Attachment 2 Performance Work Statement.pdf

PDF 404 KB Posted

Attached to
Electronic Security System Maintenance Support Services Federal contract opportunity
Solicitation number
SP330025Q0013
Issued by
Defense Logistics Agency Distribution

About this file

This document is a Performance Work Statement (PWS) for Electronic Security System (ESS) Maintenance Support Services at the Defense Logistics Agency (DLA) Distribution Puget Sound, WA (DDPW) location. The PWS outlines requirements for project management, operations and sustainment maintenance support, application, network, infrastructure and cybersecurity support for the Lenel OnGuard ESS, Closed Circuit Television (CCTV) systems, Mass Notification Systems (MNS), and Morse Watchman Keypro systems at the DDPW site. Key tasks include providing preventative and corrective maintenance, responding to service calls, maintaining configuration and asset management documentation, and meeting cybersecurity requirements. The contractor shall provide a Contract Project Manager, certified workforce, and all necessary labor, equipment, and materials to perform the work. The period of performance is a one-year base period with four one-year option periods.

View the file

Other files for this federal contract opportunity

Other files attached to Electronic Security System Maintenance Support Services, newest first.
File Type Posted
Amendment 0003.pdf PDF
Attachment 1 Schedule of Supplies.xlsx XLSX spreadsheet
Amendment 0001.pdf PDF
Attachement 5 Maintenance Task List.pdf PDF
Attachemnt 4 Wage Determination.pdf PDF
CSS SP330025Q0013.pdf PDF
Attachement 3 Equipment List.pdf PDF
Attachment 1 Schedule of Supplies.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CUI

SOURCE SELECTION INFORMATION – SEE FAR 2.101 AND 3.104

Performance Work Statement (PWS)

ELECTRONIC SECURITY SYSTEM MAINTENANCE SUPPORT SERVICES

Defense Logistics Agency (DLA) Distribution Puget Sound, WA (DDPW)

Controlled By: DLA Distribution J7-AF CUI Category(s): PROCURE Distribution / Dissemination Controls: FEDCON POC: Joseph Roe, Joseph.Roe@dla.mil

1.0 BACKGROUND

The Defense Logistics Agency (DLA) is a United States (U.S.) Department of Defense (DoD) agency providing worldwide logistics support to the missions of the Military Departments and the Combatant Commands.

In support of these missions, DLA Installation Management (DM) maintains a presence at DLA locations for the life, health, and safety systems including Electronic Security Systems (ESS) and Electronic Key Control Systems (EKC) which DM serves as the functional proponent for all ESS requirements, policy, and procedures.

ESS encompasses Intrusion Detection Systems (IDS), Access Control Systems (ACS), Closed Circuit Television (CCTV) systems, intercoms, and other alert type systems. EKC includes various type key control systems for DLA facilities, personnel and property.

2.0 SCOPE

This Performance Work Statement (PWS) outlines requirements for the project management, operations and sustainment maintenance support, application, network, infrastructure and cyber security and general requirements.

Specifically, for this effort the Contractor will provide technical services for DLA Distribution Puget Sound WA (DDPW) – Bremerton WA is a tenant activity on the Naval Base Kitsap-Bremerton WA.

The Contractor shall provide maintenance and repair services to include kind upgrades to include but not limited to daily operations testing, cybersecurity support and artifacts, upgrades, patches, migrations, enhancements, inspection and corrective and preventive maintenance. The Contractor shall assist with supporting information protection needs and system security requirements for Commercial Off the Shelf (COTS) ESS solutions.

When the DLA networks are utilized, all servers, switches, and workstations are provided by the Government.

Software/firmware, in all instances, shall be approved in writing by the DLA Contracting Officer Representative COR with coordination with the J6 Technical Point of Contact (TPOC) before procurement and installation.

3.0 TASK REQUIRMENTS

The Contractor shall adhere to the following requirements and definitions for all Tasks within this PWS:

3.1 TASK 1 – PROJECT MANAGEMENT

The Contractor shall provide sufficient project management to ensure that all contract task requirements are performed efficiently, accurately, on time, and in compliance with the requirements of this document. The Contractor shall support the following:

3.1.1 Contract Project Manager (CPM)

The Contractor shall provide a Contract Project Manager (CPM) who shall be responsible for the performance of the work. The CPM shall provide project management support for all contract personnel and all items detailed in this PWS. This support includes providing planning, direction, coordination, and the control necessary for effective and efficient accomplishment of all contract requirements. The CPM shall be the senior subject matter expert and monitor, control and report status on cost, schedule, and performance. The CPM will coordinate with the Contracting Officer (KO), the COR, and the J6 TPOC. The CPM shall attend meetings and provide support on task requirements as needed to meet the requirements of this contract. The CPM or alternate shall have full authority to act for the Contractor on all contract matters relating to the operations of this contract. The CPM or alternate shall normally be available as required Monday through Friday, excluding Federal holidays, between the hours of 0630 to 1500 HRS (3:00 PM) PST (local time). Most systems are “next business day” for support; however, in emergency situations support may be required within four (4) hours (emergency repairs). Upon request of the KO or COR, the Contractor shall provide personnel to meet on the installation as required to discuss problem areas break fix solutions and permanent solutions during the installation and testing period. provide maintenance and repair services (including in kind upgrades) on the site Lenel Electronic Security System (ESS), Closed Circuit Television Systems (CCTV), Mass Notification Systems (MNS), and Morse Watchman Keypro System.

3.1.2 Work Effort

The Contractor shall manage the total work effort associated with the PWS herein to assure fully adequate and timely completion of all Tasks including, but not limited to, planning, developing, and implementing project plans, scheduling, report preparation, communication and coordinating with stakeholders, escalation procedures, establishing and maintaining records, monitoring, and quality control. The Contractor shall provide an adequate staff of personnel with the necessary management expertise, training, and certifications to assure the performance of the work in accordance with sound and efficient management practices.

3.1.3 Work Control

The Contractor shall implement all necessary work control procedures to ensure timely accomplishment of work requirements, as well as to permit tracking of work in progress. The Contractor shall plan and schedule work to assure material, labor and equipment of all contracted items are available to complete work requirements within the specified time limits and in conformance with the quality standards established herein.

3.1.4 Enterprise Configuration Management (ECM)

The Contractor shall adopt DLA ECM plans ensuring all hardware and software changes are approved by the J6 TPOC and coordinated with the COR. The Contractor shall use the DLA enterprise ticketing system and Business Capability Management (BCM) ServiceNow (as of this writing), Change Implementation Plans (CIPs), and provide technical expertise in Enterprise Change Requests (ECRs) that addresses product management and version control for software (changes) and hardware (changes). The Contractor shall support business processes documentation such as Scheduled Maintenance Requests and Information Technology Operations Center (ITOC) notice (INFOSPOT) and all other control items such as customer notifications. The Contractor shall evaluate all changes to the approved system requirements baseline for risk to security, and for schedule and cost impact, provide evaluations in writing and with sufficient detail to allow for review and approval by the configuration governance structure as required. CIPs and ECRs are normally required 21 business days in advance of required change.

3.1.5 Configuration Audit

A configuration audit is an inventory of all hardware, software, data, drawings, devices, and technical documentation and is a function of configuration management. The Contractor shall perform a configuration audit and provide to the COR within ten (10) business days of performance start. Asset lists shall be provided upon request and include product details such as hosting location, model, versioning, product type, serial numbers, machine address code (MAC), and other available details about the product, software, hardware, or device. The Contractor shall report updates to asset list(s) within the monthly status reports. Additionally, a data dictionary is required.

3.1.6 Work Schedule

The Contractor shall schedule and arrange work to cause the least interference with the normal occurrence of Government business and mission. In those cases where some interference may be essentially unavoidable, the Contractor shall make every effort to minimize the impact of the interference, inconvenience, equipment downtime, interrupted service, and/or customer discomfort. Site visits for any Preventative Maintenance activities will be coordinated with the COR at least five (5) working days in advance. Non-scheduled visits will be coordinated with the COR at least five (5) working days in advance and notify the COR if the work being performed may cause interference.

Notification shall include the type of work to be done and the estimated completion date/time. The Contractor shall reschedule any work that the KO/COR deems necessary to avoid unacceptable disruptions in the Government's business.

3.1.7 Work Records/Reports/Authorizations/Checklists

The Contractor shall maintain management, configuration documentation, maintenance, repair records, and reports as set forth herein. All records and copies of reports, authorizations and checklists shall be turned over to the COR within (2) two working days upon request and/or after completion of respective work and prior to contract completion.

3.1.8 Staffing

Contractor shall maintain a certified work force to complete work in accordance with the time and quality standards specified.

3.1.9 Project Schedule/Plan

The Contractor shall create, maintain, and submit project plan(s)/schedule(s). Initial plans and schedules are due within five (5) business days after award and will be updated monthly (on 1st Monday of month) until the final inspection is completed. The Contractor shall create, maintain, and submit project plan(s)/ schedule(s) 15 business days following a request for any upgrade, installation, or replacement of device(s) and or application(s). Microsoft Project is the preferred software/format for project plans/schedules. Project plans/schedules shall include Task ID, Task Name, Actual Start, Actual Finish, Baseline Start, Baseline Finish, % complete, resource name/title, with the critical path defined utilizing predecessors and/or successors. The Government may return unacceptable plans and schedules for re-work, and the Contractor shall update and re-submit project plans and schedules within five (5) business days of request.

3.1.10 Meetings

The Contractor shall coordinate a post award Kickoff meeting prior to the initiation of work and conduct monthly In Process Review (IPR) meetings. These meetings will be held with the Contractor, CPM, KO, Contract Specialist (KS), COR, and the J6 TPOC to discuss an overview of Contractor’s plans to manage scope, schedule, and resources. The Contractor will discuss stakeholders’ expectations, details of contract execution including incident management, triage support, technology road map plans including current and future software/hardware landscape general conditions, project schedule/plan, work schedules, coordination, security, safety, deliverables, permits, and other matters pertinent to work accomplishments shall be discussed in this meeting. Contractor shall attend other meetings as required in support of contract tasks.

3.1.11 Phase In Training

A phase-in period shall be established to allow the Contractor sufficient time to integrate personnel and transition into duties required to perform the requirements of the contract and ensure employees who will require access to the Installation and Government Information Technology (IT) systems obtain a Common Access Card (CAC) In Accordance With (IAW) this PWS. Instructions for all Phase in Training are available upon request.

