Attachment 2 - MAHG 11-1042 Bryan Hall - Specs - Vol 2 - 02182022.pdf
PDF 2 MB Posted
- Attached to
- Renovate Bryan Hall Federal contract opportunity
- Solicitation number
- FA301023R0001
View the file
Other files for this federal contract opportunity
Show all 21
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SPECIFICATIONS – VOLUME 2
100% DES IGN SUBMITTAL
REPAIR BRYAN HALL B6901
KEESLER AFB, B I LOXI , MISS ISS IPP I
PROJECT NO. MAHG 11-1042
21-006/ KES700259
1091 Tommy Munro Drive Biloxi, MS 39532
228.594.2323
Attachment 2 Solicitation FA301023R0001
MAHG 11-1042 BRYAN HALL RENOVATIONS
KEESLER AFB, BILOXI, MS
PROJECT TABLE OF CONTENTS Page 1
PROJECT TABLE OF CONTENTS
VOLUME 1
DIVISION 01 - GENERAL REQUIREMENTS
STATEMENT OF WORK
01 45 35 SPECIAL INSPECTIONS
01 91 00.15 20 TOTAL BUILDING COMISSIONING
DIVISION 02 - EXISTING CONDITIONS
02 41 00 DEMOLITION
02 82 16.00 20 ENGINEERING CONTROL OF ASBESTOS CONTAINING MATERIALS
02 83 00 LEAD REMEDIATION
DIVISION 03 – CONCRETE
03 30 00 CAST-ON-PLACE CONCRETE
DIVISION 04 - MASONRY
04 20 00 UNIT MASONRY
DIVISION 05 – METALS
05 12 00 STRUCTURAL STEEL
05 40 00 COLD-FORMED METAL FRAMING
05 50 13 MISCELLANEOUS METAL FABRICATIONS
05 52 00 METAL RAILINGS
DIVISION 06 - WOOD, PLASTICS, AND COMPOSITES
06 10 00 ROUGH CARPENTRY
06 20 00 FINISH CARPENTRY
06 61 16 SOLID POLYMER (SOLID SURFACING) FABRICATIONS
DIVISION 07 - THERMAL AND MOISTURE PROTECTION
07 21 16 MINERAL FIBER BLANKET INSULATION
07 22 00 ROOF AND DECK INSULATION
07 24 00 EXTERIOR INSULATION AND FINISH SYSTEMS
07 84 00 FIRESTOPPING
07 92 00 JOINT SEALANTS
DIVISION 08 - OPENINGS
08 11 13 STEEL DOORS AND FRAMES
08 11 16 ALUMINUM DOORS AND FRAMES
08 14 00 WOOD DOORS
08 71 00 DOOR HARDWARE
08 81 00 GLAZING
08 91 00 METAL WALL LOUVERS
PROJECT TABLE OF CONTENTS Page 2
DIVISION 09 - FINISHES
09 22 00 SUPPORTS FOR GYPSUM BOARD
09 29 00 GYPSUM BOARD
09 30 00 CERAMIC TILE
09 51 00 ACOUSTICAL CEILINGS
09 65 00 RESILIENT FLOORING
09 65 36 STATIC-RESILIENT FLOORING
09 68 00 CARPET
09 69 13 RIGID GRID ACCESS FLOORING
09 90 00 PAINTS AND COATINGS
DIVISION 10 - SPECIALTIES
10 10 00 VISUAL COMMUNICATIONS SPECIALTIES
10 14 02 INTERIOR SIGNAGE
10 21 13 TOILET COMPARTMENTS
10 26 13 WALL AND CORNER GUARDS
10 28 13 TOILET ACCESSORIES
10 44 16 FIRE EXTINGUISGERS
DIVISION 11 - EQUIPMENT
NOT USED
DIVISION 12 - FURNISHINGS
NOT USED
DIVISION 14 – CONVEYING SYSTEMS
14 24 00 HYDRAULIC ELEVATOR
DIVISION 21 - FIRE SUPPRESSION
21 13 13 WET PIPE SPRINKLER SYSTEMS, FIRE PROTECTION
DIVISION 22 - PLUMBING
22 00 00 PLUMBING, GENERAL PURPOSE
DIVISION 23 - HEATING, VENTILATING, AND AIR CONDITIONING (HVAC)
23 03 00.00 20 BASIC MECHANICAL MATERIALS AND METHODS
23 05 15 COMMON PIPING FOR HVAC
23 05 48.19 SEISMIC BRACING FOR HVAC
23 05 93 TESTING, ADJUSTING, AND BALANCING FOR HVAC
23 07 00 THERMAL INSULATION FOR MECHANICAL SYSTEMS
23 08 00.00 20 COMMISSIONING OF MECHANICAL AND PLUMBING SYSTEMS
23 09 00 INSTRUMENTATION AND CONTROL FOR HVAC
23 09 23.02 BACNET DIRECT DIGITAL CONTROL FOR HVAC AND OTHER BUILDING
CONTROL SYSTEMS
23 09 53.00 20 SPACE TEMPERATURE CONTROL SYSTEMS
23 11 20 FACILITY GAS PIPING
23 11 13.00 20 LOW TEMPERATURE WATER (LTW) HEATING SYSTEM
23 30 00 HVAC AIR DISTRIBUTION
PROJECT TABLE OF CONTENTS Page 3
23 64 26 CHILLED, CHILLED-HOT, AND CONDENSER WATER PIPING SYSTEMS
23 73 13.00 40 MODULAR INDOOR CENTRAL-STATION AIR-HANDLING UNITS
23 82 20.00 10 TERMINAL HEATING UNITS
VOLUME 2
DIVISION 25 - INTEGRATED AUTOMATION
25 05 11 CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS
DIVISION 26 - ELECTRICAL
26 20 00 INTERIOR DISTRIBUTION SYSTEM
26 24 13 SWITCHBOARDS
26 28 01.00 10 COORDINATED POWER SYSTEM PROTECTION
26 29 23 ADJUSTABLE SPEED DRIVE (ASD) SYSTEMS UNDER 600 VOLT
26 32 15.00 ENGINE-GENERATOR SET STATIONARY 15-2500 KW, WITH
AUXILIARIES
26 36 23 AUTOMATIC TRANSFER SWITCHES AND BY-PASS/ISOLATION SWITCH
26 41 00 LIGHTNING PROTECTION SYSTEM
26 51 00 INTERIOR LIGHTING
26 56 00 EXTERIOR LIGHTING
DIVISION 27 – COMMUNICATION
27 05 13.43 TELEVISION DISTRIBUTION SYSTEM
27 10 00 BUILDING TELECOMMUNICATIONS CABLING SYSTEM
DIVISION 28 - ELECTRONIC SAFETY AND SECURITY
28 31 76 INTERIOR FIRE ALARM AND MASS NOTIFICATION SYSTEM
DIVISION 31 – EARTHWORK
31 00 00 EARTHWORK
31 10 00 CLEARING FOR CIVIL WORKS
DIVISION 32 – EXTERIOR IMPROVEMENTS
32 16 19 CONCRETE CURBS, GUTTERS, AND SIDEWALKS
32 17 25.00 10 PAVEMENT MARKINGS
32 92 23 SODDING
