Attachment 1_SSS_End User Remote Access_Solution_DRAFT.pdf
PDF 406 KB Posted
- Attached to
- MARINE CORPS ENTERPRISE NETWORKS (MCEN) END USER REMOTE ACCESS SOLUTION Federal contract opportunity
- Solicitation number
- M67854-25-I-4011
- Issued by
- United States Marine Corps
About this file
This is a System/Subsystem Specification (SSS) document for the Marine Corps Enterprise Network (MCEN) End User Remote Access (EU RAS) Solution, prepared by Program Executive Office Digital and Enterprise Services. The document defines required capabilities and characteristics for modernizing MCEN's remote access solution to replace the previous Virtual Private Network (VPN) system that was removed due to vulnerabilities.
The technical specifications require a solution that provides secure access from external networks to MCEN resources using DoD encryption ciphers, with 5Gb/s minimum throughput at each Policy Enforcement Point. Key requirements include: support for agent-based deployments, on-premises and cloud deployment capabilities, continuous monitoring of user activity, micro-segmentation principles, and integration with User/Entity Behavior Analytics. The system must be FIPS 140.2 certified, support up to 150,000 concurrent users, and provide high availability with globally distributed Policy Enforcement Points. The solution must authenticate via USMC implementation of DoD PKI, integrate with MCEN architecture and enterprise services, and comply with applicable Security Technical Implementation Guides (STIGs). The document includes detailed specifications for policy enforcement, administration, compliance, logging, and system requirements, with both threshold (T) and objective (O) requirements clearly defined.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| EU RAS RFI Announcement_Final.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SYSTEM/SUBSYSTEM SPECIFICATION (SSS) 19 DECEMBER 2024
MCEN END USER REMOTE ACCESS (EU RAS) VERSION DRAFT
UNCLASSIFIED
i
Marine Corps Enterprise Network End User Remote Access Solution System/Subsystem Specification
DRAFT
19 December 2024
PREPARED BY:
Program Executive Office Digital and Enterprise Services (PEO Digital) Marine Corps Systems Command (MCSC)
Distribution Statement A. Approved for public release: distribution is unlimited.
ii
MCEN End User Remote Access Solution
SUBMITTED BY
CONCURRED BY
APPROVED BY
Mr., CIV Solution Lead Systems Engineer Cybersecurity & Operational Services PEO Digital, Digital & Enterprise Services Marine Corps Systems Command
Deputy Portfolio Manager
Assistant Program Manager-Engineering (APM-ENG)
MCEN Director iii
Change History
The table below identifies all changes incorporated into the updated version of this document after initial approval. The System Specification is a configuration item and will be managed in accordance with the Network and Infrastructure (N&I) Configuration Management (CM) process. Updates to this document that are related to any significant changes in the project will go through the CM process for approval. The lead systems engineer may make minor updates, such as newer versions of figures and tables, as they become available. The following table contains a record of changes made to this document.
Change History Log
NEW OR
UPDATE
DATE
PUBLISHED /
REVISED
VERSION NO. AUTHOR
SECTION /
DESCRIPTION OF
CHANGE
New 18 October 2024 0.1 Document Established iv
Table of Contents
1. Scope
1.1 System Overview
1.2 Document Overview
2. Referenced Documents
2.1 Principle References
2.2 Federal Specifications, Standards, and Handbooks
2.3 DoD Specifications, Standards, and Handbooks
2.4 USMC Specifications, Standards, and Handbooks
2.5 Other Publications
2.6 Order of Precedence
3. Requirements
3.1 Alignment with NGEN
3.2 System Capability Requirements
3.3 System Interface Requirements
4. Verification
4.1 Verification
5. Notes
5.1 Definitions
5.2 Human Systems Integration
5.3 Security
5.4 Logistics
5.5 MCEN Sites
UNCLASSIFIED
1. Scope
This System/Subsystem Specifications (SSS) defines the required capabilities and characteristics of the End User Remote Access (EU RAS) solution within Marine Corps Enterprise Network
(MCEN).
1.1 System Overview
The EU RAS solution is an effort to modernize the previous MCEN remote access solution which was provided by a Virtual Private Network (VPN) solution that built an encrypted tunnel between the remote end user’s device, running client software, and the MCEN entry point. This provided the user access to internal MCEN resource once their device and the user were authenticated. Several vulnerabilities, in a short time span, led to the removal of these devices from operation to protect valuable resources from being targeted. The replacement solution will authenticate and authorize remote users and their devices and then allow access to MCEN resources without the vulnerabilities of a VPN type solution.
1.2 Document Overview
This document describes the specified and derived requirements for the EU RAS solution as it pertains to the USMC garrison and tactical networks. This document introduces the specifications the system will have to meet in order to be designed and integrated into the MCEN, interface with required MCEN systems / solutions, and be operated and sustained throughout its lifecycle.
Specifications for the solution will only be found in Table 3-1 and Table 3-2. Information outside of the previously listed tables should be considered informational only and not an official specification of the solution.
UNCLASSIFIED
2. Referenced Documents
The following specifications, standards, policies, and handbooks are applicable to the capability under development. Unless otherwise specified in the procurement acquisition document, the latest revision of these specifications and standards shall be adhered to within the solution (during development, testing, deployment, and operation). Dates and versions listed for each document reflect a point in time when the SSS was written. The latest published versions and documents that supersede these shall apply. Unless otherwise indicated, copies of federal/military specifications, standards, and handbooks are available from the Standardization Documents Order Desk, Bldg. 4D, 700 Robbins Avenue, Philadelphia, PA 19111-5094.
Department of Defense (DoD) documents listed, are in the issue of the DoD Index of Specifications and Standards. United States Marine Corps documentation is available through the Headquarters Marine Corps (HQMC) published through the Marine Corps Publications Electronic Library.
2.1 Principle References
Table 2-1, Principle References, lists the documents that serve as references to the EU RAS solution capability referenced throughout this document.
Table 2-1 Principle References
REF DOCUMENTATION DATE
a Next Generation Enterprise Network (NGEN) Capability Production Document (CPD) Version 1.5.7 15 Aug 2012
2.2 Federal Specifications, Standards, and Handbooks
Table 2-2 lists the federal specifications, standards, and handbooks that apply to the new EU RAS solution. They include Federal Information Processing Standard (FIPS) publications, Federal Standard (FED-STD), and other regulatory requirements.
Table 2-2 Federal References a FIPS PUB-200 Minimum Security Requirements for Federal information and Information Systems 01 Mar 2006 b Special Publication (SP) 800-53A Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Rev 4 18 Dec 2014 c FIPS PUB-140-2 Security Requirements for Cryptographic Modules 25 May 2001
UNCLASSIFIED
2.3 DoD Specifications, Standards, and Handbooks
There are no Department of Defense (DoD) specifications, standards, and handbooks that apply to the EU RAS.
2.4 USMC Specifications, Standards, and Handbooks
Table 2-3 contains the USMC specifications, standards, and handbooks that apply to the new EU
RAS.
Table 2-3 USMC Specifications, Standards, Policy, and Handbook
a. ECSM 020 Information Assurance Vulnerability Management Program 31 Dec 2013
b. ECSM 004 Remote Access Systems 1 Dec 2013
c. ECSD 021 Ports, Protocols, and Services Management 15 May 2012
d. ECSM 012 Cybersecurity Reference Architecture Framework 7 July 2021
e. ECSM 018 Marine Corps Assessment and Authorization Process 25 Jan 2024
2.5 Other Publications
There are no additional publications and specifications that apply to this solution.
2.6 Order of Precedence
In the event of a conflict between the text of this document and the references cited herein, the text of this document shall take precedence. Nothing in this document however, supersedes applicable laws and regulations.
UNCLASSIFIED
3. Requirements
This section contains system and subsystem specifications for the capabilities of the EU RAS solution. Specifications in this section provide detailed criteria that must be met to ensure the solution meets MCEN requirements. Table 3-1 and Table 3-2 provide the specifications for the solution. Other sections are provided for reference, context, and outline non-technical requirements. The scope of this project includes the immediate need for a Remote Access solution with the ability to enable Secure Service Edge (SSE) and Zero Trust Network Access (ZTNA) over time.
3.1 Alignment with NGEN
Capability requirements are taken from the documents referenced in Table 2-1 to define a required capability of the system and its components.
The solution must meet Sustainment (Availability)/Operational Availability Key Performance Parameters (KPP) and associated Key System Attributes (KSA). The KSAs within NGEN define requirements of network capabilities once a user is authenticated.
3.2 System Capability Requirements
The specifications derived from the current EU RAS solution are outlined below. Table 3-1 lists technical specifications derived from requirements from the NGEN CPD. Table 3-2 lists the specifications derived from the current EU RAS solution and the future SDP requirements, with a consideration also given to DoD Zero Trust (ZT) Activities and Headquarters Marine Corps (HQMC) Deputy Commandant for Information (DCI) Command, Control, Communications and Computers (C4) ZT user stories. These specifications are associated with the product, solution (the designed solution complete with configurations to enable deployment and activation of the identified feature or capability), and vendor (product vendor and third-party integrator).
UNCLASSIFIED
Table 3-1 SDP Specifications Mapped to Applicable NGEN KPPs and KSAs
CPD REF UNIQUE ID REQUIREMENT / SPECIFICATION TYPE
THRESHOLD
OBJECTIVE
VERIFICATION
METHOD
NGEN
CPD
NGEN Increment 1 Net-Ready KPP
NGEN must fully support execution of joint critical operational activities and information exchanges identified in the DOD Enterprise Architecture and solution architectures based on integrated Department of Defense Architecture Framework (DODAF) content, and must satisfy the technical requirements for transition to Net- Centric military operations to include:
Information assurance requirements including availability, integrity, authentication, confidentiality, and nonrepudiation and issuance of an Interim Authorization to Operate (IATO) or Authorization To Operate (ATO) by the Designated Accrediting Authority (DAA)
User Req’t NA NA
NGEN
CPD NNR0001
The solution shall have an Assessment and Authorization (A&A) through the MCEN Authorizing Official (AO) resulting in an Authority to Operate
(ATO).1
Derived Spec T Analysis
NGEN
CPD
NGEN Increment 1 Sustainment
KPP
The Sustainment of NGEN Increment 1 will be measured by the ability to be operationally available in two major areas, Network Connectivity and User Authentication Logon Services.
User Req’t NA NA
NGEN
CPD KPP2001
The solution shall not interfere with NGEN’s ability to meet the sustainment (availability) KPP.
Derived Spec T Analysis
1 This includes all accreditation dependencies (e.g. STIG and IAVA compliance, DADMS registration, etc.). The solution components and design shall comply with applicable STIGs, security configuration guides, and SRGs with any exceptions documented and approved by the responsible AO.
UNCLASSIFIED
CPD REF UNIQUE ID REQUIREMENT / SPECIFICATION TYPE
THRESHOLD
OBJECTIVE
VERIFICATION
METHOD
NGEN
CPD
NGEN Increment 1 Sustainment
KPP
Security Product Refresh shall be the time required to distribute new/revised security hardware and software after Enterprise Configuration Control Board (ECCB) or other Government forum approval. Note: These product updates shall have completed security testing and integration prior to implementation. This is not applicable to real-time security fixes that are mandated to be completed in shorter time frames (e.g., Information Assurance Vulnerability Alert [IAVA], Information Operations Condition
[INFOCON]).
How measured: Percentage of implementations completed within the ECCB approved timeframes
Metric(s): Not applicable
User Req’t NA NA
NGEN
CPD KPP3001
The software shall be upgraded to the latest verified version as approved by the
AO.
Derived Spec T Analysis
Table 3-2 Specifications Derived from References in Section 2 CPD Ref Unique ID Requirement / Specification Type Threshold
/ Objective Verification Method
General
NGEN CPD RAS0001 The system shall provide users secure access from external network connections to MCEN resources using approved DoD encryption ciphers
NGEN CPD RAS0002 The system shall support agent-based deployments for user workstations.
T
NGEN CPD RAS0003 The system shall be capable of on prem deployments T
NGEN CPD RAS0004 The system shall be capable of cloud deployments T
NGEN CPD RAS0005 The system shall be capable of physical deployments O
NGEN CPD RAS0006 The system shall encrypt data between the user and destination resource
NGEN CPD RAS0007 The system shall encrypt data between the user and the Policy Enforcement Point
UNCLASSIFIED
NGEN CPD RAS0008 The system shall encrypt data between the Policy Enforcement Point and the Policy Decision Point
NGEN CPD RAS0009 The system shall be capable of virtual deployments O
NGEN CPD RAS0010 The system shall operate at minimum of 5Gb/s throughput at each Policy Enforcement Point without traffic degradation
NGEN CPD RAS0011 The system shall be capable of continuously monitoring user activity
NGEN CPD RAS0012 The system shall support micro-segmentation principles
NGEN CPD RAS0013 The system shall feed User and Entity Behavior Analytics data to Detection and analysis tools
NGEN CPD RAS0014 The system shall natively employ User and Entity Behavior Analytics detection and reports alerts in real time
O
NGEN CPD RAS0015 The system shall allow for virtualization and integration into the enterprise architecture of all components
NGEN CPD RAS0016 The system should provide a hybrid architecture that allows for multi-cloud providers and on-prem deployments of PDPs and PEPs
NGEN CPD RAS0017 The system shall provide a policy decision point that tracks a confidence score (or equivalent) of a user and endpoint to either approve the identity, deny, challenge, reauthenticate or downgrade access to the requested resource
Policy Enforcement
NGEN CPD RAS0018 The system shall provide policy enforcement defined in the Policy Decision Point for remote connections with the ability to segment user traffic per session, application, or item
NGEN CPD RAS0019 The system shall provide policy enforcement defined in the Policy Decision Point for internal connections with the ability to segment user traffic per session, application, or item
NGEN CPD RAS0020 The system shall support agentless policy enforcement for non-credentialed network devices (IoT/oT)
NGEN CPD RAS0021 The system shall provide a policy enforcement point that executes segmentation policies and connects the user or endpoint to the requested resource
NGEN CPD RAS0022 The system shall provide network layer segmentation from the Policy Enforcement Point for user access based on defined policy
NGEN CPD RAS0023 The system shall ensure End User Devices possess valid machine certificates issued by the domain certificate authority prior to granting access to MCEN resources
NGEN CPD RAS0024 The system shall continuously check for changes in users access rights to MCEN resources
NGEN CPD RAS0025 The system shall continuously check for changes in device compliance
NGEN CPD RAS0026 The system shall continuously check for changes in device connection
NGEN CPD RAS0027 The system shall be able to quarantine access for non-compliant devices based on centrally defined policies
UNCLASSIFIED
NGEN CPD RAS0028 The system shall be able to quarantine access for non-compliant users based on centrally defined policies
NGEN CPD RAS0029 The system shall limit network access to endpoints prior to authentication supporting an "always on" model
NGEN CPD RAS0030 The system shall provide entity access authenticated via USMC implementation of DoD PKI
Administration
NGEN CPD RAS0031 The system shall be configurable to provide granular least privilege administrator access between multiple operation groups
NGEN CPD RAS0032 The system shall be configurable to provide granular least privilege administrator access between multiple regions
NGEN CPD RAS0033 The system shall provide system administrator access authenticated via USMC implementation of DoD PKI
NGEN CPD RAS0034 The solution shall support the capability for web-based access to a centralized management GUI
NGEN CPD RAS0035 The system shall be configurable by administrators to back up configurations automatically
NGEN CPD RAS0036 The system shall be capable of backing up configuration files to a remote server
NGEN CPD RAS0037 The system shall integrate with the MCEN architecture and enterprise services to include Identity solutions, SDWAN, SDN solutions
NGEN CPD RAS0038 The system shall provide access to policy creation and maintenance, logging, and monitoring functions via secure, open application programming interfaces (APIs)
NGEN CPD RAS0039 The system shall integrate with or meet the requirements of MCEN Compliance to Connect system(s)
Compliance
NGEN CPD RAS0040 The system shall be FIPs 140.2 certified T
NGEN CPD RAS0041 The system shall be FIPs 140.3 certified O
NGEN CPD RAS0042 The system shall be configurable to limit available ciphers to only FIPs certified variants
NGEN CPD RAS0043 The system SaaS component(s) shall be approved for use in DOD IL-5 T
NGEN CPD RAS0044 The system SaaS component(s) shall be approved for use in DOD IL-6 O
NGEN CPD RAS0045 The system shall comply with the requirements of the NIAP program in accordance with NSA approved processes
NGEN CPD RAS0046 The system shall provide root level access credentials for the purposes of vulnerability scanning and management
High Availability
NGEN CPD RAS0047 The system shall support globally distributed Policy Enforcement Points across the MCEN providing High Availability failover without manual intervention
UNCLASSIFIED
NGEN CPD RAS0048 The system shall support globally distributed Policy Decision Points across the MCEN providing High Availability failover
NGEN CPD RAS0049 The system shall support operations in disadvantaged sites with limited or intermittent access to DoDIN or Cloud resources
NGEN CPD RAS0050 The system shall be able to operate on last known policy and configuration
NGEN CPD RAS0051 The system shall provide disaster recovery of user and management traffic
NGEN CPD RAS0052 The system shall be scalable to support up to 150,000 total concurrent users
NGEN CPD RAS0053 The system shall be able to fail over to a minimum of 2 other locations to maintain availability for a failed device
Logging
NGEN CPD RAS0054 The system shall support encrypted remote log forwarding via SYSLOG
NGEN CPD RAS0055 The system shall support remote logging integrations with KAFKA
NGEN CPD RAS0056 The system components shall transfer collected logs in near-real-time to remote repository or log collection SIEM
NGEN CPD RAS0057 The system components shall be capable of transmitting syslog data to a minimum of two (2) syslog servers
NGEN CPD RAS0058 The system shall be capable of filtering the transmission of logs/events by log/event type and forwarding to multiple specific logging systems
NGEN CPD RAS0059 The system components shall be capable of generating audit logs that reflect connection, configuration changes, and log-in attempts
NGEN CPD RAS0060 The system shall be capable of continuously monitoring and logging all transactions including permitted and denied requests for access to protected resources
System
NGEN CPD RAS0061 The system shall be capable of obtaining Network Time Synchronization (NTS) from a minimum of two sources utilizing Network Time Protocol version 4 (including latest ratified RFC 5905) supporting Stratum III
NGEN CPD RAS0062 The system shall ensure system components are synchronized to an authoritative time source within +/- 1 msec
NGEN CPD RAS0063 The system shall utilize Symmetric Key Authentication per latest ratified RFC 5905 with NTP source
NGEN CPD RAS0064 The system shall be capable of synchronizing timestamps to network time in Coordinated Universal Time (UTC)
NGEN CPD RAS0065 The system shall be deployable in a method to minimize datacenter footprint per hosted location
NGEN CPD RAS0066 The system devices shall have N+1 redundant 100–240 VAC (50–60Hz) auto-sensing power supply configurations with detachable power cords
NGEN CPD RAS0067 The system devices shall be rack mountable on standard 19-inch rail rack
UNCLASSIFIED
NGEN CPD RAS0068 The system devices shall be rack mountable within a standard 39" depth rack enclosure cabine
NGEN CPD RAS0069 The system hardware shall provide 10Gb/s ethernet LC fiber interfaces O
NGEN CPD RAS0070 The system components shall be designed to prevent the introduction of unauthorized code into privileged programs or system libraries
NGEN CPD RAS0071 The system components shall be designed to validate system updates prior to installing them for windows, iOS, and Linux endpoints
NGEN CPD RAS0072 The system components shall be designed to stage system update deployments
NGEN CPD RAS0073 The system components shall be designed to protect stored passwords with acceptable encryption algorithms
NGEN CPD RAS0074 The system components shall be designed to restrict access to the encrypted passwords to appropriate administrators
3.3 System Interface Requirements
The solution will need to interface with the existing MCEN infrastructure and enterprise services to ensure proper functionality. The interfacing systems are listed Table 3-3. Table 3-3 identifies each interface, the purpose of the interface, and the direction of the data flows.
Table 3-3 SDP Solution Interfaces
System Interface Purpose Direction
Active Directory / Entra ID Provide user authentication and authorization data to the Policy engine
Bi-Directional, Inbound and
Outbound
DNS Provide IP to Hostname resolution to the solution components
Bi-Directional, Inbound and
Outbound
NTP Time synchronization Bi-Directional, Inbound and Outbound
Syslog Server Solution Logs will be forwarded to the Syslog server for processing Inbound
Enterprise resources
The Policy Enforcement point will provide communication between the resource and the user once their authentication and authorization are validated
Bi-Directional, Inbound and
Outbound
UNCLASSIFIED
4. Verification
4.1 Verification
The verification process confirms that a system element meets design-to and build-to specifications defined in section 3. Throughout the system’s lifecycle, design solutions at all levels of the physical architecture are verified through a cost-effective combination of analysis, examination, demonstration, and testing, all of which can be aided by modeling and simulation.
Verification of requirements will be conducted to ensure performance and functionality of the system meet requirements in this document. The verification method for each specification can be found in Section 3 based on the following definitions.
4.1.1 Examination. The visual examination of the system, component, or subsystem.
Examination is a qualification method based on the visual examination of system hardware, software, and documentation.
4.1.2 Analysis. Analysis is a qualification method based on the processing of accumulated data obtained from other qualification methods.
4.1.3 Demonstration. Demonstration is a qualification method based on observable functional operation of the system not requiring the use of instrumentation, special test equipment, or subsequent analysis.
4.1.4 Test. Testing is a qualification method based on operation of the system and the related use of instrumentation or other special test equipment to collect data for later analysis.
UNCLASSIFIED
5. Notes
5.1 Definitions
Table 5-1: Definitions
TERM DEFINITION
Administrators A privileged user with access to the systems hosted on the mcdsus.usmc.mil domain.
Component A piece of hardware or software that is part of the system and performs a specific function that contributes to the overall capability of the solution.
MCEN
The Marine Corps enterprise infrastructure and services required to provide any approved user connectivity and access to required resources.
Policy Decision Point A component of the solution that evaluates access requests to resources, validates the authentication and authorization of the user and/or device and either allows or denies the request.
Policy Enforcement Point
A component of the solution that receives the authenticated and authorized user request to a resource and brokers the connection between the user and the resource and continually checks that the user status has not changed.
System The totality of all components properly configured to meet all the specifications identified.
User Individual accessing the MCEN enclave.
5.2 Human Systems Integration
5.2.1 Manpower
Currently the EU RAS solution imposes no new requirements on manpower, however, additional manpower could be required depending on the equipment and/or software procured.
5.2.2 Training
Training should be evaluated with each new solution and obtained whenever that evaluation indicates that the new hardware and/or software with new features has been procured. Training of personnel should be a fundamental practice for keeping the Government workforce abreast of the new technology and security features on all systems.
5.2.3 Human Factors Engineering
No human factors engineering will be performed for the solution. There is minimal human interaction with the solution; the human-machine interface will use best practices for monitor and administrator input device placement on a workstation in accordance with NGEN approved human factors engineering (HFE) guidelines. The network administrators will administer each device individually through Graphical User Interface (GUI) and Command Line Interface (CLI).
UNCLASSIFIED
5.3 Security
5.3.1 Security Requirements
The solution will be evaluated for security requirement compliance based on specifications listed in Section 3. This system is required to be FIPS 140-2 compliant and use equipment listed on the DoDIN Unified Communications Approved Products List (UC APL). The system should have completed both the information assurance and inter-operability testing. The completed solution will be compliant with applicable STIGs as defined by the cybersecurity plan and validated during the USMC A&A process.
5.3.2 Physical Security
Equipment used in the solution will be consistent with the base, post, or station’s physical security plan.
5.3.3 Personnel Security
Personnel responsible for the operation of the solution will be certified as part of the Cybersecurity Workforce.
5.4 Logistics
The solution will be incorporated into the enterprise solution portfolio. PEO Digital will retain sustainment responsibility. Asset accountability will be transferred to the MCCOG. The following sections describe the integrated product support requirements for the SDP solution.
5.4.1 Maintenance Planning
Maintenance planning includes:
• Diminishing Manufacturing Sources and Material Shortages (DMSMS) planning and mitigation
• Configuration Management
• Operational metrics collection and analysis
• Asset Accountability in Defense Property Accountability System (DPAS)
• Packaging, Handling, Storage and Transportation Marking will be performed in accordance with applicable contracts.
5.4.2 Technical Data
Technical data for the solution includes all design, implementation, training, and sustainment documentation created by the Government and vendor. All technical data will be held in the Government’s Definitive Media Library (DML) or other Government authorized locations.
5.4.3 Support Equipment
Support equipment will include a scaled solution for remote access services in the support environment. This will allow the Government to perform policy integration and testing prior to deployment. The support environment will be housed in the EEVE lab and used for sustainment engineering for the remaining lifecycle. This equipment is part of the solution and will be maintained as part of the acquisition contract.
UNCLASSIFIED
5.4.4 Facilities and Infrastructure
The solution will be installed in facilities where network equipment resides. The solution will not impact existing facilities or infrastructure. Facilities Impact Report (FIR) will be required for each location that the solution is installed to determine if the facility and infrastructure will support the new switches.
Equipment mounted in racks must fit in 19” standard equipment racks. Power cables will connect to rack mounted power distribution units supported with facility uninterruptable power supplies (UPS). Power will comply with National Fire Protection Agency (NFPA) 70: National Electrical Code. Equipment will have multiple network ports to support failover and potential expansion within each site.
5.5 MCEN Sites
An analysis will be conducted for each MCEN site and tactical use case to determine the appropriate sizing and placement of the solution components.
| 1. Scope |
| 1.1 System Overview |
| 1.2 Document Overview |
| 2. Referenced Documents |
| 2.1 Principle References |
| 2.2 Federal Specifications, Standards, and Handbooks |
| 2.3 DoD Specifications, Standards, and Handbooks |
| 2.4 USMC Specifications, Standards, and Handbooks |
| 2.5 Other Publications |
| 2.6 Order of Precedence |
| 3. Requirements |
| 3.1 Alignment with NGEN |
| 3.2 System Capability Requirements |
| 3.3 System Interface Requirements |
| 4. Verification |
| 4.1 Verification |
| 4.1.1 Examination. The visual examination of the system, component, or subsystem. Examination is a qualification method based on the visual examination of system hardware, software, and documentation. |
| 4.1.2 Analysis. Analysis is a qualification method based on the processing of accumulated data obtained from other qualification methods. |
| 4.1.3 Demonstration. Demonstration is a qualification method based on observable functional operation of the system not requiring the use of instrumentation, special test equipment, or subsequent analysis. |
| 4.1.4 Test. Testing is a qualification method based on operation of the system and the related use of instrumentation or other special test equipment to collect data for later analysis. |
| 5. Notes |
| 5.1 Definitions |
| 5.2 Human Systems Integration |
| 5.2.1 Manpower |
| 5.2.2 Training |
| 5.2.3 Human Factors Engineering |
| 5.3 Security |
| 5.3.1 Security Requirements |
| 5.3.2 Physical Security |
| 5.3.3 Personnel Security |
| 5.4 Logistics |
| 5.4.1 Maintenance Planning |
| 5.4.2 Technical Data |
| 5.4.3 Support Equipment |
| 5.4.4 Facilities and Infrastructure |
5.5 MCEN Sites
File details come from the government source that posted it. Updated .