Attachment 2 - Technical Specifications.pdf
PDF 309 KB Posted
- Attached to
- Vindicator IDS for Building 4430 Federal contract opportunity
- Solicitation number
- FA480921Q0108
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| B4430 Questions Responses.docx | DOCX document | |
| Attachment 6 - Provisions and Clauses.pdf | ||
| Attachment 5 - Brand Name Justification - Below the SAT-Bldg 4430_Redacted.pdf | ||
| Attachment 1 - SOW.pdf | ||
| Attachment 4 - Air Force-approved Equipment List.pdf | ||
| Combo_ 4430 IDS - Vindicator.docx | DOCX document | |
| Attachment 3 - Floorplan.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Technical Specifications for Construction and Management of Sensitive Compartmented
Information Facilities
VERSION 1.5
IC Tech Spec – for ICD/ICS 705
An Intelligence Community Technical Specification Prepared by the
National Counterintelligence and Security Center
, 20
Chapter 7 Intrusion Detection Systems
Chapter 7. Intrusion Detection Systems (IDS)
A. Specifications and Implementation Requirements
1. General SCIF IDS Requirements
a) SCIFs shall be protected by IDS when not occupied.
b) Interior areas of a SCIF through which reasonable access could be gained, including walls common to areas not protected at the SCI level, shall be protected by IDS. However, these adjacent areas do not need IDS protection if the AO determines that a facility’s security programs consist of layered and complementary controls sufficient to deter and detect unauthorized entry and movement.
c) Doors without access control systems and that are not under constant visual observation shall be continuously monitored by the IDS.
d) If any component of the IDS is disrupted to the extent the system no longer provides essential monitoring service (e.g., loss of line security, inoperable Intrusion Detection Equipment (IDE), or loss of power), SCI-indoctrinated personnel shall physically occupy the SCIF until the system is returned to normal operation. As an alternative, the outside SCIF perimeter may be continuously monitored by a response or guard force.
e) IDS failure shall be addressed in the SCIF emergency plan.
2. System Requirements
a) IDS installation related components and monitoring stations shall comply with Underwriters Laboratories (UL) Standard for National Industrial Security Systems for the Protection of Classified Material, UL 2050.
b) Installation shall comply with an Extent 3 installation as referenced in UL 2050.
c) Systems developed and used exclusively by the USG do not require UL certification, but shall nonetheless comply with an Extent 3 installation as referenced in UL 2050.
d) Areas of a SCIF through which reasonable access could be gained, including walls common to areas not protected at the SCI level, shall be protected by IDS consisting of UL 639 listed motion sensors and UL 634 listed High Security Switches (HSS) that meet UL Level II requirements and/or other AO-approved equivalent sensors. All new SCIF accreditations shall use UL Level II HSS. Existing UL Level I HSS are authorized until major IDS modifications/upgrades are made.
e) IDE cabling that extends beyond the SCIF perimeter shall employ Encrypted Line Security or be installed in a closed and sealed metal conveyance defined as a pipe, tube or the like constructed of ferrous Electrical Metallic Tubing (EMT), ferrous pipe conduit or ferrous rigid sheet metal ducting. All joints and connections shall be permanently sealed completely around all surfaces (e.g. welding, epoxy, fusion, etc.).
Set screw shall not be used. The seal shall provide a continuous bond between the components of the conveyance. If a service or pull box must be utilized, it must be secured with a GSA approved combination padlock or AO approved key lock.
f) SCIFs that share common or contiguous perimeter and support the same IC Element, or have an established Co-Use-Agreement (CUA), may have the Premise Control Unit (PCU) programmed into multiple logical units or partitions, of the same PCU, that function as individual control units for the intrusion detection system installed in multiple areas or rooms operated independently of one another. All conditions of compliance that apply to a PCU and IDS apply equally to the partitions of the PCU. The PCU shall be independent of IDS safeguarding non-UL 2050 certified areas.
g) If a monitoring station is responsible for more than one IDS, there shall be an audible and visible annunciation for each IDS.
h) IDS’s shall be separate from, and independent of, fire, smoke, radon, water, and other systems.
i) If the IDS incorporates an access control system (ACS), notifications from the ACS shall be subordinate in priority to IDS alarms.
j) System key variables and passwords shall be protected and restricted to U.S. SCI-indoctrinated personnel.
k) IDS technical drawings, installation instructions, specifications, etc., shall be restricted as determined by the AO and documented in the CSP.
l) Systems shall not include audio or video monitoring without the application of appropriate countermeasures and AO approval.
m) Monitoring systems containing auto-reset features shall have this feature disabled.
n) Alarm activations shall remain displayed locally until cleared by an authorized SCI-cleared individual.
o) The AO shall approve all system plans. Final system acceptance testing shall be included as part of the SCIF accreditation package.
p) False alarms shall not exceed one alarm per 30-day period per IDS partition.
False alarms are any alarm signal transmitted in the absence of a confirmed intrusion that is caused by changes in the environment, equipment malfunction or electrical disturbances. If false alarms exceed this requirement, a technical evaluation of the system shall be conducted to determine the cause, repaired or resolved, and documented.
3. System Components
a) Sensors
(1) All system sensors shall be located within the SCIF, except as noted in 3.a.(2) below.
(2) With AO approval, sensors external to the SCIF perimeter may be installed in accordance with paragraph A.2.e.
(3) Failed sensors shall cause immediate and continuous alarm activation until the failure is investigated and corrected by procedures as documented in the SCIF SOP or Emergency Action Plan.
(4) Dual technology sensors are authorized when each technology transmits alarm conditions independent of the other technology.
(5) A sufficient number of motion detection sensors shall be installed to meet the requirements of paragraph A.2.d or shall be approved by the AO. However, for facilities outside the U.S. and in Category I and II countries, motion detection sensors above false ceilings or below false floors may be required by the AO.
(6) When the primary entrance door employs a delay to allow for changing the system mode of access, the delay shall not exceed 30 seconds.
(7) SCIF perimeter doors shall be protected by an HSS and a motion detection sensor.
(8) Emergency exit doors shall be alarmed and monitored 24 hours per day.
b) Premise Control Units (PCUs)
(1) PCUs shall be located within a SCIF and only SCIF personnel may initiate changes in access modes.
(2) Operation of the access/secure switch shall be restricted by using a device or procedure that validates authorized use.
(3) Cabling between all sensors and the PCU shall be dedicated to the system, be contained within the SCIF, and shall comply with national and local electric codes and Committee for National Security Systems (CNSS) standards. If the wiring cannot be contained within the SCIF, such cabling shall meet the requirements for External Transmission Line Security 3.b.(10) below.
(4) Alarm status shall be continuously displayed with an alphanumeric display at the PCU and/or monitoring station.
(5) Every effort shall be made to design and install the alarm-monitoring panel in a location that prevents observation by unauthorized persons.
(6) The monitoring station or PCU shall identify and display activated sensors.
(7) Immediate and continuous alarm annunciations shall occur for the following conditions.
(a) Intrusion Detection
(b) Failed Sensor
(c) Tamper Detection
(d) Maintenance Mode (a maintenance message displayed in place of an alarm)
(e) IDE Sensor Points shunted or masked during maintenance mode
(8) A change in power status (AC or backup) shall be indicated locally and at the monitoring station.
(9) All system events shall be reset by authorized SCI-indoctrinated personnel after an inspection of the SCIF and a determination for the cause of the alarm.
Any auto-alarm reset feature of the IDS shall be disabled.
(10) IDS transmission lines leaving the SCIF to the monitoring station, must meet National Institute of Standards and Technology, Federal Information Processing Standards (FIPS) for certified encrypted lines. The FIPS standard employed must be noted on the UL 2050/CRZH Certificate or other certificate employed. PCUs certified under UL 1610 must meet FIPS 197 or FIPS 140-2 encryption certification and methods. For PCUs certified under UL1076, only FIPS 140-2 is the acceptable encryption certification and method. Alternative methods shall be approved by the AO and noted on the IDS Certificate
(11) The SCI cleared IDS Administrator(s) shall change maintenance and master profiles, PINs or passcodes from their default settings to a unique PIN or passcode.
c) Integrated IDS and Remote Terminal Access.