1. The phase-in period shall begin at the effective date of the contract and shall not exceed one (1) month, at which time full performance shall commence.

2. The Contractor shall ensure that all Contractor personnel are ready to begin working on the first day of full performance including obtaining any account access, permissions, and/or roles required to administer the application software/hardware. Training and documentation such as rules of behavior and cyber awareness may be required for accesses.

3. During the phase-in period, Contractor personnel shall complete security and safety training on site. Training will be scheduled through the DDPW site training office and will at a minimum include the following classes. Estimated time to complete is three (3) hours.

a. Active Shooter Briefing

b. Safety Briefing

c. Shelter in Place/Evacuation Awareness Briefing

4. During the one-month phased-in period to ensure all Contractor personnel know and understand regulations and policy pertaining to physical, information, operations, and personnel security.

The Contractor shall provide security and antiterrorism training to all employees in accordance with applicable DOD regulatory requirements. At a minimum, estimated in class time is eight

(8) hours, security training requirements as required by the DLA Issuances and other applicable DOD guidance, will be completed annually for the following on-line training. If the Contractor has previously taken this training valid copies of completion is allowed. At this time mandatory training classes are (training may vary):

a. Cyber Awareness Challenge

b. Antiterrorism (AT) Level 1

c. Operations Security (OPSEC)

d. Counterintelligence Awareness Training

e. Personally Identifiable Information Awareness

f. Trafficking in Persons

The security training is web-based, and access will be provided by the Government. The Contractor shall ensure Contractor personnel have taken the required security training to meet DoD guidance and that the personnel continue to maintain their certifications. The Government may add, delete, or change the annual training requirements.

3.1.12 Transition Support

The Contractor shall provide knowledge transfer and training to any follow-on provider to include all the necessary documentation, orientation, collaboration, and training to facilitate the comprehensive understanding and execution of tasks, processes, procedures, schedules, and deliverables in a timely and orderly fashion. All transition activities shall be coordinated with and approved by the COR. This task may start up to ninety days before the end of a base or option period.

The support services provided under this contract are critical to the DLA mission. It is vital that to ensure continuation of services without interruption or dramatic effort be provided. To maintain continuity of services the following requirements will be provided by the Contractor:

1. Continue to perform all services as prescribed within the PWS and existing Task Orders without reduction of manpower, quality of services and interruption to customers.

2. Provide a transition plan to include risks and costs associated with the transition of Contractor support within fifteen business days of request for a transition plan from the COR. The transition plan shall address impacts including:

a. Provide current active project transition services associated with any break/fix, upgrade, migration, and/or enhancements planned or in-process.

b. Assist secure required permission, roles, account accesses required for administration of software/hardware.

c. Provide landscape and asset documentation, data dictionaries, or other system documentation for DLA equipment, hardware, software, processes, and overall environment.

d. Provide transition cost analysis, propose schedules, and document risks associated with such transition.

3.2 TASK 2 – OPERATIONS, SUSTAINMENT, AND MAINTENANCE SUPPORT

The Contractor shall provide operations, sustainment, and maintenance support including Preventative Maintenance (PM) (scheduled), On-Call Corrective Maintenance (CM) (unscheduled), and technical services support of software/hardware including any required manufacturer support plan products.

Specifically, the Contractor shall provide the personnel, equipment, spares, mechanical hardware, software/firmware including licensing required for fully operational ESS systems including, but not limited to, testing, inspection, maintenance, services, patching, upgrading, migrating, and/or enhancing ESS systems. The DDPW Equipment List is provided to identify each piece of equipment and software that requires maintenance services and the PM schedule requirements. The DDPW Equipment List is subject to change by the government when the equipment addition(s) and/or deletions(s) are required due to the needs of the site.

Technical services support includes daily operations support, version upgrades, patching, security updates, enhancements, data migrations, and/or network migrations required for ESS systems. All required cyber updates and patches shall be done through Preventative Maintenance CLINs including Information Assurance Vulnerability Alert (IAVAs), Cyber Task Order (CTO), Assured Compliance Assessment Solution (ACAS) scan remediations or any other cyber requirements to include updating or creating any supporting cybersecurity documentation required for assessment and accreditation.

There is an ongoing effort of device upgrades, building consolidation and expansion, the government reserves the right at its discretion to add to or delete equipment from the ESS upgrade, maintenance, repair and support services contract anytime during the performance periods of the contract as needs arise without explanation with proper notification.

3.2.1 Operations

The Contractor shall support operations of systems including system monitoring, break/fix triage support, incident management, project management, configuration management and PM/CM required in day-to-day operations support. While a dedicated, onsite, full time equivalent (FTE) is not required - the Contractor may coordinate with the site to provide the necessary operations support for all ESS systems remotely, or onsite as needed, to meet the site’s requirements. The Contractor shall provide an Incident Response Plan (IRP) for incident management to the COR and J6 TPOC for approval.

3.2.2 Sustainment

The Contractor shall develop and implement a Sustainment Plan for all systems, subsystems, and equipment IAW with original equipment manufacturer and/or Federal/DoD/DLA policies and procedures. The Sustainment Plan shall include the periodic maintenance, repair, replacement, and overhaul of existing systems, hardware, and software including planned version upgrades of the application and Operating System (OS). The Contractor shall provide the Sustainment Plan which includes the PM schedule and Corrective Maintenance (CM) approach to the COR for approval within five (5) days of contract award. The Sustainment Plan should include:

1. Schedule of all maintenance and tests for a year

2. Positions, qualifications, and certifications of personnel, test equipment, and other pertinent information needed to quickly diagnose and make repairs.

3. Plans and documentation for systems testing and/or diagnoses.

4. Identify critical system operations and implement strategies to prevent potential failures or administrative downtime from creating a critical system outage.

5. Analyze fault histories and fault trends to proactively predict and mitigate repetitive issues.

6. Plan to respond to and take corrective action to resolve cybersecurity vulnerabilities and mechanical emergency repairs identified by the Contractor or the Government both during normal hours and after hours.

The Contractor will be responsible for all version upgrades, patching, device enhancements, device replacements that reach end of life/support and for device replacements of hardware equipment that does not meet cyber standards/requirements including migrations required for ESS systems compliance. As a software upgrade becomes available, the Contractor shall develop a plan for the upgrade and present that plan to the COR and J6 TPOC for written approval. Once approved, the Contractor shall work with the COR to execute their plan to install the upgrade(s) and return the ESS system(s) to an operational state.

The COR will coordinate with the J6 TPOC, as necessary, to support these efforts.

3.2.3 Maintenance

The Contractor shall perform Quarterly Preventive Maintenance (PM) services on all equipment which consists primarily of routine recurring inspection, testing, cleaning, lubrication, adjustment, and calibration to verify proper system operation to minimize malfunction, breakdown, and deterioration of systems and equipment. The Contractor shall submit and maintain an up-to-date schedule with status for all PM tasks. Any modifications, changes, additions, or deletions shall be submitted to the COR for approval and once approved and implemented, documented in as-built drawings, and provided to the site.

1. All battery voltage and charge levels shall be checked as part of any maintenance visit. Any battery incapable of maintaining a 75% charge shall be replaced immediately.

2. Within one (1) working day after completion of each Preventive Maintenance and Battery Maintenance event, the Contractor shall add the following information to the work authorization form and return to the COR:

a. Description of Preventive Maintenance work completed.

b. Brief description of material and parts used, including quantities.

c. Date and time work began.

d. Date and time work was completed.

e. Hours of labor (by trade) expended.

f. Signature or initials of the Contractor's craftsman performing the work (or supervisor), indicating that the work has been completed.

3.2.4 Service Call

1. Service calls are defined as emergent maintenance and repair work requirements which are identified by building occupants or generated by the COR. The Contractor shall perform service call work as necessary to determine the cause of system and equipment malfunctions, eliminate the cause(s), and restore the system or equipment to working condition.

2. The COR will advise the Contractor by phone or email of all service call requests received during and after regular working hours. A description of the problem or requested work, date and time received, location, classification, and other appropriate information will be placed on a Service Call Request.

3. The Contractor shall have adequate procedures for receiving and responding to service calls 24 hours per day, seven days per week, 365 days per year, including weekends and holidays. A single local or toll-free telephone number shall be provided by the Contractor for receipt of all service calls. All telephone calls shall be answered within 30 minutes by an individual fully familiar with the Contractor's work, control procedures, and the terms and conditions of this contract. Service calls shall be considered received by the Contractor at the time and date the telephone call is placed, or email is sent by the COR. The Contractor shall respond immediately and must be on the job site and working within four (4) hours after receipt of a service call. The Contractor shall work continuously without interruption and shall resolve the issue before departing the job site.

4. Within one (1) working day after completion of each service call, the Contractor shall add the following information to the work authorization form and return to the COR:

a. Description of work completed.

b. Brief description of material and parts used, including quantities.

c. Date and time work began.

d. Date and time work was completed.

e. Hours of labor (by trade) expended.

f. Signature or initials of the Contractor's craftsman performing the work (or supervisor), indicating that the work has been completed.

5. The Contractor shall have access to the materials and equipment necessary to support service call work requirements. Lack of availability of materials or equipment shall not relieve the Contractor from the requirement to complete service call work within the time limits specified above.

6. Replacement parts required in the performance of CM shall be invoiced to the Government in accordance with the terms and conditions of this contract (FAR 52.212-4 Alternate I).

The Contractor shall perform Corrective Maintenance (CM) services on all equipment which consists primarily of the non-recurring unscheduled repairs or services required to make the systems fully operational.

3.3 TASK 3 – APPLICATION, NETWORK, AND INFRASTRUCTURE SUPPORT

The Contractor shall support application network and infrastructure requirements including:

3.3.1 Application System and Network Requirements

The Government provides system administration support for most OS on the application server, database server and the client workstations. The Contractor shall receive a network assignment and provide all application-level support and provide the Government OS administration support as required. The Contractor shall support the following system and network requirements including, but not limited to:

1. All system/network components and applications shall be compatible with all applicable Defense Information System Agency (DISA) Security Technical Implementation Guides (STIGs). Any STIG exceptions must be identified as part of the Contractor’s proposal to the Government and approved by J6 Cybersecurity. Exceptions incurring risk found unacceptable to the DLA Authorizing Official are not permitted.

2. All network components and applications shall be IPv4 and IPv6 compatible.

3. Network components shall allow configuration of IEEE 802.1x or port security for authentication.

4. The Contractor shall provide a complete list of all ports, protocols and services required for any computer system running control system applications or required to interface the control system applications. The listing shall include all ports and services required for normal operation as well as any other ports and services required for emergency operation. The listing shall also include an explanation or cross reference to justify why each service is necessary for operation.

5. The Contractor shall identify any system wireless communication capability, enabled, or disabled. All wireless communications shall meet applicable STIG requirements to include FIPS 140-2 certification. Any requirement to use wireless or cellular must be approved in writing by DLA J6, coordinated with the J6 TPOC and documented with the DLA Frequency Manager.

6. All application wiring and/or cabling shall be in Electric Metal Tubing (EMT) type conduit.

7. The Contractor shall provide any patch cabling required.

3.3.2 Information and Operational Technology Infrastructure Requirements

In general, the DLA expects to furnish the IT Infrastructure to host the OT solution(s) and/or system(s) (including VLANs, and Virtual Machines (VMs)) unless there is a hardware, compatibility, or mission issue preventing it. As such, the Contractor must clearly identify “what” anticipated Government IT Infrastructure is required to host and operate the OT solution(s) and/or system(s) within the design documentation submitted for Government approval at time of award. These anticipated designs will be incorporated into the system CONOPs. The Contractor will be responsible for all installation, configuration, and deployment of the OT solution(s) and/or system(s) (including but not limited to) its subsystem(s), application(s), and patch cabling, if required.

Any requirement for the Contractor to provide their own IT Infrastructure, standalone server, or management workstation hardware due to compatibility issues must be documented in the Contractor’s proposal and approved by J6 prior to contract award. All Contractor provided IT Infrastructure must meet DoD STIG requirements. If the Contractor provides their own IT Infrastructure for the OT solution(s) and/or system(s), upon AO approval of the security authorization package (and prior to final OT solution(s) and/or system(s) acceptance or go-live), all Contractor provided IT Infrastructure will become the property of the Government.

All specialized software provided by the Contractor to the Government must have the applicable license key(s) as well as sales/transaction records, ownership control(s), manuals, technical publications, documentation, and any other information supporting ownership accompanying it. At the time of Contractor hand-off of Contractor owned IT Infrastructure to the Government, all design information for Enterprise Architecture (EA) for the “as built” OT solution(s) and/or system(s) will be provided. Any Contractor provided OS, software, and firmware throughout the duration of the contract will be upgraded by the Contractor prior to the Contractor’s end of mainstream support for the OS, software, or firmware.

DLA’s preference is for maximized virtual IT Infrastructure. As such, the Government will provide the virtual infrastructure to support deployment of Contractor supplied virtual servers or virtual appliance (OVA files). DLA will provide a virtual server up to the following:

1. CPU: 12 Cores

2. RAM: 32GB

3. Disk 1 (OS Drive): 150 GB

4. Disk 2 (Data Drive): 150 GB

Any requirements exceeding these specifications shall be submitted in writing and approved by DLA J6 with supporting documentation prior to contract award.

The Contractor will be responsible for the implementation including meeting all required STIG compliance.

The Contractor shall be responsible for all configuration and deployment which meet DoD, NIST and USG regulatory and cybersecurity policy requirements.

Any OT solution(s) and/or system(s) with IT Infrastructure provided by the Contractor must be upgradeable and remain compliant to cybersecurity specifications during the lifecycle of the solution.

Contractor supplied systems must meet DoD STIG requirements, with any exceptions noted in the design documentation.

The Contractor shall be responsible for all software updates, patches or necessary maintenance activities for any/all appliances including but not limited to, firmware updates, OS patching, software patches etc.

for the duration of the contract period.

The Contractor will be responsible for all physical maintenance activities for any/all appliances including but not limited to, replacement of defective components such as hard drives (to be destroyed onsite per DoD policy, guidance), motherboards, daughter cards etc. for the duration of the contract period.

Maintenance activities start after handover of the DLA Automation Solution to the DLA asset owner and may continue until the asset owner no longer requires them.

Activities are typically short and frequently recurring, and may include one of more of the following:

a. Patching and anti-virus updates

b. Equipment upgrades and maintenance, including small engineering adjustments not directly related to control algorithms

c. Component and system migration

d. Change management

e. Contingency plan management

System(s) shall operate using a fully supported operating system (OS), software, and firmware throughout the duration of the contract. All operating systems, software, and firmware shall be upgraded prior to the Contractor’s end of mainstream support for the operating system, software, or firmware. The solution must be upgradeable and remain compliant to DoD cybersecurity specifications during the lifecycle of the solution.

Any removable flash media required for system operation must be reviewed and approved in writing by the DLA J6 Flash Media Approval Program prior to implementation.

All OT solution(s) and/or system(s) must use the Purdue Enterprise Reference Architecture (PERA) Model for Control Hierarchy (reference ISBN 1-55617-265-6) to provide logical and/or physical architecture for networking, security hardware, software, and methods. The PERA Model is an industry standard for manufacturing and/or industrial control systems that segments hardware, devices, and equipment into a hierarchical based design.

The Contractor shall support the following application infrastructure requirements to include, but not limited to:

1. DLA shall furnish all application and database servers and laptop/workstation hardware as required. Any requirement for the Contractor to provide their own server or laptop/workstation hardware due to compatibility issues shall be documented in the proposal and approved by the J6 TPOC and Information System Security Manager (ISSM) prior to any procurements and/or network installations. Contractor supplied systems must meet DoD STIG requirements, with any exceptions noted in their proposal. The application software shall be capable of operating on DLA’s approved operating systems, virtual environments, and databases listed below:

a. Workstations/laptops shall operate on Windows 10 or 11 higher, with minimum system requirements of: processor: Intel i5 -1145G7 @ 2.6 GHZ, 4 Cores, RAM: 8GB, Hard Drive:

256 GB.

b. Windows Server 2016 or 2019 Operating System (OS) (or higher versions).

c. For virtualized appliances or virtualized servers, the system shall be capable of running on

VMware ESX and vSphere 7.0 virtual server environment (or higher versions). Database shall operate using SQL Server 2016 or 2019 (or higher versions).

d. System must be capable of operating with McAfee ePolicy Orchestrator enabled.

2. Application video appliance(s) and network recording requirements:

a. In some instances (such as video surveillance) where there is a requirement for a large amount of storage, the preferred solution will be available as an appliance that includes compute/storage in one physical appliance that meets DoD, National Institute of Standards and Technology (NIST) and Under Secretary General (USG) regulatory and cybersecurity policy requirements.

b. The appliance will not be used as a combined server and shall be sized adequately to store video feed data for a minimum of 180 calendar days.

c. All videos will be stored under the DLAM 5200.08 guidance.

d. The Contractor shall be responsible for configuration and deployment.

e. All operating systems, software, and firmware shall be upgraded and patched to the latest version prior to the Contractor’s end of mainstream support for the OS, software, or firmware.

f. The solution must be upgradeable and remain compliant to cyber security specifications during the lifecycle of this contract period.

3.4 TASK 4 - CYBERSECURITY REQUIREMENTS

The Contractor shall provide cybersecurity (CS) in accordance with all current policies, procedures, and statutes, to include (but not restricted to) the following, as applicable, to specific task orders (most current version): The Contractor shall provide cybersecurity that is in accordance with current policies, procedures, and statutes, to include, but not limited to, the following or most current version:

System Identification Reference Documents:

a. Committee on National Security Systems Instruction 1253, Security Categorization and Control

Selection for National Security Systems, July 29, 2022

b. Federal Information Processing Standards Publication 199, Standards for Security Categorization of Federal Information and Information Systems, February 2004

c. Federal Information Processing Standards Publication 200, Minimum Security Requirements for

Federal Information and Information Systems, March 2006

d. Federal Information Security Management Act (P.L. 107-347, Title III), December 2002

e. Department of Defense Instruction 5000.02, Operation of the Defense Acquisition System, January 23, 2020

f. Department of Defense Instruction 5200.39, Critical Program Information (CPI) Identification and

Protection within the Research, Development, Test, and Evaluation (RDT&E) Incorporating Change 3, Effective October 1, 2020

System Compliance, Instructions and Guidelines Reference Documents:

a. 44 U.S.C. § 3542, January 2012

b. Department of Defense Instruction 8510.01, Risk Management Framework (RMF) for DoD

Information Technology, July 19, 2022

c. Department of Defense Instruction 5200.44, Protection of Mission Critical Functions to Achieve Trusted Systems & Networks, Incorporating Change 3, October 15, 2018

d. DoD Program Manager’s Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) into the System Acquisition Lifecycle

e. Defense Acquisition Guidebook (DAG)

f. Department of Defense Directive 8140.01, Cyberspace Workforce Management, October 5, 2020

g. Department of Defense Instruction 8330.01, Interoperability of Information Technology (IT), Including National Security Systems (NSS), September 27, 2022

System Cybersecurity Implementation Reference Documents:

a. Department of Defense Instruction 8580.1, Information Assurance (IA) in the Defense Acquisition

System, July 9, 2004

b. National Institute of Standards and Technology Special Publication 800-82 Revision 2, Guide to

Industrial Control Systems (ICS) Security, February 2015

c. UFGS-25 50 00.00 20 Cybersecurity of Facility-Related Control Systems

d. United Facilities Criteria (UFC) 4-010-06, Cybersecurity of Facilities-Related Control Systems

Personnel Requirements Reference Documents:

a. DoD Manual (DoDM) 8140.03 Cyberspace Workforce Qualification & Management Program, dated 15 Feb 2023

FRCS Guidelines Reference Documents:

a. Deputy Under Secretary of Defense (Installations and Environment) Memo dated 19 Mar 14, subject: Real Property Related ICS Cybersecurity

b. Defense Logistics Agency Risk Management Framework Standard Operating Procedures, April

c. Office of the Assistant Secretary of Defense Facility Related Control Systems (FRCS) Master List

Memo, October 2020

d. Department of Defense Control Systems Security Requirements Guide Version 1, Release 1, July

14, 2021

3.4.1 Cybersecurity Tasks and Deliverable

The Contractor shall provide required implementation and design documentation to the DLA PM and security engineering teams to conduct a cybersecurity risk assessment (RA) of proposal. Results from accepted RAs will be incorporated into the Systems concepts of operations (CONOPs).

The Contractor, in collaboration with assigned security manager, PM and system owner, shall identify and document applicable cybersecurity enterprise architectures and deliver system conceptual design drawings.

The Contractor shall leverage, to the greatest extent possible, DLA Enterprise processes and capabilities.

The Contractor shall provide the following accreditation artifacts:

a. System Diagrams

Architecture Network Diagram Authorization Boundary Diagram Data Flow Diagram Purdue Diagram

b. Comprehensive Hardware Inventory Report

c. Comprehensive Software Inventory Report

d. Concept of Operations (CONOPS)

e. Plan of Actions and Milestones (POAM)

f. Software Upgrade and Support Plan (SUSP)

g. Ports, Protocols, and Services Management (PPSM) Documentation for Registration

h. Federal Information Processing Standard 199 (FIPS-199) Cybersecurity Strength

Requirements

i. PII Confidentiality Impact Level (PCIL) Categorization Worksheet

j. Enterprise Configuration Management Plan

k. Security Technical Implementation Guide (STIG) and Security Requirement Guides (SRG)

Mitigations

3.4.2 Cybersecurity Strength Requirements

The Contractor shall provide the following cybersecurity strength requirements including, but not limited to the following:

1. The Contractor shall adhere to all existing authorities and policies of the Director of National Intelligence regarding the protection of sensitive compartmented information (SCI), as directed by Executive Order 12333 and other laws and regulations.

2. The Contractor shall satisfy the Risk Management Framework (RMF) requirements of subchapter III of chapter 35 of Title 44, United States Code (U.S.C.), also known as the “Federal Information Security Management Act (FISMA) of 2002”.

3. The Contractor shall enable DLA to meet the standards required by the Office of Management and Budget (OMB) and the Secretary of Commerce, pursuant to FISMA and section 11331 of Title 40, U.S.C.

4. FIPS 199 / CNSSI 1253 Security Categorization: The Contractor shall participate in categorization discussions with the DLA J6 TPOC, functional lead, and the Information System Security Manager (ISSM) and provide all required FIPS 199 documentation as requested to support security categorization.

5. The Contractor shall provide a recommendation on system categorization based on sound technical expertise in accordance with FIPS 199 then work in coordination with the prescribed DLA System Owner (SO) and ISSM to support the categorization IAW FIPS 199, CNSSI 1253 and OSD Facility Related Control Systems (FRCS) Master List including DLA specific systems, then document the results of the security categorization in the System DLA FIPS 199 document and the Concept of Operations (CONOPs).

6. DLA J6 COR will coordinate with the Contractor to identify and document Confidentiality, Availability, Integrity (CIA) of the system in a DLA FIPS 199 document for approval by DLA J6 ISSM personnel.

3.4.3 Completion Of System Hardening (Scan/Fix/Scan) Testing and Analysis The Contractor shall harden systems using a scan, fix, scan methodology remediating findings IAW current DOD, DLA, and Defense Information Systems Agency (DISA) standards. This includes automated and manual STIG application, Assured Compliance Assessment Solution (ACAS) scanning, WebInspect, and any other hardening efforts required to make the system ready to connect to a DOD network. Whenever findings occur, as required periodically, and/or following any major system change, the Contractor shall scan/fix/scan until all issues have been fixed and/or properly and acceptably mitigated. Any Critical or High impact level findings that cannot be fixed are to be reported to the J6 TPOC/ISSM immediately along with a valid reason the vulnerability cannot be fixed and a POAM.

Once the Contractor has completed hardening efforts, system monitoring and audits shall occur to ensure STIG compliance is maintained.

Upon connection to the production network, the Contractor is expected to maintain the current approved settings. The Contractor is expected to notify the J6 TPOC/ISSM of any known published system patches and OS updates that will negatively impact the cybersecurity posture of the system. Any identified issues should be documented in advance to the J6 TPOC/ISSM with a valid reason the system patch or OS update cannot be applied and a mitigation plan to fix the pending vulnerability with the date to be fixed.

3.4.4 Cybersecurity Assurance Requirements

The Contractor shall design, develop, and integrate cybersecurity solutions supporting the Department of Defense and all other applicable Government agencies.

This will be achieved through abiding by all applicable cybersecurity policies, regulations, and directives to ensure a favorable Assessment and Authorization (A&A), Assessment and Incorporate (A&I), or FRCS Assess Only Risk Assessment decision, as well as obtaining an Authority to Connect (ATC) to DLA’s network. The Contractor shall mitigate risk identified through the RMF authorization process down to a level acceptable to the DLA Authorizing Official (AO).

Coding for Security. The Contractor shall provide documentation of development practices and standards applied to Government approved Contractor-written control system software, including firmware, used to ensure a high level of defense against unauthorized access.

The solution shall comply with the security control requirements documented in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53r4, “Security and Privacy Controls for Federal Information Systems and Organizations” and NIST 800-82r2, “Guide to Industrial Control Systems (ICS) Security”. The Contractor shall provide details of any alternative but equally effective security measures used to compensate for the inability to satisfy a particular derived security requirement (mitigation to control compliance findings). This information shall be submitted in writing to the DLA J6 for cybersecurity approval as soon as the alternative is identified.

Typical Contractor services activities include:

a. Analyzing DLA physical, electrical, computerized, and mechanical environments the identified FRCS solution will control (e.g., the physical Operational process to be controlled, such as those used in manufacturing, metering and robotics)

b. Developing a DLA Automation Solution FRCS architecture in terms of devices, dataflow, and control loops, outlining interconnectivity with engineering and operator workstations, and Safety Instrumented Systems (SISs) for testing; testing shall be in accordance with DoD Control Systems Security Requirements Guide (SRG), and other identified DLA test processes.

c. Defining how the DLA FRCS Automation Solution will connect to external (e.g., plant) and networks, by system description, concept, and dataflow diagram on Perdue Levels. Guidance on the applicability of Purdue Enterprise Reference Architecture (PERA) levels are found in the United Facilities Criteria (UFC) 4-010-06, Cybersecurity of Facilities-Related Control Systems.

e. Installing, configuring, patching, backing up, and testing for DLA handover of the Automation Solution to the DLA asset owner for operation.

f. Gaining approval of the DLA asset owner for many of the decisions made and outputs generated during the execution of these activities.

The Contractor shall protect unclassified DoD data from unauthorized access or disclosure in accordance with DoDI 8582.01, “Security of Unclassified Information on Non-DoD Information Systems.” Controlled Unclassified Information: All Government controlled unclassified information obtained by the Contractor shall be protected in accordance with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations”.

Agencies or Military Services providing external information system services must comply with DLA information security requirements and employ overlayed security controls in accordance with applicable federal laws, Executive Orders, directives, instructions, policies, regulations, standards, and guidance.

To support cybersecurity assessments and monitoring, the contractor may be required to get access to eMASS and may be required to review and input various information in eMASS.

3.5 GENERAL REQUIREMENTS

This Section provides general information relating to the conditions of operation and general requirements relating to this PWS.

1. This is a non-personal services contract. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government. The Government and the Contractor understand that the services to be provided under this contract by the Contractor are non-personal services and that no employer-employee relationship exists between the Government and the Contractor. The Government may provide technical direction which will assist the Contractor in accomplishing the PWS; however, the Government will not control the methods used by the Contractor to perform the service requirements set forth in the PWS.

2. The Contractor shall furnish all labor, supervision, tools, materials, equipment, transportation, and management necessary for completion of items within this PWS.

3. The Contractor shall be an authorized, licensed service representative for the applications used and comply with all applicable DoD, Federal, State, and local laws. The Contractor shall maintain updated copies of any applicable licenses and certifications for all employees and make them available to the Government upon request.

4. With the ongoing efforts keeping up with cyber and enterprise infrastructure updates, the Government reserves the right to ADD to or DELETE from the contract anytime during the period of the contract as the need arises.

5. The Contractor shall submit an Accident Prevention Plan to the Contracting Officers Representative (COR). No work shall start prior to COR receiving the approved Accident Prevention Plan.

6. The Contractor shall turn over any equipment or material removed through this task to the Government at the completion of work, or after COR approval, properly dispose of in accordance with regulations and/or local codes.

7. The Contractor shall maintain a separate set of drawings, elementary diagrams, and wiring diagrams of the system to be used for As-Built Drawings and shall keep this set accurately and neatly up to date with all changes and additions throughout the contract. As-Built Drawings shall be developed and maintained by the Contractor and depict actual conditions. As-Built Drawings are to be submitted to the COR in original Auto Computer Aided Design (AutoCAD) and Adobe Portable Document Format (PDF) format and shall not be overlays. A complete As- Built Drawing will be submitted to the Government within fourteen calendar days of completed work.

8. The Contractor will provide a monthly status report which shall include, but not limited to:

a. Contract number

b. Brief task description

c. Review of project plans including work accomplished during the reporting period and/or significant events

d. Project progress

e. Problem areas

f. Anticipated activity for the next reporting period

g. Project Schedule/Plan

h. Configuration Management Plan

i. Configuration Audit

j. 8140 Report Spreadsheet

k. Contractor Quality Control Plan

l. Data Dictionary

9. The Contractor shall follow all applicable National Electrical Code (NEC), Unified Facilities Criteria (UFC), United Technologies Corporation (UTC), National Fire Protection Association

(NFPA), and Security Standards.

10. The Contractor will follow all Security Technical Implementation Guides (STIGs), Data

Encryption standards, Intelligence Community Directive (ICD)/ Intelligence Community Standard (ICS) 705, DLA Physical Security Manual and DLA building codes.

11. The Contractor shall obtain written COR approval if any digital or physical media is required.

All video, still photos, digital photos, all usernames, passwords, and any other documentation obtained and developed during the execution of this contract shall be turned over to the Government with all digital and hard copy files and associated negatives at the completion of this project. Digital photographs shall be submitted to the Government on Compact Disk (CD) in Joint Photographic Experts Group (JPG) format, and the Contractor shall delete all associated files from their records.

12. For any ESS/EKC related incidents that impacts or has the potential to impact DLA’s customers or partners, the Contractor will create/report and update Infospots.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .