix- alice.m.hendrix.civ@mail.mil, phone: 903-334-1638, DSN 829- Title- COR

10.2 Donald Carrier donald.r.carrier.civ@mail.mil, phone: 903-334-1652, DSN 829- Title- Subject Matter Expert/Government Representative

10.3 Scott Van Zile scott.w.vanzile.naf@mail.mil, phone: 903-334-1676, DSN 829- Title- Subject Matter Expert/Government Representative

11. SECURITY REQUIREMENTS:

Personnel Security Investigation (PSI) Requirements. Contractor personnel working on this contract will require a favorably adjudicated Tier 3, or equivalent Noncritical Sensitive (formerly IT-II) level or higher investigation. No access to classified information is required. IAW standard DFAS Personnel Security policy, ALL incoming contractors, regardless of whether they possess a favorably adjudicated Noncritical Sensitive (formerly IT-II) or higher investigation, must submit a Declaration for Federal Employment (OF-306), and a new set of fingerprints* to the COR, who will submit these forms with a Contractor Request for Investigation (CRI) (DFAS Form 9035) to DFAS Personnel Security. DFAS Personnel Security will review all submitted documentation to validate whether contractor personnel meet personnel security requirements to perform work on the contract or if a new background investigation is required.

*New fingerprints are not required if any of the following apply:

mailto:alice.m.hendrix.civ@mail.mil mailto:donald.r.carrier.civ@mail.mil mailto:scott.w.vanzile.naf@mail.mil

Defense Finance and Accounting Service (DFAS) Texarkana

The person has been fingerprinted for the Office of Personnel Management (OPM) within the past 120 days;

The person is currently undergoing a background investigation, or reinvestigation, by OPM or any other Federal agency;

The person has a background investigation currently being adjudicated by the Department of Defense Consolidated Adjudications Facility (DoD-CAF) or another CAF;

The person has been favorably adjudicated within the past 30 days by the DoD CAF or a CAF from any other Federal agency; or

The person is coming directly from another DoD agency, with no break in service. This includes any of the military branches as well as the U.S. Coast Guard; however, service members in an inactive reserve status are not included.

The Personnel Security Office otherwise determines that no new fingerprints are required.

Security Requirements. Contractor personnel shall follow the security and training requirements in DFAS 2000.1-I, “Force Protection Mission,” DoDM 5200.01, Volumes 1-3, “DoD Information Security Program,” DoDI, 5200.48, “Controlled Unclassified Information,” DFAS 5200.1-I, “Information Security Program,” DFAS 5200.8-I, “Physical Security Program,” and DFAS 5200.10, “Insider Threat Program.” Contractor personnel shall follow all host security requirements in accordance with DoD 5220.22-M, paragraph 6-105. The contractor shall immediately report any occurrences of violation of stated regulations to the Contracting Officer (CO), Contracting Officer Representative (COR) and the Personnel Security Office.

DFAS Personnel Security Incident Reporting Requirements, the National Industrial Security Program and Due Process as it Relates to DFAS Contractor Personnel. The National Industrial Security Program (NISP) is a partnership between the federal government and private industry to safeguard classified information.

Executive Order 12829, as amended, "National Industrial Security Program", further amended by Section 6 of E.O. 13691, was established to achieve cost savings and to ensure that industry safeguards the classified information with which it is entrusted while performing work on contracts, programs, bids, or research and development efforts while working for United States Government.

It is important to note that personnel employed as contractors for DFAS are not covered under the National Industrial Security Program (NISP) and are exempt from the provisions of 5 C.F.R.

731. This means that DFAS contractor personnel involved in an incident that potentially violates one or more of the National Security Adjudicative Guidelines found at https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-4-Adjudicative-Guidelines- U.pdf, are not entitled to Due Process rights normally afforded to federal civilian employees and

Defense Finance and Accounting Service (DFAS) Texarkana those personnel covered under NISP; more specifically, Personnel Security may suspend or revoke their access to DFAS IT systems, sensitive information and/or DFAS facilities.

Incident Reporting Requirements. Whenever a DFAS contractor displays conduct, or is involved in any incident, which is in violation of any of the thirteen National Security Adjudicative Guidelines*, a report shall be made immediately following the incident, or as soon as practicable thereafter, to a member of DFAS management, if there is one, of the area to which they are assigned, the COR, and in all cases, the Personnel Security Office. Reporting to Personnel Security may be made by phone to (317) 212-7888, by email to dfas.indianapolis-in.zh.mbx.dfas-inhrsecurity@mail.mil , or, in the case of personnel physically located at DFAS Indianapolis Center, in person to the Personnel Security Office located on the third floor center hallway at Column 320T.

All incidents will be investigated by Personnel Security and, depending on the date of the subject’s most recent investigation, may need to have an updated background investigation initiated. Those that do not require a new investigation will have all relevant information regarding the incident forwarded to the Department of Defense, Consolidated Adjudications Facility (DoD-CAF) for review and re-adjudication.

*The thirteen National Security Adjudicative Guidelines are:

1. GUIDELINE A: Allegiance to the United States;

2. GUIDELINE B: Foreign Influence

3. GUIDELINE C: Foreign Preference

4. GUIDELINE D: Sexual Behavior

5. GUIDELINE E: Personal Conduct

6. GUIDELINE F: Financial Considerations

7. GUIDELINE G: Alcohol Consumption

8. GUIDELINE H: Drug Involvement and Substance Misuse

9. GUIDELINE I: Psychological Conditions

10. GUIDELINE J: Criminal Conduct

11. GUIDELINE K: Handling Protected Information

12. GUIDELINE L: Outside Activities

13. GUIDELINE M: Use of Information Technology

Some Examples of Incidents That Require Reporting to Personnel Security:

a. An arrest for any criminal offense, not including minor traffic violations, by any law enforcement agency. This does include the traffic offenses of Driving Under the Influence of Alcohol or Drugs, and Reckless Driving;

b. Violation of any court order;

Defense Finance and Accounting Service (DFAS) Texarkana

c. Delinquencies on any debt for 180 days or longer;

d. Federal, State or Local tax issues or delinquencies;*

e. Delinquencies on any Federal debt;*

f. Child Support delinquencies;

g. Filing for Chapter 7 or Chapter 13 bankruptcy in any Federal Bankruptcy Court;

h. Civil judgements;

i. Having a close personal friendship with a Foreign National (person from a foreign country) with regularly occurring contact;

j. Being approached by a person know to be, or suspected to be, working as an agent of a foreign government or terrorist organization, or any other person, who seeks any information about DFAS, the Department of Defense, or the U.S. Government, especially if the person offers money or something of value to the contractor employee; and

k. Ownership of property or financial accounts in a foreign country.

It should be noted that persons delinquent on Federal debt of any kind may not obtain or maintain favorable personnel security adjudication be considered for a contractor position with DFAS unless they can provide documentary proof that a payment plan has been established with the government agency to whom the debt is owed, and that regularly recurring payments are being made. Contractor personnel who cannot obtain and maintain a favorable personnel security adjudication may not have access to the government data, facility, and equipment required under the contract.

NOTE: This list does not cover every potential incident or offense; any incident in which a contractor is involved and a question exists as to whether it should be reported, should report the incident to Personnel Security, who will then determine if further action is warranted. Failure to report an incident is, in and of itself, an incident involving personal conduct, and may, in some cases, be more serious than the original incident.

Foreign Travel by DFAS Contractor Personnel. Official and Unofficial (Personal) Travel:

Official U.S. Government Business: persons employed as contractor employees with DFAS, to include those with Noncritical Sensitive (formerly IT-II) access, Critical Sensitive (formerly IT- I) access, access to critical program information (related to Research, Development, Test, and Evaluation), sensitive compartmented information, and/or special access program information, in accordance with DoD Directive 5240.06, are required to complete a DFAS Form 9133, Notification of OCONUS Travel, not less than fourteen (14) calendar days prior to the scheduled travel. One copy shall be sent the DFAS Personnel Security group box at dfas.indianapolis-

Defense Finance and Accounting Service (DFAS) Texarkana in.zh.mbx.dfas-inhrsecurity@mail.mil and one copy shall be turned into the Site Security/Force Protection Office of the DFAS site where they are stationed.

Upon receipt of the completed Form 9133, the Site Security/Force Protection Office will contact the contractor employee and schedule a Foreign Travel briefing. Immediately prior to travel, contractor employees will check with the State Department at https://travel.state.gov/content/travel/en/traveladvisories/traveladvisories.html.html for any travel advisories for the country or region being traveled to and take the appropriate steps to ensure their safety for any location covered by a travel advisory or warning.

Security Education and Training. Contractor personnel shall receive initial, continuous and refresher security education training in accordance with DFAS 2000.1-I, DoDI 5200.48, and DFAS 5200.1-I. Contractor personnel shall also complete all required contractor training requirements identified in this Statement of Work.

Access To, Accountability For, and Safeguarding Of Controlled Unclassified Information (CUI). The DFAS manager of the requiring office will determine what CUI contractor personnel are given access to. CUI may not be disclosed to contractor personnel unless required for contract performance. Contractor personnel shall safeguard CUI in accordance with DoDI

5200.48 and DFAS 5200.1-I Enclosure 13. The sponsoring DFAS activity will provide storage capability for all CUI required for contract performance.

Installation Entry Requirements. The Contractor shall comply with established security procedures for entering government installations and facilities. Contractor employees shall be required to obtain and wear identification (ID) badges that will permit access into the facility.

All credentials issued to Contractor personnel are Government property and must be returned to the assigned DFAS COR/TA upon departure from the program or at the conclusion of the contract, whichever comes first. Contractors whose credential is lost or stolen must report the loss as soon as possible to the assigned DFAS COR/TA and present documentation that the credential is missing and describing the circumstances under which the loss occurred. The assigned DFAS COR/TA will follow local procedures to replace the credential.

The credential contains personally identifiable information (PII) and must be treated as a controlled item. Contractors’ must not share their credentials with any other staff members. The assigned DFAS COR/TA will report any violation or suspected violation to the Contracting Officer and DFAS Trusted Agent Security Manager (TASM). Any violators will be temporarily or permanently removed from the project. If a Contractor has a credential issued from a previous engagement with another agency that credentials must be returned to that agency before issuance of a new credential.

Training.

Defense Finance and Accounting Service (DFAS) Texarkana

Antiterrorism Level One. For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:

https://jkodirect.jten.mil/Atlas2/page/login/Login.jsf

Combating Trafficking in Persons (CTIP) Awareness Training. For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:

http://ctip.defense.gov/

DoD Mandatory Controlled Unclassified Information (CUI) Training. For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:

https://securityawareness.usalearning.gov/cui/index.html.

NOTE: This list of training requirements is subject to change.

Web-based Training: The contractor personnel shall retain a PDF copy of the “Certificate of Completion” or a “screen shot” with the date of the completion for all required training. The COR will maintain a file for proof of completion.

Contractor personnel who do not require network access but require unescorted access into a DFAS facility shall receive applicable security training through the site Force Protection Office.

Contactor shall contact the COR to identify Site Force Protection Officers at each DFAS location.

The prime contractor official representative shall provide the COR with a group list of its personnel requiring completion of the required training. The COR will submit the ‘group list’ to the Site Force Protection Officer to schedule training. As a reminder, the prime contractor official representative shall submit this group list of names within 30 days after contract award.

Requests for individual training shall be justified in writing and submitted to the COR for evaluation. Special arrangements will be determined by the Site Force Protection Officer and the

COR.

Interaction with Contractor Personnel. The COR shall forward questions or concerns directly to the prime contractor official representative who is directly responsible for managing its own employees/subcontractor personnel.

The prime contractor official representative shall coordinate with the COR a training schedule without causing undue delays to contract performance.

The prime contractor official representative (including subcontractor’s personnel when applicable) shall provide the COR, within 30 days after contract award/exercise of an option, a written report identifying:

- Contractor employees required to take the training, Defense Finance and Accounting Service (DFAS) Texarkana

- Contractor employees who have completed the training and

- Contractor employees who are delinquent.

Contractor personnel shall direct their training questions or concerns to their contractor management chain and/or company representative.

Training Point of Contact (POC). The COR is the POC for the Contractor. The Contractor shall provide regular training updates to the COR, and keep an updated registry to assure employees who come on board at any time in the contract life have completed all required training.

File details come from the government source that posted it. Updated .