(1) US government LAN or WAN requires the AO’s Chief Information Officer (CIO) to be consulted before connecting an IDS. The system hosting the IDS shall be issued Authority to Operate (ATO) by the agency CIO, following the FISMA Risk Management Framework as outlined in NIST SP 800-53.
(2) For IDS that have been integrated into a networked system (local area network (LAN) or wide area network (WAN)), the requirements below shall be met.
(a) IDS System software shall be installed on a host computing device that is logically and physically restricted to corporate/government security elements cleared to the SCI level. The host device shall be located in a Physically Protected Space, which is defined as a locked room with walls, floor and ceiling that are fixed in place forming a solid physical boundary to which only SCI-cleared personnel have access. If uncleared personnel or personnel with less than SCI indoctrination require access to this space, they shall be escorted by authorized SCI-cleared personnel. The door(s) shall use Commercial Grade 1 hardware fitted with high security key cylinder(s) in compliance with UL 437. This room will be protected by a UL Extent 3 burglar alarm system and access control unless manned 24 hours.
(b) All system components and equipment shall be isolated in a manner that may include, but are not limited to firewalls, Virtual Private Networks, Virtual Routing Tables, Application Level security mechanisms or similar enhancements, that are configured to allow secure and private data transfers only between the PCU, host computer, remote terminal and monitoring station.
(c) If any component of the IDS is remotely programmable, continuous network monitoring is required. Continuous network monitoring includes auditing and reporting of network intrusion detection and prevention systems used in A.3.c.2.b.
(d) A secondary communication path may be utilized to augment an existing data communication link to reduce investigations of data communication failures of less than five minute duration. The supervision provided by the secondary communication path shall be equivalent to that of the primary communication path. The secondary communications path may only be wireless if approved by the AO in consultation with the CTTA and/or the appropriate technical authority.
(e) A unique user ID and password is required for each individual granted access to the system host computing devices or remote terminal. Passwords shall be a minimum of twelve characters consisting of alpha, numeric, and special characters, and shall be changed every six months or utilize US Government Personal Identity Verification (PIV) Card or Common Access Card (CAC) with two factor certificate authentication.
(f) Individuals with IDS administrative access shall immediately notify the AO or designee of any unauthorized modifications.
(g) All transmissions of system information over the LAN/WAN shall be encrypted using National Institute of Standards and Technology (NIST) FIPS 140-2, VPN, or closed and sealed conveyance (see A.2.e). FIPS-197 (AES) may be used with AO approval.
(h) Remote System terminals shall:
Utilize role based user permissions (e.g. Super User, SO, Guard) as approved by the AO. USG installations shall be in compliance with paragraph 7.A.3.c.1Prohibit Non SCI Cleared personnel from modifying the IDS or ACS.
Require an independent user ID and password in addition to the host login requirements. Requirements for IDS Systems Software Passwords shall be: a unique user ID and password for each individual granted access to the remote terminal. Passwords shall be a minimum of twelve characters consisting of alpha, numeric, and special characters and shall be changed every six months or utilize US Government Personal Identity Verification (PIV) Card or Common Access Card (CAC) with two factor certificate authentication if supported by the application.
Host systems shall log and monitor failed login attempts. All remote sessions shall be documented and accessible to AO upon request.
All Host systems and PCUs shall be patched and maintained to implement current firmware and security updates. USG systems shall be in compliance with Information Assurance Vulnerability Alert (IAVA) guidance.
B. IDS Modes of Operation
1. General Information
a) The system shall operate in either armed or disarmed mode.
b) There shall be no remote capability for changing the mode of operation by non- SCI cleared personnel.
c) Changing arm/disarm status of the system shall be limited to SCI-indoctrinated personnel.
2. Requirements for Disarmed Mode
a) When in disarmed mode, normal authorized entry into the SCIF, in accordance with prescribed security procedures, shall not cause an alarm.
b) A record shall be maintained that identifies the person responsible for disarming the system.
c) Tamper circuits and emergency exit door circuits shall remain in the armed mode of operation.
d) The PCU shall have the ability to allow alarm points to remain in armed status while other points are in disarmed status.
3. Requirements for Armed Mode
a) The system shall be placed into armed mode when the last person departs the
SCIF.
b) A record shall be maintained identifying the person responsible for arming the system.
c) Each failure to arm or disarm the system shall be reported to the responsible SCIF Security Manager. Records of these events shall be maintained for two years.
d) When in the armed mode, any unauthorized entry into the SCIF shall cause an alarm to be immediately transmitted to the monitoring station.
4. Requirements for Maintenance and Zone Shunting/Masking Modes
a) When maintenance is performed on a system, the monitoring station must be notified and logged. The initiation of system maintenance can only be performed by an SCI cleared IDS administrator or SCIF Security Officer (SO).
b) When an IDE point is shunted or masked for reasons other than maintenance, it shall be displayed as such at the monitoring station throughout the period the condition exists.
c) Any sensor that has been shunted shall be reactivated upon the next change in status from armed to disarmed.
d) All maintenance periods shall be archived in the system.
e) A Personal Identification Number (PIN) is required, for maintenance purposes, to be established and controlled by the SCI cleared IDS administrator or SCIF SO.
Procedures shall be documented in the SCIF SOP.
f) Portable Electronic Devices (PEDs) are allowed attachment to system equipment either temporarily or permanently for the purposes of system maintenance, repair and reporting (See A.3.c). In addition, when utilizing a stand-alone device, the requirements below shall be met.
(1) Such devices shall be kept under control of SCI-cleared personnel.
(2) When not in use, the PED shall be maintained in a Physically Protected Space (see A.3.c.2.a).
(3) Mass storage devices containing SCIF alarm equipment details, configurations, or event data will be protected at an appropriate level approved by the AO.
g) After the initial installation, the capability for remote diagnostics, maintenance, or programming of IDE shall be accomplished only by SCI-cleared personnel and shall be logged or recorded.
5. Requirements for Electrical Power
a) In the event of primary power failure, the system shall automatically transfer to an emergency electrical power source without causing alarm activation.
b) Twenty-four hours of uninterruptible backup power is required and shall be provided by batteries, an uninterruptible power supply (UPS), generators, or any combination.
c) An audible or visual indicator at the PCU shall provide an indication of the primary or backup electrical power source in use.
d) Equipment at the monitoring station shall visibly and audibly indicate a failure in a power source or a change in power source. The individual system that failed or changed shall be indicated at the PCU or monitoring station as directed by the AO.
6. Monitoring Stations
a) Monitoring stations shall be government-managed or one of the following in accordance with UL 2050:
(1) AO-operated monitoring station.
(2) Government contractor monitoring station (formerly called a proprietary central station).
(3) National industrial monitoring station.
(4) Cleared commercial central station (see NISPOM, Chap. 5).
b) Monitoring station employees shall be eligible to hold a U.S. SECRET clearance.
c) Monitoring station operators shall be trained in system theory and operation to effectively interpret system incidents and take appropriate response action.
d) Records shall be maintained shall be maintained in accordance with Chapter 12 section L.
C. Operations and Maintenance of IDS
1. Alarm Response
a) Alarm activations shall be considered an unauthorized entry until resolved.
b) The response force shall take appropriate steps to safeguard the SCIF, as permitted by a written support agreement, until an SCI-indoctrinated individual arrives to take control of the situation.
c) An SCI indoctrinated individual must arrive in accordance with UL 2050 requirements (60 minutes) or the response time approved by the AO, after receipt of the alarm signal to conduct an internal inspection of the SCIF, attempt to determine the probable cause of the alarm activation, and reset the IDS prior to the departure of the response force.
2. System Maintenance
a) Maintenance and repair personnel shall be escorted if they are not TOP SECRET-cleared and indoctrinated for SCIF access.
b) Repairs shall be initiated by a service technician within 4 hours of the receipt of a trouble signal or a request for service.
c) The SCIF shall be continuously manned by SCI-indoctrinated personnel on a 24-hour basis until repairs are completed or alternate documented procedures approved by the AO are initiated.
d) The following apply to emergency-power battery maintenance:
(1) The battery manufacturer’s periodic maintenance schedule and procedures shall be followed and documented in the system’s maintenance logs and retained for two years. Batteries should be replaced per manufacture’s recommendations or as environmental conditions dictate.
(2) If the communications path is via a network, the local uninterruptible power source for the network shall also be tested.
(3) If a generator is used to provide emergency power, the manufacturers recommended maintenance and testing procedures shall be followed.
e) Network Maintenance
(1) System administrators shall maintain configuration control, ensure the latest operating system security patches have been applied, and configure the operating system to provide a high level of security.
(2) Inside the U.S., network maintenance personnel within a SCIF shall be a U.S.
person and be escorted by cleared SCIF individuals.
(3) Outside the U.S., network maintenance personnel shall be U.S. TOP SECRET-cleared or U.S. SECRET-cleared and escorted by SCIF personnel.
D. Installation and Testing of IDS
1. Personnel Requirements
a) Installation and testing within the U.S. shall be performed by U.S. companies using U.S. citizens.
b) Installation and testing outside of the U.S. shall be performed by personnel who are U.S. TOP SECRET-cleared or U.S. SECRET-cleared and escorted by SCIF personnel.
2. Installation Requirements
All system components and elements shall be installed in accordance with requirements of this document, UL 2050, and manufacturer’s instructions and standards.
3. Testing
a) Acceptance testing shall be conducted on systems prior to operational use to provide assurance that they meet all requirements of this section prior to SCIF accreditation.
b) Semi-annual IDS testing shall be conducted to ensure continued performance.
c) Records of testing and test performance shall be maintained in accordance with documentation requirements.
d) Motion Detection Sensor Testing
(1) All motion detection sensors shall be tested to ensure activation of the sensor at a minimum of four consecutive steps at a rate of one step per second; that is, 30 inches ± 3 inches or 760 mm ± 80 mm per second. The four-step movement shall constitute a “trial.”
(2) The test shall be conducted by taking a four-step trial, stopping for three to five seconds, and taking another four-step trial.
(3) Trials shall be repeated throughout the SCIF and from different directions.
(4) An alarm shall activate at least three out of every four consecutive trials made by moving progressively through the SCIF.
e) HSS Testing
All HSS devices shall be tested to ensure that an alarm signal activates before the non-hinged side of the door opens beyond the thickness of the door from the closed position, e.g., the sensor initiates before the door opens 1¾ inch for a 1¾ inch door.
f) Tamper Testing
(1) Each IDS equipment cover shall be individually removed or opened to ensure there is alarm activation at the PCU or monitoring station in both the secure and access modes.
(2) Tamper detection devices need only be tested when installed.
(3) The AO may require more frequent testing of tamper circuits.
Chapter 8 Access Control Systems
Chapter 8. Access Control Systems (ACS)
A. SCIF Access Control
1. Guidelines
a) SCIFs shall be controlled by SCI-indoctrinated personnel or by an AO- approved ACS to ensure access is restricted to authorized personnel.
b) Personnel access control shall be utilized at all SCIFs.
c) Visual recognition of persons entering the SCIF by an SCI-indoctrinated person at the entrance to a SCIF is the ideal access control.
d) Entrances where visitor control is conducted shall be under continuous visual observation unless the SCIF is properly secured.
e) When the SCIF is an entire building, access control shall occur at the building perimeter.
2. ACS Requirements if Continuous Visual Observation is Not Possible
a) An automated personnel ACS that verifies an individual’s identity before the individual is permitted unescorted access shall be utilized when personal recognition and verification is not used. Automated verification shall employ two of the following three technologies:
(1) Identification (ID) badge or card used in conjunction with the access control device that validates the identity of the person to whom the card is issued.
Compromised or lost access cards shall be reported immediately and updated in the system to reflect “no access.”
(2) A personal identification number (PIN) that is entered into the keypad by each individual. The PIN shall consist of four or more random digits, with no known or logical association to the individual or which can be derived from the person or system generated. Compromised PINs shall be reported immediately to the facility Security Officer (SO) or SCIF SO and updated in the system to reflect “no access.”
(3) Biometric personal identity verification using unique personal characteristics such as fingerprint, iris scan, palm print, etc.
b) The automated personnel ACS shall ensure that the probability of an unauthorized individual gaining access is no more than one in ten thousand while the probability of an authorized individual being rejected access is no more than one in one thousand.
Manufacturers must certify in writing that their system meets these criteria.
B. ACS Administration
1. ACS administrators shall be SCI-indoctrinated.
2. Remote release buttons that by-pass the ACS shall be inside the SCIF and in a location that provides continuous visual observation of personnel entering the SCIF.
3. ACSs shall not be used to secure an unoccupied SCIF.
4. When not occupied, SCIFs shall be alarmed and in secure mode in accordance with Chapter 7 and secured with an approved GSA FF-L-2740A combination lock.
5. Authorized personnel who permit another individual to enter the SCIF shall verify the individual’s authorized access.
6. SCIF access authorization shall be removed when the individual is transferred, terminated, or the access approval is suspended or revoked.
C. ACS Physical Protection
1. Card readers, keypads, communication interface devices, and other access control equipment located outside the SCIF shall be tamper-protected and be securely fastened to a wall or other fixed structure.
2. Electrical components, associated wiring, or mechanical links shall be accessible only from inside the SCIF.
3. System data that is carried on transmission lines (e.g., access authorizations, personal identification, or verification data) to and from equipment located outside the SCIF shall be protected using FIPS AES certified encrypted lines. If this communication technology is not feasible, transmission lines shall be installed as approved by the AO.
4. Equipment containing access-control software programs shall be located in the SCIF or a SECRET controlled area.
5. Electric door strikes installed in conjunction with a personnel ACS shall have a positive engagement and be approved under UL 1034 for burglar resistance.
D. ACS Recordkeeping
1. Records shall reflect the active assignment of ID badge/card, PIN, level of access, entries, and similar system-related information.
2. Records and information concerning encoded ID data, PINs, Authentication data, operating system software, or any other data associated with the personnel ACS shall be secured in an open-storage facility or, when unattended, secured in a GSA-approved container in a closed-storage facility. Access to such data shall be restricted to only SCI-indoctrinated personnel responsible for the access control system.
3. Records of personnel removed from the system shall be retained for two years from the date of removal.
4. Records of security incidents (violations/infractions) regarding ACS shall be retained by the SO for five years from the date of an incident or until investigations of system violations and incidents have been resolved.
E. Using Closed Circuit Television (CCTV) to Supplement ACS
1. CCTV may be used to supplement the monitoring of a SCIF entrance for remote control of the door from within the SCIF. The system shall present no technical security hazard.
2. The remote control device shall be within the interior of the SCIF.
3. The system shall provide a clear view of the SCIF entrance and shall be monitored/operated by SCI-indoctrinated personnel within the SCIF.
4. CCTV communication lines should be located within the SCIF. Communication lines that must run external to the SCIF shall be installed to prevent tampering as approved by the AO.
F. Non-Automated Access Control
1. Non-automated access control devices (mechanical, electric, or electromechanical) may be approved by the AO to control access to SCIFs where the number of personnel that require access is low and there is only one entrance.
2. Combinations shall consist of four (4) or more random digits.
3. The use of pass keys to bypass such devices should be avoided except when local fire/safety codes require them. Any pass keys for such devices must be strictly controlled by SCI-indoctrinated personnel.
4. Mechanical access control devices (e.g., UNICAN, Simplex) shall be installed to prevent manipulation or access to coding mechanisms from outside the door.
5. The following shall apply to electric or electromechanical access control devices:
a) The control panel or keypad shall be installed in such a manner to preclude unauthorized observation of the combination or the actions of a combination change.
b) The selection and setting of combinations shall be accomplished by the SO and shall be changed when compromised or deemed necessary by the SO.
c) The control panel in which the combination and all associated cabling and wiring is set shall be located inside the SCIF and shall have sufficient physical security to deny unauthorized access to its mechanism.
File details come from the government source that posted it. Updated .