DIVISION 33 – UTILITIES
33 11 00 WATER UTILITY DISTRIBUTION PIPING
33 71 02 UNDERGROUND ELECTRICAL DISTRIBUTION
33 82 00 TELECOMMUNICATIONS OUTSIDE PLANT (OSP)
-- End of Project Table of Contents --
MAHG 11-1042 BRYAN HALL RENOVATION
SECTION 25 05 11
CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS
05/21
PART 1 GENERAL
Many subparts in this Section contain text in curly braces ("{" and "}") indicating which cybersecurity control and control correlation identifier (CCI) the requirements of the subpart relate to. The text inside these curly braces is for Government reference only and enables coordination of the requirements of this Section with the RMF process throughout the design and construction process. Text in curly braces are not contractor requirements.
This Section refers to Security Requirements Guide (SRGs) and Security Technical Implementation Guide (STIGs). STIGs and SRGs are available online at the Information Assurance Support Environment (IASE) website at https://public.cyber.mil/stigs/downloads/ and an SRG/STIG Applicability Guide and Collection Tool is available at https://public.cyber.mil/stigs/SCAP/ . Not all control system components have applicable STIGs or SRGs. The "Control Systems SRG" does not apply to work performed under this Section; all requirements within this section to apply applicable SRGs DO NOT include the "Control Systems SRG".
1.1 CONTROL SYSTEM APPLICABILITY
There are multiple versions of this Section associated with this project.
Different versions have requirements applicable to different control systems. This specific Section applies only to the following control systems: Distributed low voltage lighting controls, fire alarmsystem, HVAC control system .
1.2 RELATED REQUIREMENTS
This section does not contain sufficient requirements to procure a control system and must be used in conjunction with other Sections which specify control systems. This Section adds cybersecurity requirements to the control systems specified in other Sections, and as these requirements are conditioned on the control system being provided, there may be requirements in this Section that will not apply to this project. All Sections containing facility-related control systems or control system components are related to the requirements of this Section. Review all specification sections to determine related requirements.
In cases where a requirement is specified in both this Section and in another Section, the more stringent requirement must be met. In cases where a requirement in this Section conflicts with the requirements of another Section such that both requirements cannot be met at the same time, request direction from the Contracting Officer Representative to
SECTION 25 05 11 Page 1 determine which requirement applies to the project.
1.3 REFERENCES
The publications listed below form a part of this specification to the extent referenced. The publications are referred to within the text by the basic designation only.
AMERICAN SOCIETY OF HEATING, REFRIGERATING AND AIR-CONDITIONING
ENGINEERS (ASHRAE)
ASHRAE 135 (2020; Errata 2021) BACnet—A Data Communication Protocol for Building Automation and Control Networks
INSTITUTE OF ELECTRICAL AND ELECTRONICS ENGINEERS (IEEE)
IEEE 802.1x (2010) Local and Metropolitan Area Networks - Port Based Network Access Control
INTERNET ENGINEERING TASK FORCE (IETF)
IETF RFC 2819 (2000) Remote Network Monitoring (RMON) Management Information Base (MIB)
NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST)
NIST FIPS 140-2 (2001) Security Requirements for Cryptographic Modules
NIST FIPS 201-2 (2013) Personal Identity Verification (PIV) of Federal Employees and Contractors
U.S. DEPARTMENT OF DEFENSE (DOD)
DODI 8551.01 (2014) Ports, Protocols, and Services Management (PPSM)
DTM 08-060 (2008) Policy on Use of Department of Defense (DoD) Information Systems - Standard Consent Banner and User Agreement
1.4 DEFINITIONS
1.4.1 Administrator Account
An administrator account is an account with full permissions to a device, application, or operating system, including the ability to create and modify other user accounts.
Note that the operating system Administrator Account may be different than Administrator Accounts for applications hosted on that operating system.
Also, most controllers will not have any support for accounts and will therefore not have an 'Aministrator Account'.
SECTION 25 05 11 Page 2
1.4.2 Computer
A computer is one of the following:
a. a device running a non-embedded desktop or server version of Microsoft Windows
b. a device running a non-embedded version of MacOS
c. a device running a non-embedded version of Linux
d. a device running a version or derivative of the Android Operating System, where Android is considered separate from Linux
e. a device running a version of Apple iOS
Unless otherwise indicated or clear from context use of the word "device" in this Section includes computers.
1.4.3 Controller
A device other than a computer or Ethernet switch. For Fire Protection systems this includes fire alarm control panels, remote operating consoles, and remote annunciators.
1.4.4 Mission Space
A device or media is in mission space if physical access to the device or media is controlled by the organization served by the device. For example, a VAV box controller in a suspended ceiling is in mission space if the VAV box serves that room; an electrical switchgear in an electrical room or an AHU in a mechanical room or on a rooftop may still be considered to be in mission space if the organization (mission) served by that switchgear or AHU controls access to the electrical room, mechanical room or rooftop..
1.4.5 Network
A network is a group of two or more devices that can communicate using a network protocol. Network protocols must provide a method for addressing devices on the network; a communication method that does not provide an addressing scheme is not a networked form of communication. Devices that communicate using a method of communication that does not support device addressing are not using a network.
1.4.6 Network Connected
A component is network connected (or "connected to a network") only when the device has a network transceiver which is directly connected to the network and implements the network protocol. A device lacking a network transceiver (and accompanying protocol implementation) can never be considered network connected. Note that (unlike many IT definitions of "Network Connected") a device connected to a non-IP network is still considered network connected (an IP connection or IP address is not required for a device to be network connected).
SECTION 25 05 11 Page 3
1.4.6.1 Wireless Network Connected
Any device that supports wireless network communication is network connected to a wireless network, regardless of whether the device is communicating using wireless. Unless physically disabled, devices with wireless transceivers support wireless, it is not sufficient to disable the wireless in software.
1.4.7 Network Media
The thing that provides the communication channel between the devices on a network. Typically wire, but might include wireless, fiber optic, or even power line (some network protocols allow sending network signals over power wiring).
1.4.8 User Account Support Levels
The support for user accounts is categorized in this Section as one of three levels:
1.4.8.1 FULLY Supported
Device supports configurable individual accounts. Accounts can be created, deleted, modified, etc. Privileges can be assigned to accounts.
These devices support user-based (as opposed to role-based) authentication.
1.4.8.2 MINIMALLY Supported
Device supports a small, fixed number of accounts (perhaps only one).
Accounts cannot be modified. A device with only a "User" and an "Administrator" account would fit this category. Similarly, a device with two PINs for logon - one for restricted and one for unrestricted rights would fit here (in other words, the accounts do not have to be the traditional "username and password" structure). These devices typically only support role-based authentication.
Examples of devices which MINIMALLY support accounts are a) a variable frequency drive with a single account which requires a PIN for access to configuration; and b) a room lighting control touchpad interface that has a single account.
1.4.8.3 NOT Supported
Device does not support any Access Enforcement therefore the whole concept of "account" is meaningless.
1.4.9 Manual Local Input
Manual Local Inputs are system analog or binary inputs that are adjustable by a person but are, by intrinsic hardware design, very limited in potential capabilities. Manual Local Inputs do not have touch screens or full keyboards, but may have a few buttons or dials to allow input.
Manual Local Inputs do not have full graphic screens or dot-matrix displays, but may have simple lights (LEDs) or 7-segment displays. Manual Local Inputs do not have any sort of menu structure, each button has a single well-defined function.
Examples of Manual Local Inputs are H-O-A switches, simple thermostats, and disconnect switches.
SECTION 25 05 11 Page 4
1.4.10 User Interface
A User Interface (UI) is something other than a Manual Local Input or Card Reader that allows a person to interact with the system or device. Note that while a Card Reader is not by itself a User Interface, a User Interface may contain a Card Reader in order for it to authenticate its user. Within control systems, there are a wide range of User Interfaces.
Two important distinctions are 1) whether the user interface is Local or Remote, and 2) the effective capabilities of the User Interface to alter data, which is the "privilege" of the user interface (where effective privilege available to a specific user at a specific user interface is the combination of the greatest privilege offered by the user interface and the specific account the user is logged into).
1.4.10.1 Local User Interface
A Local User Interface is a user interface where the physical hardware the user interacts with (keyboard, buttons, display, etc.) is physically part of the device being affected. All of the relevant characteristics of the user interface are embodied within a single device.
Note that a Local UI may be able to access data in a different device, Local versus Remote in this context refers to the user interface itself;
the capability to access data in a different device is covered under "Full User Interface".
1.4.10.2 Remote User Interface
A Remote User Interface implements a Client/Server model where the physical hardware the user interacts with (Client) is physically distinct from the device being affected (Server). Most or all of the security and functionality characteristics of the user interface are defined by the Server, not the Client. The Client and Server communicate via a network connection. A common example of a remote user interface is a web-based interface where the browser (client) is generally on different hardware than the web server (server). A Remote UI remains a Remote UI even if the user happens to be at a Client on the same hardware as the Server. What is important is that a) the Client may be on different hardware than the Server and b) the majority of the security and functional characteristics of the interface are defined at the Server.
Note that this definition of "remote" is consistent with that generally used in the control industry but is not aligned with the NIST 800-53 definition of "Remote", which refers to "outside the system". The term "Remote" here better aligns with the NIST 800-53 definition of "Network" (remote from within the system) Access.
1.4.10.3 Types of User Interface (by capability)
User interfaces are also categorized by their capabilities as being Read Only, Limited, or Full.
1.4.10.3.1 Read-Only User Interface
A Read Only User Interface (also referred to as a View-Only User Interface) is a user interface that only allows for reading data, it does
SECTION 25 05 11 Page 5 not allow (have the capability to) modify data. A Read Only User Interface may be either Local or Remote. A User Interface that is configured to be Read Only (by some other means than the interface itself, such as using configuration software on a laptop) is a Read-Only Interface. Note a Read Only User Interface may have buttons (or touch screen, etc.) allowing the user to navigate through the presentation of data.
Examples of a Read Only User Interfaces are a) a publicly viewable "energy dashboard" showing weather data and energy usage within a building and b) digital wayfinding signage.
1.4.10.3.2 Limited User Interface
A Limited User Interface is a user interface that - by design - can only alter information local to the user interface. Note that the determination of "alter" includes only direct interactions, it explicitly excludes interactions that might occur as secondary effects. For example, an interface changing the flow setpoint in a pump controller is a direct interaction, the subsequent change in flow (as well as any subsequent downstream changes in valve position) are not direct interactions.
Two examples of LIMITED UIs are: a) a variable speed drive has a Limited Local User Interface which allows the user to change properties within the drive, but does not allow affecting things outside the drive; and b) a typical home WiFi Router has a Limited Remote User Interface which allows configuration of the Router, but does not allow direct interaction with other devices.
1.4.10.3.3 Full User Interface
A Full User Interface can alter information in devices outside the device with the user interface. For example, a typical Local Display Panel is a Full Local User Interface while a browser-based front end is a Full Remote User Interface.
1.4.10.3.4 View-Only User Interface
See Read-Only User Interface
1.4.10.4 Other User Interface Terminology
In addition to defining whether a user interface is a Hardware Limited, Read-Only, Limited or Full, and whether it is Local or Remote, user interfaces are classified by whether they are writable or privileged.
1.4.10.4.1 Writable User Interface
Any User Interface that is not Read-Only is Writable. (Limited User Interfaces and Full User Interfaces are both writable user interfaces (as they are capable of changing a value)).
1.4.10.4.2 Privileged User Interface
A Privileged UI is a UI that has sufficient capabilities or functionality that it requires specific cybersecurity measures to be put in place to limit its unauthorized use. Ultimately, whether a specific user interface is considered a Privileged User Interface must be determined by usage.
Unless otherwise specified, user interfaces can be determined to be
SECTION 25 05 11 Page 6 privileged or not using the following:
a. Read-Only User Interfaces are not privileged user interfaces.
b. Full User interfaces for Fire Alarm Systems are privileged user interfaces as indicated and shown, or when another requirement of this Section establishes they are privileged. For all other systems, Full User Interfaces are privileged user interfaces.
c. User interfaces that allow for configuration of auditing or allows for modification or deletion of audit logs are privileged user interface.
d. User interfaces that allow for reprogramming a network connected device is a privileged user interface.
e. For Fire Protection Systems, User Interfaces that can inhibit or force the activation of a fire suppression system (e.g. such as for a pre-action or deluge system) are privileged user interfaces.
e. Except as specified above, a Limited User Interface must be determined to be privileged or not based on the specific capabilities and use case of the user interface. In general however, user interfaces that do not offer significant capabilities above and beyond those available at that location via other means (e.g. such as a disconnect switch, breaker, or hand-off-auto switch, or physical attack) are not privileged.
1.4.11 Wireless Network
Any network that communicates without using wires or fiber optics as the communication media. Wireless networks include: WiFi, Bluetooth, ZigBee, cellular, satellite, 900 MHz radio, 2.4 GHz, free space optical, point-to-point laser, and IR.
1.4.12 Wired Broadcast Network
Wired Broadcast Networks are any network, such as powerline carrier networks and modem (wired telephony), that use wire-based technologies where there is not a clearly defined boundary for signal propagation.
1.5 ADMINISTRATIVE REQUIREMENTS
1.5.1 Points of Contact
Coordinate with the following Points of Contact as indicated in this Section and as required. Not all projects will require coordination with all Points of Contact. When coordination is required and no Point of Contact is indicated, coordinate with .
a. Government Computer Access Point of Contact: The Contracting Office Representative (COR)
b. HTTPS Certificate Point of Contact: The Contracting Office Representative (COR)
c. Email Address Point of Contact: The Contracting Office Representative
(COR)
SECTION 25 05 11 Page 7
d. Password Point of Contact: The Contracting Office Representative (COR)
e. Mobile Code Point of Contact: The Contracting Office Representative
(COR)
1.5.2 Coordination
Coordinate the execution of this Section with the execution of all other Sections related to control systems as indicated in the paragraph RELATED REQUIREMENTS. Items that must be considered when coordinating project efforts include but are not limited to:
a. If requesting permission for wireless or wired broadcast communication, the Wireless and Wired Broadcast Communication Request submittal must be approved prior to control system device selection and installation.
b. If requesting permission for alternate account lock permissions, the Device Account Lock Exception Request must be approved prior to control system device selection and installation.
c. If requesting permission for the use of a device with multiple physical connections to IP networks, the Multiple IP Connection Device Request must be approved prior to control system device selection and installation.
d. Wireless testing may be required as part of the control system testing. See requirements for the Wireless Communication Test Report submittal.
e. If the Device Audit Record Upload Software is to be installed on a computer not being provided as part of the control system, coordination is required to identify the computer on which to install the software.
f. The Cybersecurity Interconnection Schedule must be coordinated with other work that will be interconnected to, and interconnections must be approved by the Government before relying on them for system functionality.
g. Cybersecurity testing support must be coordinated across control systems and with the Government cybersecurity testing schedule.
h. Passwords must be coordinated with the indicated contact for the project site.
i. If applicable, HTTPS web server certificates must be obtained from the indicated HTTPS Certificate Point of Contact.
j. Contractor Computer Cybersecurity Compliance Statements must be provided for each contractor using contractor owned computers.
1.6 SUBMITTALS
Government approval is required for all submittals. Submit the following in accordance with Division 01 Requirements:
SD-01 Preconstruction Submittals
SECTION 25 05 11 Page 8
Device Account Lock Exception Request; G
Multiple Ethernet Connection Device Request; G
Contractor Computer Cybersecurity Compliance Statements; G
Contractor Temporary Network Cybersecurity Compliance Statements; G
Protection of Information At Rest Proposal; G
Proposed STIG and SRG Applicability Report; G
SD-02 Shop Drawings
Network Communication Report; G
Cybersecurity Riser Diagram; G
SD-03 Product Data
Control System Cybersecurity Documentation; G
SD-06 Test Reports
Control System Cybersecurity Testing Procedures; G
Control System Cybersecurity Testing Report; G
SD-07 Certificates
Software Licenses; G
SD-11 Closeout Submittals
Enclosure Keys; G
Software and Configuration Backups; G
Auditing Front End Software; G
Device Audit Record Upload Software; G
System Maintenance Tool Software; G
Control System Scanning Tools; G
STIG, SRG and Vendor Guide Compliance Result Report; G
Control System Inventory Report; G
Integrity Verification Software; G
1.7 QUALITY CONTROL
1.8 CYBERSECURITY DOCUMENTATION
{For Government Reference Only: This subpart (and its subparts) relates to PL-7; CCI-003071}
SECTION 25 05 11 Page 9
1.8.1 Proposed STIG and SRG Applicability Report
For each model of network connected or network infrastructure device, use the DISA SRG/STIG Applicability Guide and Collection Tool (available at https://public.cyber.mil/stigs/SCAP/ to identify applicable STIGs or SRGs and provide a report indicating applicable STIGs and SRGs for each model.
1.8.2 Network Communication Report
{For Government Reference Only: This subpart (and its subparts) relates to CA-9, PL-8; CCI-003075; CCI-002102, CCI-002103, CCI-002104, CCI-002105, CCI-003072, CCI-003073, CCI-003075 and also the submittal requirements associated with CM-6, CM-7, SC-8 and SC-41 including CM-7(3), CCI-000388. }
Provide a network communication report. For each networked device, document the communication characteristics of the device including communication protocols, services used, encryption employed, and a general description of what information is communicated over the network. For each device using IP, document all TCP and UDP ports used. For non-IP communications, document communication protocol and media used. If other control system Sections used on this project include submittals documenting this information, provide copies of those submittals to meet this requirement.
In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Network Communication Report as an editable Microsoft Excel file.
1.8.3 Control System Inventory Report
{For Government Reference Only: This subpart (and its subparts) relates to CM-8(a), SI-17, IA-3; CCI-000389, CCI-000392, CCI-000398, CCI-002773, CCI-002774, CCI-002775, CCI-000777, CCI-000778, CCI-001958}
Provide a Control System Inventory report using the Inventory Spreadsheet listed under this Section at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11 documenting all networked devices, including network infrastructure devices. For each device provide all applicable information for which there is a field on the spreadsheet in accordance with the instructions on the spreadsheet.
In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Control System Inventory Report as an editable Microsoft Excel file.
1.8.4 Software and Configuration Backups
{For Government Reference Only: This subpart (and its subparts) relates to CP-10; CCI-000550, CCI-000551, CCI-000552}
For each computer on which software is installed under this project, provide a recovery image of the final as-built computer. This image must allow for bare-metal restore such that restoration of the image is sufficient to restore system operation to the imaged state without the need for re-installation of software. If additional user permissions are required to meet this requirement, coordinate the creation of the image
SECTION 25 05 11 Page 10 with the identified Government Computer Access Point of Contact.
For all ethernet switches provide a backup of the switch configuration.
For all controllers, provide a backup of the controller configuration and the source code for all loaded application programs (all software that is not common to every controller of the same manufacturer and model).
If any or all of these are provided under another Section, provide documentation indicating this and referencing those submittals.
1.8.5 Cybersecurity Riser Diagram
{For Government Reference Only: This subpart (and its subparts) relates to PL-2(a), PL-8; CCI-003051, CCI-003053, CCI-003072, CCI-003073, CCI-003075}
Provide a cybersecurity riser diagram of the complete control system including all network and device hardware. If the control system specifications require a riser diagram submittal, provide a copy of that submittal as the cybersecurity riser diagram. Otherwise, provide a riser diagram in one-line format.
1.8.6 STIG, SRG and Vendor Guide Compliance Result Report
For every component (device or software) with an applicable STIG or SRG in the Proposed STIG and SRG Applicability Report, provide a result report documenting compliance with the STIG or SRG requirements. For components which are scannable by the SCAP (security content automation protocol) tool (available online at https://public.cyber.mil/stigs/scap ), provide the SCAP report and raw scan results.
For every component (device or software) with manufacturer provided cybersecurity documentation, procedure, or method for secure configuration or installation, provide a report documenting how the component was configured and any deviation from the manufacturer instructions.
1.8.7 Control System Cybersecurity Documentation
{For Government Reference Only: This subpart (and its subparts) relates to SA-5 (a),(b),(c); CCIs: CCI-003124, CCI-003125, CCI-003126, CCI-003127, CCI-003128, CCI-003129, CCI-003130, CCI-003131}
Provide a Control System Cybersecurity Documentation submittal containing the indicated information for each device and software application.
1.8.7.1 Software Applications
For all software applications running on computers provide:
a. administrator documentation that describes secure configuration of the software {For Government Reference Only: relates to CCI-003124}
b. administrator documentation that describes secure installation of the software {For Government Reference Only: relates to CCI-003125}
c. administrator documentation that describes secure operation of the software {For Government Reference Only: relates to CCI-003124}
SECTION 25 05 11 Page 11
d. administrator documentation that describes effective use and maintenance of security functions or mechanisms for the software {For Government Reference Only: relates to CCI-003127}
e. administrator documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the software {For Government Reference Only: relates to
CCI-003128}
f. user documentation that describes user-accessible security functions or mechanisms in the software and how to effectively use those security functions or mechanisms {For Government Reference Only:
relates to CCI-003129}
g. user documentation that describes methods for user interaction which enables individuals to use the software in a more secure manner {For Government Reference Only: relates to CCI-003130}
h. user documentation that describes user responsibilities in maintaining the security of the software {For Government Reference Only: relates to CCI-003131}
1.8.7.2 For HVAC Control System Devices
1.8.7.2.1 HVAC Control System Devices FULLY Supporting User Accounts
For all HVAC Control System Devices which FULLY support user accounts, provide:
a. Documentation that describes secure configuration of the device {For Government Reference Only: relates to CCI-003124}
b. Documentation that describes secure operation of the device {For Government Reference Only: relates to CCI-003124}
c. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {For Government Reference Only:
relates to CCI-003127}
d. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {For Government Reference Only: relates to CCI-003128}
e. Documentation that describes user-accessible security functions or mechanisms in the device and how to effectively use those security functions or mechanisms; or a specific indication that there are no user-accessible security functions or mechanisms in the device {For Government Reference Only: relates to CCI-003129}
f. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {For Government Reference Only: relates to CCI-003130}
1.8.7.2.2 All Other HVAC Control System Devices
For all HVAC Control System Devices which do not FULLY support user accounts, provide:
SECTION 25 05 11 Page 12
a. Documentation that describes secure configuration of the device; or a specific indication that there are no secure configuration steps that apply {For Government Reference Only: relates to CCI-003124}
b. Documentation that describes effective use and maintenance of security functions or mechanisms for the device; or a specific indication that there are no security functions or mechanisms in the device {For Government Reference Only: relates to CCI-003127}
c. For devices which include a user interface, documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {For Government Reference Only:
relates to CCI-003130}
1.8.7.3 For Lighting Control System Devices
1.8.7.3.1 All Other Lighting Control System Devices
For all Lighting Control System Devices which do not FULLY support user accounts, provide:
a. Documentation that describes secure configuration of the device; or a specific indication that there are no secure configuration steps that apply {For Government Reference Only: relates to CCI-003124}
b. Documentation that describes effective use and maintenance of security functions or mechanisms for the device; or a specific indication that there are no security functions or mechanisms in the device {For Government Reference Only: relates to CCI-003127}
c. For devices which include a user interface, documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {For Government Reference Only:
relates to CCI-003130}
1.8.7.4 Default Requirements for Control System Devices
For control system devices where Control System Cybersecurity Documentation requirements are not otherwise indicated in this Section, provide:
a. Documentation that describes secure configuration of the device {For Government Reference Only: relates to CCI-003124}
b. Documentation that describes secure installation of the device {For Government Reference Only: relates to CCI-003125}
c. Documentation that describes secure operation of the device {For Government Reference Only: relates to CCI-003124}
d. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {For Government Reference Only:
relates to CCI-003127}
e. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {For Government Reference Only: relates to CCI-003128}
f. Documentation that describes user-accessible security functions or
SECTION 25 05 11 Page 13 mechanisms in the device and how to effectively use those security functions or mechanisms {For Government Reference Only: relates to
CCI-003129}
g. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {For Government Reference Only: relates to CCI-003130}
h. Documentation that describes user responsibilities in maintaining the security of the device {For Government Reference Only: relates to
CCI-003131}
1.9 SOFTWARE LICENSING
{For Government Reference Only: This subpart (and its subparts) relates to SI-2(a), SI-2(c), SI-7(14); CCI-001227, CCI-002605, CCI-002737}
For all software provided that has not already been licensed to the government or project site, provide a license to the Government for a period of no less than 5 years, and the license must also include the following software updates:
a. Security and bug-fix patches issued by the software manufacturer.
b. Security patches to address any vulnerability identified in the National Vulnerability Database at http://nvd.nist.gov with a Common Vulnerability Scoring System (CVSS) severity rating of MEDIUM or higher.
Provide a single Software Licenses submittal with documentation of the software licenses for all software provided
1.10 CYBERSECURITY DURING CONSTRUCTION
{For Government Reference Only: This subpart (and its subparts) relates to
AC-18, SA-3; CCI-000258}
In addition to the control system cybersecurity requirements indicated in this section, meet following requirement throughout the construction process.
1.10.1 Contractor Computer Equipment
Contractor owned computers may be used for construction. Contractor computers connected to the control system, control system network, or a control system component at any point during construction must meet the following requirements:
1.10.1.1 Operating System
The operating system must be an operating system currently supported by the manufacturer of the operating system. The operating system must be current on security patches and operating system manufacturer required updates.
SECTION 25 05 11 Page 14
1.10.1.2 Anti-Malware Software
The computer must run anti-malware software from a reputable software manufacturer. Anti-malware software must be a version currently supported by the software manufacturer, must be current on all patches and updates, and must use the latest definitions file. Computers used on this project must be scanned using the installed software at least once per day.
1.10.1.3 Passwords and Passphrases
The passwords and passphrases for computers, applications, and web-based applications supporting passwords must be changed from their default values. Passwords must be a minimum of eight characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.
1.10.1.4 User-Based Authentication
Each user must have a unique account; sharing of a single account between multiple users is prohibited.
1.10.1.5 Demonstration of Compliance
The Government has the right to require demonstration of computer compliance with these requirements at any time during the project.
1.10.1.6 Contractor Computer Cybersecurity Compliance Statements
Provide a single submittal containing completed Contractor Computer Cybersecurity Compliance Statements for each company using contractor owned computers. Contractor Computer Cybersecurity Compliance Statements must use the template published at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11 Each Statement must be signed by a cybersecurity representative for the relevant company.
1.10.2 Temporary IP Networks
Temporary contractor-installed IP networks may be used during construction. When used, temporary contractor-installed IP networks connected to the control system, control system network, or a control system component at any point during construction must meet the following requirements:
1.10.2.1 Network Boundaries and Connections
The network must not extend outside the project site and must not connect to any IP network other than those specifically provided or furnished for this project. Any and all access to the network from outside the project site is prohibited.
1.10.3 Government Access to Network
Government personnel must be allowed to have complete and immediate access to the network at any time in order to verify compliance with this specification.
SECTION 25 05 11 Page 15
1.10.4 Temporary Wireless IP Networks
In addition to the other requirements on temporary IP networks, temporary wireless IP (WiFi) networks, when permitted, must not interfere with existing wireless networks, must use WPA2 security and must not broadcast the network name (SSID). Network names (SSID) for wireless networks must be changed from their default values.
1.10.5 Passwords and Passphrases
The passwords and passphrases for all network devices and network access must be changed from their default values. Passwords must be a minimum 8 characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.
1.10.6 Contractor Temporary Network Cybersecurity Compliance Statements
Provide a single submittal containing completed Contractor Temporary Network Cybersecurity Compliance Statements for each company implementing a temporary IP network. Contractor Temporary Network Cybersecurity Compliance Statements must use the template published at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11 Each Statement must be signed by a cybersecurity representative for the relevant company. If no temporary IP networks will be used, provide a single copy of the Statement indicating this.
1.11 CYBERSECURITY DURING WARRANTY PERIOD
All work performed on the control system after acceptance must be performed using Government Furnished Equipment or equipment specifically and individually approved by the Government.
PART 2 PRODUCTS
All products used on this project must meet the indicated requirements, but not all products specified here will be required by every project.
2.1 ETHERNET SWITCH
Provide Open Systems Interconnection (OSI) Layer 2 Ethernet switches with the following capabilities, and with an interface to support switch configuration for these capabilities:
2.1.1 Required Functionality
Switches must:
a. Copper Ethernet ports must auto negotiate for 10, 100 and 1000 megabits-per-second links.
b. Be capable of implementing port level access control by MAC address and limit the number of MAC addresses to one MAC address per port.
c. For MODERATE Impact Systems, be capable of implementing per-port access control lists (ACLs) where the list can be filtered by source and destination IP addresses, and by source and destination UDP or TCP ports.
c. For LOW Impact Systems, be capable of implementing per-port access
SECTION 25 05 11 Page 16 control lists (ACLs) where the list can be filtered by source and destination IP addresses, and by source and destination UDP or TCP ports.
d. Support Remote Network Monitoring (RMON) Port Analysis in accordance with IETF RFC 2819
e. Configure target port and analysis port such that switch clones all target port traffic to analysis port.
f. Support authentication via RADIUS server (for management and 802.1x)
g. Support IEEE 802.1x network login.
2.1.2 Configuration Requirements
Switches must:
a. Support configuration save and restore.
b. Support both manual IP address assignment and acquisition of a dynamic IP address via Dynamic Host Configuration Protocol (DHCP).
c. Be capable of limiting access for configuration to one or more of: a web interface using HTTPS, a command line interface using SSH, or an SNMP connection using SNMP version 3 or later.
d. Support the ability to lock configuration capability to a dedicated management port.
2.2 DAISY CHAIN IP CONTROLLERS
Controllers used as Daisy Chain IP Controllers must be IP controllers with exactly two Ethernet network connections and basic built-in switch capabilities to allow implementation of an Ethernet network in a daisy chain architecture. Switches incorporated by Daisy Chain IP Controllers are not required to meet the requirements for Ethernet Switches as defined in this Section.
2.3 DATABASE AND WEB SERVER SOFTWARE FOR MODERATE IMPACT SYSTEMS
{For Government Reference Only: This subpart (and its subparts) relate to
RA-5(1), RA-5(5); CCI-001062, CCI-001067, CCI-001645, CCI-002906}
All computer-based databases must use . All computer-based web interfaces must use as the web server.
PART 3 EXECUTION
3.1 CYBERSECURITY HARDENING AND CONFIGURATION GUIDES
Install, configure, and harden all hardware and software furnished on this project in accordance with manufacturer provided documentation, procedures, or methods for secure configuration or installation. Do not implement specific hardening actions if that action would conflict with requireed functionality or another requirement of this Section.
SECTION 25 05 11 Page 17
3.2 NETWORK REQUIREMENTS
3.2.1 Information Flow Enforcement In MODERATE Impact Systems
{For Government Reference Only: This subpart (and its subparts) relate to
AC-4; CCI-001368, CCI-001414, CCI-001548, CCI-001549, CCI-001550,
CCI-001551}
Install and configure Ethernet switches to block all traffic on all ports not required by the control protocol.
3.2.2 Wireless and Wired Broadcast Communication for Fire Protection Systems
The use of wireless and wired broadcast communication for fire protection systems within a facility is prohibited. Wireless communication may be used to provide communication from the fire protection system in a facility to the central monitoring station.
3.2.3 Non-IP Control Networks
When control system specifications require particular communication protocols, use only those communication protocols and only as specified.
Do not implement any other communication protocol.
When control system specifications do not indicate requirements for communication protocols, use only those protocols required for operation of the system as specified.
3.2.4 IP Control Networks
{For Government Reference Only: This subpart relates to CM-6(a), CM-7(a), CM-7(b), CM-7(1)(b), SC-41; CCI-001588, CCI-000381, CCI-000380, CCI-000381, CCI-000382, CCI-001761, CCI-001762, CCI-002544, CCI-002545, CCI-002546. For Moderate Impact Systems, this subpart (and its subparts) also relates to SC-5(1), SC-5(2); CCI-001094 CCI-001095 }
IP Networks must be Ethernet networks and must use switches which are Ethernet Switches or Daisy Chain IP Controllers as defined in this Section. Do not use nonsecure functions, ports, protocols and services as defined in DODI 8551.01 unless those ports, protocols and services are specifically required by the control system specifications or otherwise specifically authorized by the Government. Do not use ports, protocols and services that are not specified in the control system specifications or required for operation of the control system.
For MODERATE Impact Systems, unless explicitly authorized, do not use IP networks if the same control functionality is available through the use of non-IP networks.
3.2.4.1 IP Network Routers
Do not install any device that performs IP routing.
SECTION 25 05 11 Page 18
3.2.4.2 IP Devices With Multiple Ethernet Connection
Except for Ethernet Switches and Daisy Chain IP Controllers, devices must not have more than one Ethernet connection to IP networks unless doing so is required by the project specifications and the specific application is approved. If a device with Multiple Ethernet Connections to IP networks is required, provide a Multiple Ethernet Connection Device Request using the Multiple Ethernet Connection Device Request Template at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11 to request approval for each device. If a device with Multiple Ethernet Connections to IP networks is not required, instead provide a document stating that no approval is being requested.
3.2.5 Cryptographic Protection
{For Government Reference Only: This subpart relates to IA-2(9), IA-3(1), SC-8, SC-13, SC-23(1), SC-23(3); CCI-001942, CCI-001959, CCI-001967, CCI-002418, CCI-002449, CCI-002450, CCI-001185, CCI-001188, CCI-001664.}
All remote user interfaces must use HTTPS for all traffic between the user interface client and user interface server.
3.2.6 Device Identification and Authentication
{For Government Reference Only: This subpart (and its subparts) relates to IA-3; CCI-000777, CCI-000778, CCI-001958. For MODERATE Impact systems, this subpart (and its subparts) also relates to SC-23, SC-23(5);
CCI-001184, CCI-002470. }
All computers must support IEEE 802.1x for device authentication to the network.
3.2.6.1 For HVAC Control System Devices
Devices using HTTP as a control protocol must use HTTPS instead. Devices using Ethernet must support IEEE 802.1x . Devices using BACnet must support network security as specified for BACnet Secure Connect in
ASHRAE 135.
3.2.6.2 For Lighting Control System Devices
Devices using HTTP as a control protocol must use HTTPS instead. Devices using Fox Protocol must support IEEE 802.1x . Devices using Ethernet must support IEEE 802.1x . Devices using BACnet must support network security as specified for BACnet Secure Connect in ASHRAE 135.
3.2.6.3 Default Requirements for Control System Devices
For control system devices where Device Identification and Authentication requirements are not otherwise indicated in this Section: Devices using Ethernet must support IEEE 802.1x . Devices using HTTP as a control protocol must use HTTPS instead.
3.2.7 Cryptographic Module Authentication
{For Government Reference Only: This subpart (and its subparts) relates to IA-7; CCI-000803}
For devices (including but not limited to NIST FIPS 140-2 compliant
SECTION 25 05 11 Page 19 radios) that have STIG/SRGs related to cryptographic module authentication (CCI-000803), comply with the requirements of those STIG/SRGs.
3.3 ACCESS CONTROL REQUIREMENTS
3.3.1 User Accounts
{For Government Reference Only: This subpart (and its subparts) relate to AC-2(a), AC-3, AC-6(1), AC-6(10), AC-6(2), AC-6(9), CM-11(2), and IA-2;
CCI-002110, CCI-000213, CCI-002235, CCI-001558, CCI-002221, CCI-002222,
CCI-002223, CCI-002235, CCI-000039, CCI-001419, CCI-002234, CCI-001812,
and CCI-000764. For MODERATE Impact systems, this subpart (and its subparts) also relate to AC-2 (2), AC-2(3), AC-2(4), AC-6(1), and CM-5(1);
CCI-001361, CCI-000017, CCI-000217, CCI-000018, CCI-001403, CCI-001404,
CCI-001405, CCI-002130, CCI-001683, CCI-001684, CCI-001685, CCI-001686,
CCI-002132, CCI-001558, CCI-002221, CCI-002222, CCI-002223, CCI-001813. }
Any user interface supporting user accounts (either FULLY or MINIMALLY) must limit access according to specified limitations for each account.
Install and configure any device having a STIG or SRG in accordance with that STIG or SRG.
All user interfaces FULLY supporting accounts must implement user-based authentication where each account is uniquely assigned to a specific user. User interfaces FULLY supporting accounts must implement at least three (3) levels of user account privilege including: 1) an account with read-only permissions 2) an account with full permissions including account creation and modification and 3) an account with greater permissions than read-only but without account creation and modification.
3.3.1.1 Computers
All computer operating systems must FULLY support user…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .