Attachment 12 Div 25 Integrated Automation 6 June 13.pdf

PDF 2 MB Posted

Attached to
CRAH Power Diversity Federal contract opportunity
Solicitation number
HC102821R0061
Issued by
Defense Information Systems Agency

About this file

This document outlines requirements for a federal contract to provide redundant power sources to computer room air handling (CRAH) units in a data center. The contractor will purchase and install retrofit kits to enable each CRAH unit to accept dual power inputs. Additional distribution panels will also be installed to supply the new feeds. The Defense Information Systems Agency is seeking these upgrades to improve power diversity for critical cooling equipment supporting its data center operations.

View the file

Other files for this federal contract opportunity

Show all 15

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Div 25 Integrated Automation

25 00 00 Integrated Automation

The government will receive the right to use for a government purpose any intellectual property or technical data created under this contract including data and software as a government purpose license or as a nonexclusive, non transferable, paid up license to practice or have practiced such inventions throughout the world.

All infrastructure equipment and all HVAC systems for administrative, mechanical plant and datacenter areas shall be monitored and controlled through a facility Building Automation System (BAS). ). All installation, connection of new equipment, and maintenance on BAS systems and components shall be conducted solely by the enterprise BAS Service Provider

DISA has BAS equipment installed at multiple datacenter facilities and intends to continue the expansion of these systems through the enterprise.

The BAS, also known as an integrated automation system, consists of the hardware and software necessary to provide monitoring and control of infrastructure equipment and systems that support the facility.

The purpose of this Division is to define the configuration, interaction, and materials for the connection, monitoring, user interface and reporting of electrical systems, life safety systems and mechanical plant DDC systems (specified in Division 23).

All project engineers, managers, designers, installers and operators of mechanical, electrical systems and direct digital control systems shall understand and comply not only with this division, but must understand, design, install, operate and implement the integrated automation equipment in unison with the products and requirements outlined in Division 23.

The Design Engineer of Record for all infrastructure equipment installation, replacement and upgrade projects shall use the requirements outlined in this document to develop for DISA’s review and approval an Integrated Automation Specification (25 00 00).

The requirements outlined in this Division pertain specifically to new integrated automation systems as well as the repair of legacy systems.

The installing contractors Program Manager shall work closely with the ES521 BAS program manager and ES52 implementation lead to coordinate the installation on the DISA network, Information Assurance activities, BAS and DISA network access and all repairs impacting the communications or software components of the system.

New and Legacy Integrated Automation Systems Legacy systems are systems that were installed prior to June 2012. These systems are to be maintained and repaired by the original equipment manufacturer utilizing best industry practices for the installed systems.

The programming section of this Division shall be utilized to determine trending, graphics, and alarming requirements for all new and legacy systems.

The network section of this Division shall be utilized to design, configure and install the BAS-L network.

When the project contract or statement of work requires that the DDC system be connected to an existing Iconics Genesis 32 system, the references in this document to Iconics Genesis 64 shall be substituted with Iconics Genesis 32.

All existing Iconics Genesis 32 systems shall NOT be connected to a DOD or DISA network. In these existing systems, all BAS-L and BAS-G components reside in the BAS-L system architecture.

25 01 00 Installation, Operation and Maintenance of Integrated Automation

Management of Building Automation Systems The Chief of Facilities Engineering (ES521) shall designate a person to serve as the BAS Program Manager. The BAS Program Manager shall:

• Interface with ES521 personnel for BAS oversight and information assurance posture

• Manage the BAS program

• Serve as the Contracting Officer’s Technical Representative (COTR) and/or Task Monitor (TM) for BAS installation, maintenance, and repair contracts

• Coordinate Engineering project, O&M program, and equipment programming needs

• Serve as the gatekeeper for user access and Enterprise Level Operator system changes

Integrated Automation Enterprise Contract

ES521 shall maintain a contract to maintain, repair, and install the integrated automation systems outlined by this section and Division 23. The contract shall be able to deliver integrated automation services (installation, modification, preventative maintenance, and repair) to all facilities and BAS systems under the purview of ES521.

All installations, connections of new equipment, and maintenance on systems & components shall be conducted solely by the enterprise integrated automation Service Provider. No other Service Provider shall be authorized to install equipment upon, modify, or otherwise interfere with these systems because of security, contract, and warranty obligations.

The ES521 BAS Program Manager shall work closely with the ES5 implementation lead to coordinate the installation on the DISA network, Information Assurance activities, BAS and DISA network access and all repairs impacting the communications or software components of the system.

Access to Building Automation Systems

All operators, installers and repairers requesting access to a DISA BAS system shall request access via DD form 2875. The DD2875 shall be submitted to the ES521 BAS Program Manager no less than 60 prior to access being needed.

Compliance with DoD Instruction 8500.1 and 8500.2

The products, configurations and materials outlined in Division 25 and Section 23 09 23 have been considered compliant by DISA with DoD instruction 8500.1 and 8500.2.

Deviations from the products, configurations, installation requirements or materials listed in Division 25 and Section 23 09 23 are not permitted without written approval from the Chief of Facilities Engineering (ES521) and DISA’s Enterprise Services Directorate Information Assurance Manager for Networks and Applications. Acceptance of a proposal by the Government that does not clearly indicate the materials, products, installation methods and configurations used to develop the proposal does not relinquish the bidder from compliance with Division 25 Section 23 09 23, DOD instruction 8500.1 or DOD instruction 8500.2.

Designers and installers shall ensure that all software installed on the BAS-G hardware is compliant with the most current DOD instruction 8500.1, DOD instruction DOD 8500.2 and Security Technical Implementation Guides (STIG).

The installing contractor shall document all STIG settings, configurations and provide POAMs for all Category I, II and III findings for DISA review, validation, and acceptance. All STIG items shall be documented and tracked in an excel spreadsheet.

All BAS-L switch configurations shall be documented via screen shots and in writing by the installing contractor on company letterhead to the contracting officer and the DISA implementation team. This documentation shall be made for every instance that the installing contractor connects to the switch via their company owned PC. Once the switch has been connected to the DoD network, no company owned or non government owned computers may be connected to the switch or BAS-L network.

Security Requirements for Designers, Installers, Operators, and Repairers

Designer Security Requirements

The designer of the BAS shall maintain a security clearance in compliance with applicable contract documents that the design is being performed under.

BAS Operator, Installer, and Repairer Security Requirements

All operators of the BAS shall posses and maintain a valid Secret security clearance with IT-II access.

All installers and repairers, not needing access to the operating system root configurations of the BAS, shall posses and maintain a valid Secret security clearance with IT-II access.

All installers and repairers, needing access to the operating system root configurations of the BAS, shall posses and maintain a valid Secret security clearance with IT-I access.

All operators, installers, and repairers shall complete DOD information assurance training annually.

Pre-Production Environment

DISA will maintain a simulated BAS system in the Enterprise Services Pre-Production environment. The BAS pre production system will be used to test software updates for compliance with DoDI 8500.2 and system reliability prior to installing the updates into the BAS production environment (BAS-G).

The pre-production environment will simulate the production environment with the exception that it will use a simulated database versus being connected to in-service facilities infrastructure systems.

Operator Levels

All Facility Managers and appropriate O&M Service Provider personnel shall be trained as operators of the BAS for the facility. The following operator levels are the minimum required per DECC:

• One (1) Government Facility Manager capable of performing the functions of a Site Level Operator.

• One (1) O&M Service Provider per shift (24x7 coverage) capable of performing the functions of a Site Level Operator.

• One (1) O&M Service Provider on staff capable of performing the function of a Site Level Configuration.

• All other site Facility Management personnel and O&M Service Provider staff shall be capable of performing the function of a Site Level Viewer.

ES521 shall have not less than two (2) personnel trained to perform the functions of Enterprise-Level Operator and not less than two (2) to perform the function of Enterprise- Level Configuration. The same personnel can fulfill both functions.

BAS installers and integrators shall ensure that software configuration or programming supports and is set up to place approved operators into user groups that align with the operator levels.

25 01 20 Installation, Operation and Maintenance of Integrated Automation Network Equipment

25 01 30 Installation, Operation and Maintenance of Integrated Equipment

25 05 00 Common Work Results for Integrated Automation

Concept of Operations (CONOP) for Integrated Automation and DDC Systems

ES521 BAS systems are comprised of three sub-systems: A DDC system, a local BAS network (BAS-L), and an enterprise wide network (BAS-G). Of the three systems, the DDC and BAS-L are local to the particular facility while the BAS-G system has local components as well as components spread across the enterprise.

DDC CONOP

The concept of operations for the DDC systems is that the control and monitoring of site HVAC equipment will reside within the DDC controllers and network as outlined by Section 23 09 23.

The DDC system will communicate HVAC status to the BAS-L network as well as receive operator-initiated changes to the HVAC systems (i.e., setpoints, lead/lag, alarm acknowledgement) that originate in the BAS-G network. In the DDC system there is a single operator workstation that is to be used as the main point for programming for the DDC system and as an emergency operator’s workstation in the event of a failure in the BAS-G network. The DDC systems network will be directly connected to the BAS-L network and not to any other

DISA network. The integrator or DDC installer shall provide all materials and labor for the DDC system design and installation.

BAS-L CONOP

The concept of operations for the BAS-L system is to provide a network within the facility that provides the means to interconnect, control, and/or monitor the site life safety systems, electrical, and HVAC systems. The BAS-L network will have network connections to the BAS-L (subnets) and the BAS-G network. The BAS-L network contains infrastructure equipment (UPS, chiller, etc), network switches and an aggregation switch that provides:

o Local Network for all infrastructure systems o Aggregation switch for communication of data from BAS-L Network to BAS-G Network

The BAS-L network will contain a Virtual Operating Environment (VOE) server that will have network connections to the BAS-L network and the BAS-G network. ES521 will provide the VOE server for this portion of the system and the communication switch that links the VOE server with the BAS-G network. The installing contractor is to provide the aggregation switch for DISA’s configuration and installation onto the DISA network.

BAS-G CONOP

The concept of operations for the BAS-G system is to provide an enterprise-wide network that links individual site BAS-L and BAS-G systems. The BAS-G shall communicate with individual site BAS-L networks, provide the connection point for site and remote operator workstations (individual computers), provide data to the DISA enterprise monitoring tools/teams, and provide information to the DISA enterprise DCIM tool. BAS-G contains enterprise BAS networking, storage, reporting, and database components. The BAS-G will contain the local (to each site) Gen-64 server, local and remote operator workstations, enterprise BAS storage, reporting and database components. DISA has assigned system and database administrators to assist with the sustainment and installation of BAS-G software.

The connection between the BAS-G network and the BAS-L network is accomplished via a 48 port switch referred to as the aggregation switch. The switch is provided by the BAS installer.

The BAS Service Provider shall provide labor to install, configure and test the software on the DISA provided hardware. The installing contractor shall anticipate working with DISA storage, communication, processor and application engineers and administrators to ensure an operable system for the following items

• Web based software (STIG Compliant)

• Operator graphics

• Alarming;

• Trending

• System monitoring

• Email notification

• The software links between the BAS-L system and the BAS-G systems

• Alarming to Formula (DISA monitoring tool)

Graphical representation of BAS subsystem and Application interrelationships.

Submittals

All BAS submittals shall follow the requirements outlined in Section 23 09 23.

The installing integrator shall coordinate with all project disciplines prior to any mechanical, electrical or life safety submittal to ensure that the provided equipment can be integrated with the protocols shown.

Design Requirements

All BAS designs shall follow the requirements outlined in Section 23 09 23.

All submitted drawings shall comply with the requirements of Section 01 78 39 and the Record Drawing Configuration Management (CM) Specification.

The installing integrator shall coordinate with all project disciplines prior to any mechanical, electrical or life safety submittal to ensure that the provided equipment can be integrated with the protocols shown.

25 05 13 Conductors and Cables for Integrated Automation

Government Provided Equipment – For Use by Government Only

All cabling between the aggregation switch, the Gen 64 server and the government network will be provided and installed by the government. The installing contractor will have no access to these devices or cable.

Cabling

The designer of record is to provide for government review and acceptance detailed cable specifications. The designer of record shall utilize the governments cabling standard to assist in developing the cabling specifications.

All Ethernet cabling shall in accordance with EIA/TIA-568-C.

All Ethernet terminations shall use T568A pin/pair assignments.

All cable shall be plenum rated.

All Ethernet cabling, patch panels and wall jacks shall be rated CAT 6E.

All RS485 cabling shall be half duplex, 2 wire configuration and must be in accordance with EIA/TIA-485-A Label all network wiring so that the labels are readable without having to disconnect or manipulate the wire to make the label legible.

All network wiring shall be labeled with “BAS Cable” every 24 inches by the cable manufacturer as part of the wire manufacturing process.

Wire insulation and jacket color for the network shall comply with the following table:

Equipment Connected

Wire Jacket Color

Ethernet Blue MSTP, Modbus Orange

Network power wire shall be sized per NFPA 70 and with wire jacket/insulation colored as shown below

Equipment Connected

Wire Jacket Color Comments Additional Information

DC Power – Network Equipment

Blue/Brown Brown is positive conductor. The color is the conductor insulation color, not a jacket color

A bus source

Red/White Red is positive conductor. The color

B bus source is the conductor insulation color, not a jacket color

25 05 28 Pathways for Integrated Automation

25 05 28.29 Hanger and Supports for Integrated Automation

25 05 28.33 Conduits for Integrated Automation

25 05 28.36 Cable Trays for Integrated Automation

25 08 00 Commissioning, Training and Warranty of Integrated Automation

Commissioning

The Contractor shall create a commissioning plan that demonstrates compliance of the control system work with the design and contract requirements. The commissioning plan shall be performed by the Contractor and witnessed and approved by the Government. If the project is phased, provide separate testing for each phase.

The Contractor’s commissioning plan shall be compliant with the requirements in Section 01 91 00 (Commissioning).

Training

Each new system installation project shall train the site facility managers and site O&M Service Provider(s) to permit the individuals of being added to user group Site Level Operator. See Section 01 91 00 (Commissioning) for additional BAS training requirements.

The integrated automation enterprise contract shall regularly provide centralized training for personnel throughout the enterprise to be trained to the appropriate user level.

Warranty

All BAS system installations and repairs shall have a one-year warranty fully covering all parts, labor, and travel for all Contractor-provided materials and services.

25 10 00 Integrated Automation Network and Equipment

BAS-L Network Architecture

The system provided shall incorporate hardware resources sufficient to meet all functional requirements. The BAS installer or Service Provider shall include all items not specifically itemized herein necessary to implement, maintain, and operate the system in compliance with the functional intent of these Standards.

All RS485 subnets shall be linear, multi-drop configuration. Start or ring MSTP topology is not permitted.

The system(s) shall be configured as a distributed processing network(s) capable of expansion as specified below.

A multi-level local area network (LAN) utilizing Rapid Spanning Tree Protocol (RSTP) shall be created to provide an N+1 redundant LAN for the facility. The network shall be contained within the facility.

The RSTP network shall connect to the DoD Network through a VLAN and the 48 port aggregation switch. The VLAN will be created by DISA on the DoD network. The BAS installer shall configure the BAS-L network to operate with the VLAN. VLAN information will be provided to the BAS installer once the installer has:

• Received Notice to Proceed from the contracting officer

• Provided Security information to DISA

• DISA confirms security

• Written request is provided by BAS installer to contracting officer

• All submittals have been submitted, reviewed and approved by DISA and the contracting officer

The site infrastructure equipment shall connect to the RSTP LAN as follows:

• Utility Electrical Metering – Radial connection per utility meter; utility meters may share the same radial path.

• UPS Systems – Radial connection per UPS bus; UPS buses shall not share same radial path or switch.

• Chiller Plant (computer rooms) – Radial connection per chiller plant DDC control system;

chiller DDC control systems shall not share same radial path or switch. There shall be no single points of failure in the networking for these systems.

• Condenser Plant (computer rooms) – Radial connection per condenser plant DDC control system; condenser DDC control systems shall not share same radial path or switch. There shall be no single points of failure in the networking for these systems.

• Critical Power Distribution – Radial connection per critical bus; multiple components from the same critical bus (i.e., bus A) can share the same radial path and switch although.

Components from alternate buses (i.e. A and B) shall not share the same path or switch.

• Essential Power Distribution – Radial connection per Essential bus; multiple components from the same essential bus (i.e., bus C) can share the same radial path and switch.

• Life Safety Equipment – Radial Connection; all life safety equipment can share the same radial path if connection to the path makes economical and logical sense.

• Generators – Radial connection per generator bus when the generator bus is configured in a 2N fashion. When a 2N configuration exists, multiple components from the same generator bus (i.e., bus A) can share the same radial path and switch. There shall be no single points of failure in the networking for these systems. Components from alternate buses (i.e. A and B) shall not share the same path or switch. All other generator configurations shall use a radial path.

• CRAC Units –Radial connection. Group similar rooms to the same radial connection.

• UPS Room and Battery Room HVAC systems - Radial connection per type of HVAC system when the HVAC systems are configured in a 2N fashion

• Administrative HVAC systems –Radial connection. Group similar rooms to the same radial connection.

The communication speed between the DDC system(s), LAN interface devices, and operator interface devices (Graphics) shall be sufficient to ensure fast system response time under any loading condition. The BAS Service Provider shall submit guaranteed response times with shop drawings including calculations to support the guarantee. In no case shall delay times between an event, request, or command initiation and its completion be greater than those listed herein. The BAS Service Provider shall modify their BAS control design as necessary to accomplish these Not-To-Exceed (NTE) performance requirements:

• 5 seconds between a Level 1 (critical) alarm occurrence time delay expiration and enunciation at operator workstation.

• 10 seconds between a Level 2 alarm occurrence time delay expiration and enunciation at operator workstation.

• 20 seconds between a Level 3-5 alarm occurrence time delay expiration and enunciation at operator workstation.

• 10 seconds between an operator command via the operator interface to change a setpoint and the subsequent change in the controller.

• 5 seconds between an operator command via the operator interface to start/stop a device and the subsequent command to be received at the controller.

• 5 seconds between a change of value or state of an input and it being updated on the operator interface.

• 10 seconds between an operator selection of a graphic and it completely painting the screen and updating at least ten (10) points.

• 1 second between an alarm becoming active in the Iconics Genesis 64 system and its communication to BAS-L monitoring tools.

All data throughout any level of the network shall be available to and available by all other devices or controllers whether directly connected or connected remotely.

All switches must have a minimum of three unused ports that are to be labeled as spares.

Above drop ceilings or hard walled surfaces utilize J-hooks to support the cabling. When feasible, bundle DDC and other BAS cables in the same J-hook.

The figure below is a typical high-level network architecture as described in this Section.

BAS-L Network Architecture Equipment

Government Provided Equipment – For Use by the Installer and the Government

One (1) Information Technology Rack with:

• Two 120V in Rack Metered Power Distribution Units

• Two branch circuits (whips) to the IT cabinet from diverse critical power sources

• No government provided switches or servers will reside in this IT rack.

• The aggregation switch will reside in this IT rack.

Switches

Provide one aggregation switch and the necessary quantity of SIXNET switches to deliver a complete and usable BAS system.

Aggregation Switch – the BAS installer shall purchase and mount in a government furnished information technology rack in the sites main computer room. The switch shall be a CISCO 4948 with the following configuration and options:

• Catalyst 4948

• Optional SW

• 48 Port, 10/100/1000+4 SFP,

• S49LB-12253SG

• CISCO CAT 4900 IOS BAS W/O Crypto

• NOS 24X7X4 C4948, optnl sw 48Pt SFP

• Dual power supplies, hot swappable

• NEMA 5-15 power cords

Provide industrial grade managed network switch with the appropriate port quantities and the following options:

MFG: Sixnet – SLX Series Only

Standard Compliance: UL508/CSA C22.2/14; EN61010-1,CE EMI Emissions FCC Part 15, ICES-003; EN6100-6-4, CE EMC Immunity IEC6100-6-2, CE Hazardous Locations UL 1604 Eye Safety (Fiber Models) IEC60825-1 IEEE 802.3 (10mBPS Ethernet – Legacy devices) IEEE 802.3u (Fast Ethernet 100Mpbs – newer devices IEEE 802.3x (Full Duplex with flow control) IEEE 802.1D/w (Rapid Spanning Tree)

Power: Redundant Power DC Spike Protection – 5000W Transient Protection - 15,000 watts

Performance: Rapid Spanning Tree

SNMP V3

SNMP notifications (traps) for report event

Environmental: Operating temperature -40 to +75 deg C Humidity (non condensing) 5 – 95% RH

Ethernet: RJ45 ports (shielded) 10/100Base TX RJ45 speed (10 or 100M) auto-negotiation

Ports 8 Ports minimum per switch

Mounting: Din Rail

Warranty: 5 Year

Network Cabinets

All network cabinets shall be UL 509A listed.

All network cabinets shall be hinged on one side

All network cabinets shall be ANSI Grey in color

All network cabinets shall be installed with a tamper proof hasp and lock. All locks shall be keyed alike.

All components in the network cabinet shall be organized to support ease of installation, equipment identification and maintenance.

All network cabinets shall use an internal raceway for routing of power and communication cabling. Power cabling shall be separated from data cabling.

Spare Parts

Label the packaging for all spare parts with their manufacturer’s part number and nomenclature.

Provide the following spare parts with each site BAS system:

o One managed RSTP Switch o One managed Non-RSTP Switch o One DC Power supply o One of each type of input/output device o Two of each type of fuse used

25 10 10 Network Equipment Installation

Aggregation Switch

Install, but do not power on the aggregation switch in the government provided IT rack.

Notify in writing the contracting officer and DISA that the switch has been installed and is ready for DISA cabling and configuration. In the notification, provide the switch make, model and serial number along with the IT rack location.

Network Cabling

All network wire run in a mechanical or electrical room/space shall be installed in Green colored electric metallic tubing.

Use of existing DISA cable trays is acceptable when the routing of the cable (wire) from the cable tray to the infrastructure item of equipment presents a neat appearance and is protected along the path between the cable tray and the equipment. For example no wire shall exit a cable tray and travel in open air to the infrastructure equipment.

All network wire run in a computer, telecommunications, or data center room/space shall follow the DISA cabling installation guide. Exceptions to this requirement are when the existing cable tray is not (typical) installed over a infrastructure item of equipment (CRAC, PDU, In row cooler).

When DISA installed cable tray is NOT used, all cabling shall be routed under the raised floor (when installed) or overhead in an approved raceway. Approved raceways are cable trays and blue colored electric metallic tubing.

All penetrations along the network path shall be sealed with fire rated material.

All network terminations shall comply with the DISA cabling standard.

Above drop ceilings or hard walled surfaces utilize J-hooks to support the cabling. When feasible, bundle DDC and other BAS cables in the same J-hook.

BAS-L Network Switches

Install BAS-L network switches in Network cabinets.

Configure BAS-L network switches as outlined in the BAS-L Sixnet Switch Configuration Document. The document will be provided to the BAS once the installer has:

o Received Notice to Proceed from the contracting officer o Provided Security information to DISA o DISA confirms security o Written request is provided by BAS installer to contracting officer o All submittals have been submitted, reviewed and approved by DISA and the contracting officer

BAS-L Network Cabinets

Install BAS-L network cabinets in rooms that are secured by either a lock and key or a security system. Network cabinets shall not be installed in hallways, dining areas, offices, conference rooms, janitor closets, restrooms, warehouses, storage rooms.

Port and IP Address Documentation

All ports and equipment IP addresses shall be documented in the IP request spreadsheet. No aggregation switch ports will be opened until all port and IP address information is provided to DISA via the contracting officer. The spreadsheet will be provided to the BAS once the installer has:

• Received Notice to Proceed from the contracting officer

• Provided Security information to DISA

• DISA confirms security

• Written request is provided by BAS installer to contracting officer

• All submittals have been submitted, reviewed and approved by DISA and the contracting officer

25 11 00 Integrated Automation Network Devices

25 11 13 Integrated Automation Network Servers

Government Provided Equipment – For Use by BAS Installer

All servers in the BAS-G portion of the system will be provided and installed by DISA for the installing to install the software on. The hardware consists of the following items:

• New Virtualized Operating Environment Server – Gen 64 for each site

• Virtualized Operating Environment Servers – BAS-G Enterprise servers o HyperHystorian o SQL o ReportWorx

25 11 16 Integrated Automation Network Routers, Bridges, Switches, Hubs and Modems

Government Provided Equipment – For Use by Government Only

All switches between the Gen 64 server and the government network will be provided and installed by the government. The installing contractor will have no access to these devices.

25 11 19 Integrated Automation Operator Workstations

Government Provided Equipment – For Use by BAS Installer

All workstations (typically three (3)) and web HMI clients in the BAS-G portion of the system will be provided and installed by the government for the government and the installing contractors use. The installing contractor will be able to use the workstations only after their security clearances have been validated and access to the government network provided.

25 15 00 Integrated Automation Software

Configure and/or program the software to accomplish all areas covered in this standard.

All time displays are to be in ZULU time.

Place on the Gen 64 server the BAS operations and maintenance manual and links from the graphics for the operator to access the BAS operation and maintenance manual.

Place on the Gen 64 server the Electrical, Mechanical, Plumbing, Architectural and Structural as built manuals and drawings. Provide a link from the graphics to the manuals.

Government Provided Equipment – For Use by BAS Installer

The government will provide installed on the government provided servers the following software for use by the installing BAS contractor. The installing contractor shall provide to the government which applications should be installed on each server.

• Sequel Server 2008 r2 Standard

• Microsoft Office 2010

• Government security and antivirus software (installed on all servers)

• Windows Operation System

The software listed in this Section is tested for compliance with DoDI 8500.2 and is the only acceptable software. Software for BAS systems software shall be:

Direct Digital Controls

• Delta Controls

BAS-L

• Iconics Genesis 64 (minimum version 10.71) with the following applications/functions enabled:

o GraphicWorx64 o TrendWorx 64 o AlarmWorx 64 o GridWorx 64 o Unified Data Manager o Global Aliasing o FrameWorx Server o Security Server o SNMP o BacNET o ScheduleWorx 64 o GridWorx 64 server o ScriptWorx 64 o Modbus Driver o UCONN ASCII Driver o Hyper Historian 64 o Kepware Kepserver EX

BAS-G

o Iconics Genesis 64 (minimum version 10.71) with the following applications/functions enabled:

AlarmWorx Multimedia Agents

AlarmWorx64 Logger

Iconics Security Server

ReportWorx 64

All Iconics Genesis 64 database nomenclature shall follow the following format.

Site Abbreviation(three letter)_Iconics Function

For example: DEN_FrameWorx

All new installations shall utilize the existing Hyper Historian databases that are named as such:

HH_Iconics Function

HH_FrameWorx

For all installations where the Iconics Genesis 64 platform is not currently installed, the installing integrator is to provide all Iconics applications. The Government shall provide Sequel Server, DISA-mandated security, and DISA-mandated antivirus software.

As part of the installation of the software covered in this section, the installing integrator shall work with designated DISA system and database administrators to ensure the correct STIG settings are configured prior to the application being made available to the integrator for installation or communication with the facilities equipment at the site.

For every BAS installation, the integrator shall provide software licenses as necessary to support the software being provided for the BAS-L/BAS-G Iconics Genesis 64 software and sufficient licenses for ten (20) remote users to log into the system at a time.

To maintain control of which ports the BAS system is using, a list of ports will be provided only to installers that have an active contract and have demonstrated that they possess the correct security clearances.

For existing Iconics Genesis 32 systems, the licensing shall only be changed to reflect the increase in point counts to fulfill the project requirements. No additional workstation or remote user licenses are necessary unless specifically required by the project statement of work.

Password Protection and Security

A multiple-level password access protection system shall be programmed/configured in the Iconics Genesis 64 and the DDC software to limit workstation control, display and system manipulation.

All factory passwords for the system shall be removed to the BAS Program Manager. These passwords include administrator, dealer, technician, factory level passwords. Do not include these passwords in any submittal or operations and maintenance manual.

The system shall automatically log the user out of the Iconics Genesis 64 and DDC system after 10 minutes of system inactivity.

The system shall lock out users after three failed login attempts.

All graphics and user manuals shall contain the phrase “FOR OFFICIAL USE ONLY”

Access and security rights for users to the BAS system shall occur by use of domain syncing(to the BAS user group) and Iconics security. No operator shall be permitted to access the system unless they are in the domains BAS User Group and one of the user groups defined by this standard. Domain information will be provided once the installer has:

o Received Notice to Proceed from the contracting officer o Provided Security information to DISA o DISA confirms security o Written request is provided by BAS installer to contracting officer o All submittals have been submitted, reviewed and approved by DISA and the contracting officer

User Groups

The government has established user groups for the enterprise level BAS users and for users at all active sites. The BAS installer shall request in writing through the contracting office creation of site specific user groups. The user group format shall follow:

DISABAS_SiteAbb_User Level

Establish the following User Groups in the Iconics Genesis 64 software to support site level and enterprise level users.

o Enterprise Level Viewer: Provide the ability for these users to have read-only view of any site BAS system within the DISA Enterprise. These users shall also have the ability to create one-time reports.

o Enterprise Level Operator: Provide the ability for these users to have read and write capabilities for all BAS systems within the enterprise. These users shall be able to create or modify trends, graphics, setpoints, reports, and to acknowledge alarms.

o Enterprise Level Configuration: Provide the ability for these users to perform Enterprise Level Operator functions as well as the ability to make program and system configuration changes.

o Site Level Viewer: Provide the ability for these users to have read-only view of their specific site BAS system. These users shall also have the ability to create one-time reports.

o Site Level Operator: Provide the ability for these users to have read and write capabilities for their site specific BAS system. These users shall be able to create or modify trends, graphics, setpoints, reports, and to acknowledge alarms.

o Site Level Configuration: Provide the ability for these users to perform Site Level Operator functions as well as the ability to make program and system configuration changes.

OPC Point Naming Convention Coordinate OPC naming and addressing with the DISA Enterprise Services Facilities Engineering and the Division 23 contractor.

See division 23 09 23 for list of BacNET abbreviations.

All BacNET points (HVAC and non HVAC) shall implement the following naming convention:

BACnetDevice.FunctionAbbr_DataType

Where

• BACnetDevice = BACnet Device Name (typically organized per system)

• FunctionAbbr = Functional Abbreviation of the Point

• DataType = Data Type of the Point (AI, AO, AV, BI, BO, or BV)

Example:

VAV_AHU1_121.ZnTempHtgSP_AV

25 50 00 Integrated Automation Facility Controls

25 58 00 Integrated Automation Control of Electronic Safety and Security Systems

Security systems are not integrated with the BAS for isolation purposes. Access control, intrusion detection, duress alarms, and CCTV operation shall be on a separate system or systems.

25 90 00 Integrated Automation Control Sequences

25 91 00 Integrated Automation Control Sequences for Facility Equipment

Operator Control and Navigation

Provide the operator with the ability to command writable points at a higher priority/default priority if an override is not being utilized.

Provide the operator with the ability to override a writable point at priority array eight (8).

Provide the operator the ability to navigate through the entire controls systems by use of a navigation tool bar that is located on the left side of all graphics. Provide the operator the ability to drill down/view equipment by clicking on the equipment displayed on the graphic. Provide the operator the ability to drill down/view equipment/device pop ups by clicking on the equipment/device.

Trends

Create in the Iconics Genesis 64 system the trends outlined below. The trends shall present a graphic and data (spreadsheet) view. The Trends shall be capable of being exported or emailed from the Iconics Genesis 64 system for use in MS Excel 2007.

• Chilled water supply and return temperature (same trend)

• Condenser water supply and return temperature (same trend)

• Condenser water supply and return temperatures with chilled water supply and return temperatures (same trend)

• Condenser water supply, active chiller loading(in %) and chilled water supply temp

• Outside ambient temperature(dry and wet bulb), condenser water supply temperature, cooling tower fan speed

• Chiller load (in %) when all admin HVAC loads are in night setback or off

• Chiller load (in %) and computer room temperature (average of all CRAC units)

• Make-up water meter for chilled and condenser water make up systems

• Condenser water chemical treatment ‘blow down’ and chemical add to condenser water system

• Electrical Utility Consumption – peak demand in kW (15 min interval) and electrical consumption in kWH (15 min interval)

• Chiller plant and Condenser Water plant electrical consumption - demand in kW (15 min interval) and electrical consumption in kWH (15 min interval)

• UPS input and UPS output electrical consumption - demand in kW (15 min interval) and electrical consumption in kWH (15 min interval)

• Site power utilization efficiency measure in 5 min intervals

Reporting

Create in the Iconics Genesis 64 system the reports outlined below. The reports shall present a graphic and data (spreadsheet) view. The reports shall be capable of being exported or emailed from the Iconics Genesis 64 system on a regular basis or on-demand by operator request.

All reports shall be labeled “FOR OFFICIAL USE ONLY” at the top and bottom of each page in the report.

• Weekly Reports o Any equipment setpoints, alarms, or controls that were placed in manual at anytime during the week.

• Monthly Reports o Equipment runtime hours o Facility Electrical Utility Power demand and consumption o UPS system power demand and consumption

Alarming

This section outlines the alarming requirements for the Iconics Genesis 64 alarm and the transmission of the alarms to the BAS monitoring tools/teams.

Alarms shall be populated into a graphic that allows the operator to sort/ search the alarms. Use the Iconics Area, Sub Area, and Sub Sub Area to categories alarms according to the following table.

Area Sub Area Sub Sub Area Essential

HVAC

Exhaust Fan

Exhaust by Nomenclature

AHU

AHU 1-5(by Nomenclature)

VAV

VAV by Nomenclature

HW

System

HW Pump Boiler HWS Temp Diesel Fuel Tank

Fuel Storage

Gen Day Tanks

AST

UST

Other

HVAC

FCU

Radiant Heat Unit Heaters

All alarms presented by the BAS shall be differentiated and presented to the site operator workstations by criticality as defined below. Alarms shall be differentiated by color coding.

Criticality Index

Criticality Description Equipment Alarm Text Color

1 Critical

Limited to Commercial Power, UPS systems, Chiller plant, Generators, Critical Distribution, Mission Essential Distribution Life Safety Systems and

CRAC units

BLACK ON RED

2 Important

Limited to Commercial Power, UPS systems, Chiller plant, Generators, Critical Distribution, Mission Essential Distribution water leak detection and

CRAC units

RED ON YELLOW

3 Noteworthy Any ORANGE

4 Warning Any PLUM

5 Nuisance Any BLUE

Criticality 1 and 2 alarms shall capture the operator’s attention by animating (flashing) the equipment, data point and alarm (on alarm viewer).

Criticality 3, 4, and 5 alarms shall be displayed in the Iconics Genesis 64 alarm pages, but do not require a POP UP to capture the operators attention.

All infrastructure alarms, regardless of criticality, as outlined by the alarm thresholds be visible to the operator via the Iconics Genesis 64 operator workstations.

Alarms for critical infrastructure equipment shall analyzed by the integrator and the BAS Program Manager to ensure that nuisance alarms are not created when the sites infrastructure equipment responds as designed. Examples of this include, but are not limited to:

• UPS alarms as a result of power outage. The alarms shall be delayed to permit return of UPS input power due to return of utility power or successful transfer of the facility to generator power.

• Chiller, cooling tower, pump, CRAC unit and computer room over temperature alarms as a result of a power outage. The expected operation for these systems is to cycle off until power is returned. The alarms for these systems shall be delayed to provide adequate time for power to return.

• Utility power failure. The BAS shall recognize that there was a utility power failure, but shall delay notification of the failure until it can determine if the sites generator sets successfully started and transferred to support the facility. This alarm shall be designated as Facility Input Power Bus ‘XX’. This alarm shall be created for each facility service entrance bus.

• Under normal operating conditions, the alarm shall be ‘off.’

• Upon recognition of an input voltage loss to the bus, the system shall evaluate generator starting and ATS position along with a return of voltage to the impacted bus and alarm: “Facility Service Entrance Bus XX has a failed utility source, the bus is operating under generator power”

• In the event a voltage loss to the bus is recognized and the generators don’t start or transfer, the BAS shall alarm “Facility Service Entrance Bus XX has a failed utility and generators have not transferred to support the facility.”

The Iconics Genesis 64 system shall communicate via “Post E MSG” four (4) types of alarms and alarm clearing to the BAS monitoring tool. The four (4) alarms will be triggered by certain alarms in all mission critical infrastructure items of equipment. All parameters that trigger the alarm notification to the BAS monitoring tool shall be configurable by the users in the Enterprise Level Operator user group.

Alarms clearing communications shall be sent to Formula only after the operator has acknowledged the alarm and the alarm has returned to normal.

The mission critical items of equipment include, but are not limited to:

• UPS Systems

• Electrical Utility

• Critical Power Distribution Bus

• Generators

• Chiller Plant

• Condenser Water Plant

• Life Safety Equipment

• Computer room temperatures

• CRAC units

All alarms received by these mission critical items of equipment shall be summarized, and categorized into one of four (4) alarm categories:

• Informational/Situational Awareness: Notification that an alarm, maintenance event, or abnormal condition is present in a facilities infrastructure item of equipment or system. The alarm or abnormal condition is not presenting any impact to normal system operation or mission reliability. An example of this type of alarm is: In a fully redundant 2N UPS system (A and B bus) a single UPS module on UPS bus A is reporting a high temperature.

• System HAZCON: Notification that an alarm, maintenance event or abnormal condition is present in a facilities infrastructure item of equipment or system. The alarm or abnormal condition is a result of a portion of the sites redundant system operating outside of its normal operating condition, but remains available and/or online to support the mission. An example of this type of alarm is: In a fully redundant 2N UPS system (A and B bus) all of the A bus UPS modules have transferred to their external bypass as a result of a high temperature condition. The mission is still supported by the bypass source, and the B UPS bus. The A bus UPS system would be the system in HAZCON.

• Site HAZCON: A facilities HAZCON exists when a system that is normally of greater than N reliability loses that status due to equipment failure (in effect, a SPOF is introduced). An N+C system that loses the C additional units providing it redundancy through equipment failure or sustained, unplanned repair downtime is in a HAZCON. A 2N system that loses one N system through equipment failure or sustained, unplanned repair downtime is in a HAZCON. An example of this type of alarm is: In a fully redundant 2N UPS system (A and B bus) all of the A bus UPS modules have shutdown and their external bypass circuit tripped as a result of a high temperature condition. The mission is still supported by the B UPS bus, but a failure of this UPS system (B bus) will result in a mission interruption.

• Mission Interruption: Notification that an abnormal condition is present in a facilities infrastructure item of equipment or system. The abnormal condition is a result of an infrastructure system failure. The infrastructure system failure has resulted in an interruption of either power or cooling to the mission to a point that the mission may be interrupted. An example of this type of alarm is: In a fully redundant 2N UPS system (A and B bus) all of the A and B bus UPS modules have shutdown and their external bypass circuits tripped as a result of a high temperature condition. The mission has experienced a power interruption as a result of the UPS system failures.

The format for each alarm that is communicated by the BAS system to the BAS remote monitoring tool shall follow the format shown below. The equipment specific alarm shall not be communicated to the BAS remote monitoring tool, but must be displayed in the Iconics Genesis 64 alarm log. The following information will be populated by the BAS remote monitoring tool:

[Site], [Alarm Type], [Affected System]: [DISA to populate in monitoring tool]

Example: Denver, Site HAZCON, UPS: [____________________]

The BAS integrator shall use the table below to categorize and communicate infrastructure system alarms to the BAS remote monitoring tool. The table indicates the minimum requirements for alarm categorizing and communication to the BAS monitoring tool; others may be added for a given project.

Situational Awareness (SA) System HAZCON Site HAZCON Mission

Interruption UPS System Alarms

Input Voltage Deviation System in Bypass Tie Breaker Closed No Output on Any

Critical Bus High Input Current Single UPS Shutdown UPS Bus Shutdown/offline

Output Voltage Deviation

Single UPS bus on Battery/loss of input

Dual UPS bus on Battery/loss of input

SBM Notice Loss of Bypass

High UPS Temperature

UPS Room Temp out of Range

Hydrogen Detected in Battery Room

Generator System Alarms

System Not in Auto Any Alarm while Gen are supporting the facility Any Gen Shutdown while supporting the facility Battery Voltage Alarm

Gen Online and Carrying Load

Any alarm while generator are in standby Electrical Utility System Alarms

Main breaker loaded above 45% of rating Breaker Tripped

No Current on Main and

Gen Breaker Computer Room Temperature Alarms

Temp > 77 deg F Temp > 82 deg F Temp > 85 deg F Temp > 95 deg F Temp < 68 deg F

Life Safety Equipment Alarms Fire Alarm in Trouble Fire Alarm In Supervisory Fire Alarm in Alarm

Fire Pump Alarm Critical Distribution Alarms

Main Breaker Loaded above 50% rating

Feeder Breaker loaded above 50% rating Breaker Tripped

No load on any critical bus

PDU loaded above 50% rating Any PDU alarm PDU Output is zero

Two PDU's in a PDU Pair have no output PDU Branch circuit loaded above 50% rating Tie Breaker closed

Bypass breaker closed/main open CRAC Unit Alarms

Any CRAC Alarm More than 3 CRAC units in Alarm or failed More Than 5 CRAC units in Alarm or failed Chilled Water Plant Alarms

Chiller Status alarm Single Chiller in Alarm Multiple Tower Cells in

Alarm Chilled water temp alarm active Chilled water temp > 5 deg above alarm setpoint Chilled water temp > 10 deg above alarm setpoint

Chiller Alarms Chilled Water Pump

Failure Condenser Water Plant Alarms

Cooling tower status…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .