BLM WY RawlinsFieldOfficeSecuritySystemInstallationSOW.docx
DOCX document 84 KB Posted
- Attached to
- RAWLINS WY SECURITY SYSTEMS Federal contract opportunity
- Solicitation number
- 140L6220Q0080
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sol_140L6220Q0080_Amd_0006.pdf | ||
| Sol_140L6220Q0080_Amd_0005.pdf | ||
| 140L6220Q0080 AMD 0005 Question and Answer_0005.docx | DOCX document | |
| Sol_140L6220Q0080_Amd_0004.pdf | ||
| 140L6220Q0080 AMD 0004 Questions and Answers_0004.docx | DOCX document | |
| RFO Security System Prebid Tour_0004.pdf | ||
| Rawlins Field Office Security System Installation Bid Schedule Attachment 1_0003.xlsx | XLSX spreadsheet | |
| Sol_140L6220Q0080_Amd_0003.pdf | ||
| Sol_140L6220Q0080_Amd_0002.pdf | ||
| 140L6220Q0080 AMD 0002 QUESTION AND ANSWERS_0002.docx | DOCX document | |
| Sol_140L6220Q0080_Amd_0001.pdf | ||
| RAWLINS SECURITY SYSTEM FINAL DRAWINGS BID SET 02122020_0001.pdf | ||
| Sol_140L6220Q0080.pdf |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Bureau of Land Management Wyoming Rawlins Field Office Security System Installation Solicitation 140L6220Q0080
TABLE OF CONTENTS
| I. | INTRODUCTION | 6 |
| II. | SCOPE | 6 |
| III. | DEFINITIONS | 6 |
| A. | SERVICES AND REQUIREMENTS | 6 |
| A.1 Remote Connection | 6 | |
| A.2 Installation | 6 | |
| A.2.1 Outages | 6 | |
| A.2.2 Logistics | 7 | |
| A.2.3 Quality of Work | 7 | |
| A.2.4 Cabling | 7 | |
| A.2.4.1 Materials | 7 | |
| A.2.4.2 Cable Routing | 7 | |
| A.2.5 Grounding | 8 | |
| A.2.6 Cleaning | 8 | |
| A.3 Performance Requirements | 8 | |
| A.3.1 Phase I - Design, Submittals and Approvals | 8 | |
| A.3.2 Phase II – Supply and Install Systems and Training | 8 | |
| A.3.3 Internet Connection | 8 | |
| A.3.4 Closed Circuit Television (CCTV) – Base Requirement for all location. | 8 | |
| A.3.5 Access Control System (ACS) - Base Requirement | 10 | |
| A.3.6 Duress Alarm System (DAS) | 18 | |
| A.3.7 Door Hardware | 18 | |
| A.3.8 Compatibility | 18 | |
| A.3.9 Training | 18 | |
| A.3.10 Support | 19 | |
| B. | CONTRACTOR FURNISHED SERVICES AND MATERIALS | 19 |
| C. | DELIVERABLES | 19 |
| D. MINIMUM PERSONNEL REQUIRED | 20 | |
| E. | REGULATORY REQUIREMENTS | 20 |
| F. | PROJECT SITE LOCATION | 20 |
| G. | EXISTING CONDITIONS | 20 |
| IV. ADMINISTRATION DATA AND GENERAL REQUIREMENTS | 20 | |
| A. PERIOD OF PERFORMANCE | 20 | |
| B. PLACE OF PERFORMANCE | 21 | |
| C. HOURS OF OPERATION | 21 | |
| D. SECURITY REQUIREMENTS | 21 | |
| E. POST AWARD CONFERENCE CALL | 22 | |
| V. ADMINISTRATIVE ACTIVITY CONTACTS | 22 | |
| VI. | PROVISIONS/CLAUSES | 22 |
| VII. | LIST OF ATTACHMENTS | 26 |
| VIII. | REPRESENTATIONS, CERTIFICATIONS, AND OTHER STATEMENTS OF OFFERORS OR RESPONDENTS | 26 |
| IX. INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS OR RESPONDENTS | 27 | |
| All offerors shall submit Volume I and Volume II as follows: | 27 | |
| Volume I- Technical Quote | 27 | |
| Volume II- Price Quote | 28 | |
| X. EVALUATION PROCESS | 28 | |
| XI. TECHNICAL EVALUATION FACTORS | 28 |
I. INTRODUCTION
The Bureau of Land Management (BLM) has 16 Facilities throughout the state of Wyoming which require physical security system enhancements to meet current Department of Homeland Security (DHS) and Department of Interior (DOI) Physical Security Standards. This Solicitation is for the BLM Rawlins Field Office located in Rawlins, Wyoming and will be the first BLM Facility to have the new Security System Equipment installed. The Plan Set of Drawings for the Rawlins Field Office Security System Improvements were completed by Integrated Security Solutions, Incorporated in February 2020 and will be provided to the successful Contractor.
II. SCOPE
The successful Contractor is required to install the Security System Improvements for BLM Rawlins Field Office identified in the Project Site Location as specified in Section F. Facility Design, which is included in a zip drive (Attachment 2) with specific equipment and installation designs for Closed Circuit Television (CCTV) Systems, Access Control Systems (ACS), Duress Alarm System (DAS) (including local emergency notification), and door hardware must be used in the installation. The Contractor shall be required to provide dedicated internet capability, equipment, installation, and training to meet these goals. Security System configuration and programming will take place prior to physical installation.
All BLM Sites are designated as Federal Security Level II Facilities. DHS requires Federal Facilities designated as a Federal Security Level II to provide a means to secure entrance doors and to verify the identity of persons requesting access to the Facility. In addition, DHS requires Federal Facilities designated as a Federal Security Level II to provide CCTV coverage of all pedestrian entrance and exit points.
III. DEFINITIONS
Access Control System (ACS) – Includes provision of all equipment and installation of ACS complete with documentation and training.
Closed Circuit Television System (CCTV) – Includes provision of all equipment and installation of the CCTV cameras, mounting and wiring, recorder, monitor, software, training, and operating and maintenance materials.
Design – Includes visiting the Site, reviewing the Security System Design and Technical Drawings, submission of Shop Drawings, as needed, and Equipment Submittals.
Duress Alarm System (DAS) – Includes provision of all equipment and installation of complete system with training and documentation.
Closed Loop System: A network system that is stand alone and does not have access to the internet.
A. SERVICES AND REQUIREMENTS
A.1 On-Site Connection The successful Contractor shall be fully capable of on-site connection to the systems for programming, system analysis and repair, and other such things that might be required by the BLM. These connections will not be connected to the BLM network.
A.2 Installation A.2.1 Outages
· All controlled outages (e.g. electrical, network, etc.) of any type, must be cleared through the COR at least 48 hours prior to the outage.
· Material disruptions to Facility operations will be pre-planned and coordinated with the COR at the earliest possible time and no later than 48 hours prior to the event.
· The Rawlins Field Office shall be secure (doors able to lock) each night after business hours. The COR shall be notified 48 hours before any Facility is unsecure (eg. Switching the old door controllers to the new).
A.2.2 Logistics
· Ordering and installation of equipment with long lead times or having a major impact on work by other trades will be coordinated so as not to delay job or impact project schedule.
· The Contractor is responsible for damage to any equipment, materials, surfaces or other work disrupted as result of the work.
· Repair or remuneration will be the sole responsibility of the Contractor.
· If such work cannot be repaired within a reasonable time, the BLM reserves the right to repair damaged equipment, materials or surfaces and offset the costs for such repairs from the awarded contract price.
A.2.3 Quality of Work
· Concealment:
· Conceal work above ceilings and in walls, below slabs, and elsewhere throughout building.
· If concealment is impossible or impractical, notify COR before starting that part of work and install only after the review and final decision of the COR.
· The COR must review and approve all installations in areas without ceilings.
· Waterproofing:
· Seal foundation penetrations by electronic security conduits and sleeves to eliminate intrusion of moisture and gases into building.
· Conduits with Cables: Permanently sealed by firmly packing void around cable with oakum and capping with hydraulic cement or waterproof duct seal.
· Spare Conduits:
· Plugged with expandable plugs.
· Service Entrance Conduits through Building: Sealed or resealed upon cable placement.
A.2.4 Cabling A.2.4.1 Materials
· All new cable and control wiring is to be plenum rated.
· All cable and wires will be permanently marked with printed labels at each termination.
A.2.4.2 Cable Routing
· All new cable is to be installed close to the roof/ceiling above.
· Cable and wire runs will not be routed over open areas, hallways or isles and will be concealed from plain view.
· Wire molding, ceiling hangers, or cable trays, will be provided as needed for esthetics, protection, and support.
· Cables are to be routed in conduit where necessary for its protection and concealment from vandalism.
· Cables and wires are to be routed and neatly bundled together.
· Cable shall be designed and installed in accordance with TDDG so cabling and associated equipment does not interfere with operation or maintenance of other equipment.
· In accordance with the National Fire and Electrical Code, cables, wire, or conduit, will not be routed through or interfere with fire dampers.
· No cable or wire will be left hanging or unsupported across ceiling tiles, HVAC ductwork, or pipe insulation. All wire runs must be suspended and secured via plenum rated wire ties or industry approved fasteners.
· Accessible Spaces: Install cable for easy access for service, maintenance and additions.
Cable Paths above suspended ceilings, mechanical rooms, and closets are not to be blocked or covered in way to impede additional future cable.
A.2.5 Grounding
1. All equipment shall be grounded according to manufacturer’s specifications. Penetrations
· Conduit and Sleeve Openings shall be waterproofed, fireproofed, and soundproofed (where required) in compliance with federal, state, and local codes and regulations.
· Fire stopping shall be completed and in compliance with applicable federal, state, and local codes and regulations.
· All remaining openings around and inside conduit, sleeves, and cable penetrations shall be patched to maintain integrity of fire rated assembly.
A.2.6 Cleaning
1. The Contractor is to keep Site and surrounding area free from accumulation of dust, waste materials, and rubbish on daily basis.
2. Keep equipment and fixtures wrapped in electrostatic plastic and clean for duration of project. Comply with applicable regulations regarding the Rawlins Field Office and environmental cleanliness.
A.3 Performance Requirements A.3.1 Phase I - Design, Submittals and Approvals Within 10 days of contract award the Contractor shall set up a meeting with the COR and any other required BLM personnel to present the draft design of all requisite system, inclusive of the removal of existing system(s)/componentry, new device cut sheets, wiring diagrams, and anticipated project scheduling. Following the meeting, BLM will have three (3) business days to further review the draft design and provide feedback. Overall, the Contractor should anticipate a maximum of two draft iterations to address feedback or other agency concerns. The final design shall be provided to BLM within 30 days of contract award.
A.3.2 Phase II – Supply and Install Systems and Training The Contractor shall supply, deliver and install turnkey replacements and/or new device installations for the systems identified herein.
A.3.3 Closed Circuit Television (CCTV) – Base Requirement for all location.
CCTV systems shall meet the requirements of the Department of Interior’s Manual 444, Chapter 3, Closed Circuit Television. Contractor shall provide a CCTV system that includes cameras with the ability to point, tilt, zoom and, as applicable for the location requirements, view 180 degrees and 360 degrees.
Additionally, the cameras shall be of a high enough mega pixel resolution to allow for facial recognition, accommodating low light to dark conditions at a distance of approximately 40 feet minimum; specifically, during daylight hours the color of vehicles and clothing will be able to be identified. Viewing angles of the cameras will be optimal to achieve these goals. Exterior coverage requires 360 degrees digital video coverage of all Federal property at the Project Site, inclusive of main buildings, ware yards, storage buildings, vehicle storage, Photovoltaic (PV) system, parking lots, etc. The exterior coverage of the buildings shall specifically include all building entrances and all first-floor windows.
Cameras shall be rated for the environmental conditions that can occur at the Project Site. Video coverage of property will be of sufficient quality to identify make and model of vehicles. Cameras shall be installed at vehicle entrance points to each property and shall be able to identify license plate numbers. Cameras will not be pointed in such a way as to capture video of adjacent private property.
Each system shall also provide interior video coverage of the public room/contact desk identified in the floor plans. Each system shall include one video monitoring station, inclusive of software that operates and manages the CCTV system, for access and management of the system in the public room/front desk and up to three (3) additional offices. All other central system hardware shall be installed in the IT/Telecom room where applicable or as determined during the design phase. Power requirements or UPS and rack space must be verified prior to installation to ensure power and rack space availability. Each system shall allow for video retention capacity for a minimum of 60 days. Each system will have the ability to export selected video from the video retention device to a Contractor-provided portable device in standard industry video format (H.264). Video storage shall be maintained at the Project Site by BLM.
All components of the CCTV system are to be hardwired. The CCTV system shall have the capacity for added cameras in the future. The system shall be capable of being configurable to function and be administered across subnets and gateways, or from any remote Site via the internet using a secure connection.
Access to the system database shall be restricted through at least two (2) security access levels in order to prevent unauthorized program modifications or use by unauthorized personnel. The system shall require two (2) factor authentications using the PIV card for system login/administration and for authorization to change programming parameters.
At a minimum, the CCTV system shall possess the following salient characteristics:
· Motion Detection
· H.264
· Record/playback at 15-30 fps in full HD
· 1 GB network interface
· Live Camera View
· Data Protection
· 1 USB Ports
All exterior and interior cameras (at a minimum) shall possess the following salient characteristics:
· Interior 1 Megapixel HD Dome Cameras
· 9-22mm or 3-9mm P-Iris or automatic iris control
· Auto Day/Night Mode
· Auto Focus
· Self-Learning Analytics
· Motion Detection
· Better than High Definition (1080p) Resolution
· Wide Dynamic Range A.3.4 Access Control System (ACS) - Base Requirement Each ACS must comply with DHS HSPD-12 requirements as implemented by the Department of Interior. Personal Identity Verification (PIV) Policy and Guide for Federal Employees and Contractors and the National Institute of Standards and Technology (NIST) Federal Information Processing Standards 201 (FIPS 201-2) (or most current).
All components of each installed system, including card readers, door controllers, ACS database management system, and all other hardware and software components, must be compatible with authentication/certificate validation systems mandated by NIST Special Publication (SP) 800-116 (http://csrc.nist.gov/publications/nistpubs/800-116/SP800-116.pdf), including, but not limited to, Facility code, agency code, and credential value, as contained in the Federal Agency Smart Credential Number (FASCN) and/or Cardholder Unique Identifier (CHUID).
All hardware and software in each ACS will be selected from the list of approved products which can be found in the FIPS 201 PIV II Evaluation Program website (http://fips201ep.cio.gov/apl.php).
A successful system will need to use employee DOI Access cards to access the building.
Per the Project Site Location Attachments, the Contractor shall provide an ACS system that controls access as follows:
· To all designated exterior pedestrian doors of every designated building at the Project Site.
· To the IT/Telecom room, where available.
· Any power vehicle gates and personnel gates that are shown on the drawings. These will be fitted with entry and/or exit readers, utilizing the gates existing conduit and layout.
· Types of card readers
· Exterior card readers shall be resistant to direct sunlight exposure and temperature and weather extremes.
· The system shall utilize swipe only readers for all exterior doors, public areas to employee area access control doors and power vehicle gate locations shown on drawings.
· The system shall include one secure (encrypted, password-protected), appropriately equipped monitoring station to access and manage the ACS per the final approved design, in the room determined during the design phase.
· BLM will provide the workstation furniture. The central system hardware shall be mounted in the IT/Telecom room designated during the design phase.
· The ACS shall control, monitor, and record all valid entries and invalid entry attempts by personnel using access cards at card reader terminals.
· The ACS shall authenticate the person based on the credential value read from the card by the reader.
· The ACS shall automatically control door access by comparing credential value(s) stored within the access card with similar information previously programmed into the ACS.
· At the Project Site, the system shall automatically lock designated (front) exterior door(s) at the end of business hours. Business hours and door(s) will be designated by BLM during the design phase. These doors will have the ability to be unlocked at the beginning of business hours by means of a control device to be located in the IT/Telecom room with the system hardware.
· The system control of doors will not impede use of existing emergency exit devices; all doors will meet local codes for egress.
· The Contractor shall set up groups for a minimum of five (5) categories of carding requirements, as follows:
Category- Employees holding Department of Interior (DOI)-issued Personal Identity Verification (PIV) cards, needing access to common spaces at all hours.
Category- Employees holding DOI-issued PIV cards, needing access to common spaces at all hours, as well as to secured areas of the building.
Category- Employees holding DOI-issued PIV cards, with managerial duties requiring them to have access to all protected doors at all hours, including emergency exits with card readers.
Category- New employees, seasonal employees, employees who have forgotten their badges, or Contractors needing short-term access to common areas.
Category- Contractors and building visitors needing access to common areas during working hours only.
· Security must be maintained during the transition from any existing system to the new systems. The Contractor shall provide and implement a temporary system which includes transferring the current database of active proximity cards to the new system. As the systems are transitioned from an old system to a new system, active cards no longer needed for visitor and employee access will be de-authorized as employees' and other visitors' DOI-issued PIV cards are entered into each new system.
· The Contractor shall provide re-programmable proximity type access cards for use as visitor badges that are compatible with each system, Contractor will provide forty (40) of these cards for the Project Site.
· Each system will be capable of registering cards into the authorized database by individual numerical entry, bulk table/database entry, or swipe (or read)-to-enter.
· While a certificate management system for enrollment authentication and ongoing database authentication is not part of this scope of work, each system shall be capable of integration with a future local, regional or national enrollment/database authentication system (e.g., CodeBench).
· The ACS shall maintain a database describing authorized access card I.D. numbers with their authorized points and times of entry, access level, and other associated privileges based on the programming entered by the system administrator, but initially established by the Contractor.
· There shall be a central ACS application to provide credential verification/certificate monitoring. The system shall report power loss, tampering, door ajar and forced alarms.
· Access to the system database shall be restricted through at least two (2) security access levels in order to prevent unauthorized program modifications or use by unauthorized personnel. The system shall require two (2) factor authentications using the PIV card for system login/administration and for authorization to change programming parameters.
· The ACS shall maintain a calendar clock for controlling and indicating all time related functions, such as schedule door lock open and close command.
· The system administrator, using appropriate keyboard commands, may program the Access Control Panel (ACP) to automatically suppress alarms and unlock doors to enable door access for extended time intervals when monitoring is not required. However, this event information must be recorded and capable of being documented.
· All components of the ACS shall be hardwired.
Functionally, the ACS shall perform authentication and authorization as follows:
· If the information on the card is authenticated against the data stored in the ACS, a signal is sent to the card reader terminal location to operate the release device, allowing the person to open the door/gate/turnstile.
· If the information on the card is not authenticated within the ACS, the ACS does not release the activating device but sounds a brief alarm, either audible, visual or both at the reader and logs the access card number, access point, time of day, and an indication of why access was denied.
· Each door shall be monitored and logged for real time status (open/close).
· A programmable alarm shunt timer (45 seconds) allows door to be opened for authorized card access entry, allowing adequate time to enter without alarming the system. An alarm shall occur if the door remains open beyond the preset alarm period.
· The system shall not alarm when an exit device (pushbutton or request to exit sensor) is used to leave a secure area.
The system administrator may display on monitor, interact, interface, and print summary reports, including:
· Alarms
· Access activity at specified card reader
· Denied access attempts
· Doors in override mode (card access)
· Doors with alarms suppressed (monitored)
· All transactions stored in disks (printout to be sorted by date, time, transaction type, card ID number, card reader, or alarm monitor transactions)
· All user programmable data
ACS System Architecture Requirements
· The ACS system shall not require any client software (other than a standard Web browser) or client licenses to be installed on Contractor-provided workstations in order to gain administrative access to the system. Administrative access will be authenticated through use of the PIV access control credential. ACS software must be Windows 10 compatible.
· The overall system design and equipment selections shall be such that all installed equipment can be upgraded in place with only software and/or database reconfiguration.
· The ACS system shall use either multi- or single-door ACPs or edge devices, which shall make and manage local access control decisions when access cards are presented to readers.
· In addition to the PIV card, the ACPs shall be capable of accommodating multiple card formats and accept one or more readers.
· During off-line conditions, the ACP will continue to verify credentials before allowing access to the particular area. Transactions will be archived for storage until the network is restored. Upon network restoration, these transactions shall be sent to the ACS application for final archiving.
· In the case of multi-door ACPs, the ACP shall accept expansion modules that provide additional capacity or functionality to the system. Each of these expansion devices shall connect to and manage a set of inputs, outputs, or readers.
Networking and Data Security Requirements
· The webserver and database must both reside on the same physical machine.
· Should IP video cameras, digital video storage subsystems, and storage systems from other manufacturers be deployed, they will be network connectable and the ACS shall communicate with them using Transmission Control Protocol (TCP/IP) over the network.
· The system shall be capable of being configurable to function and be administered across subnets and gateways, or from any remote Site via the internet using a secure connection as approved by the BLM.
· Communications between the ACS application and ACPs shall be authenticated (e.g., X.509 certificates, SHA-256, or equivalent cryptographic techniques).
· The system shall support the following networking and encryption standards and shall operate on existing building network infrastructure:
1. Email: SMTP
2. Messaging: SMS
3. Encryption: NIST FIPS 140-2 validated encryption which meets the required certification level
· Communications between the ACS application and the ACP shall use NIST FIPS 140-2 validated encryption or equivalent.
· In addition, communication between the network application and network remote ACP or edge devices shall be authenticated using NIST FIPS 140-2 validated encryption or equivalent.
· Administrative access to the security management application and the personnel security data shall also be protected by dual-factor FIPS 201 credentials.
Access Control Functional Requirements The ACS (Application and ACP) shall support the following features and access control features shall include:
1. Multiple group privileges per person
2. Reader/credential support
3. Federal standards: PIV-II
4. Contact and contactless smart cards
5. Detailed time specifications
6. Multiple card formats for mixed card populations
7. Activation/expiration date/time by person with one-minute resolution
8. Access levels disable for immediate lockdown
9. Multiple holiday schedules
10. Timed unlock schedules
11. Scheduled actions for arming inputs, activating outputs, locking and unlocking portals
12. Card enrollment reader support
13. Visitor Management: Electronic log with data captured from valid issued ID to populate specified fields within software
14. Timed anti-pass back
15. Muster / Roll Call Reporting
16. Dual reader portal support
17. Wiegand keypad PIN support
18. First-in/Supervisor unlock rule
19. At least twenty (20) user-defined and searchable database fields
20. An administrative interface that integrates video, system activity logs, floor plans, ID photos, and alarm notifications
21. Event and alarm notifications delivered via email, SMS, and browser interfaces
22. Graphic floor plans with active icons of security system resources
23. System user permissions to grant whole or partial access to system resources, commands, and personal data
24. Ability to arm/disarm groups of inputs based on other system inputs or alarm events
25. Tiered administrative access to system functions and data such that some administrators’ access may be restricted
Reporting Requirements
· The system shall be capable of producing a variety of predefined reports regarding software and security hardware configuration, event history, and the administration of people within the system.
· It shall be possible for the Administrator to create ad hoc reports through a graphical user interface. When creating custom reports, the end user will be able to select the database fields, including user defined fields, for inclusion in reports. For filtering time and date, the custom report writer will allow entry of relative time and dates such as, “last week, last day, last 60 days,” up through one year.
· It shall be possible to produce reports based on:
· Event data
1. Personnel data
2. System configuration data
· The custom report writer shall allow for selection of devices to be reported on. This shall include which specific events will be included in the report and have filters for selection of personnel.
· It shall be possible to save custom reports for later reuse. Report results can be printed, output to a .pdf file, or exported to excel in a grid (columns) format.
Access Control Panel (ACP) Requirements
· The ACP shall be a microprocessor-based access control and monitoring panel that serves as the data collection and communications interface between the ACS application and the various field devices, such as card readers, alarm inputs, and control outputs. The ACP may also be implemented as a single door edge device.
· The ACP shall have battery backup for uninterrupted, on-line operation for a minimum of four operational hours, in case of ac power loss. The battery shall meet all applicable safety standards. Batteries shall be 12-volt, 7.2-amp hour or better. In addition, an Uninterrupted Power Source (UPS) equal to 30 minutes of backup shall be required.
· The ACP shall support the following communications protocols and standards:
1. Network: Ethernet, TCP/IP
2. Telephony: Cellular, Dial-Up (optional)
3. Serial: RS-232, RS-485 (optional)
4. NIST FIPS 140-2 validated encryption with the required certification level
· The ACP shall comply with Underwriters Laboratories (UL) 294 - Standard for Safety Access Control System Units.
· Shall provide diagnostic status lights for:
1. Operational status of the ACP
2. Relay output status
3. Communication, TX/RX traffic through server, and operational Ethernet interface
4. Internal diagnostic/system configuration
· Performance: The ACP shall make authorization decisions and allow or deny access within 250 milliseconds of receiving a credential from a reader.
· The ACP shall be housed in a tamper-proof case enhanced with alarm monitoring features.
· Provide for protection of secrets (e.g. master keys) in an ACS. See NIST SP 800-57, Parts 1 and 2.
General Reader Requirements
· Readers shall support the following protocols: Wiegand (DO/D1), magnetic stripe (CLK/Data), RS232, and RS-485 communications with future TCP-IP support. Readers shall be capable of reading existing HSPD-12 FIPS-201 compliant cards.
Contactless/Contact Reader Requirements
· Contactless reader/writers shall be provided where shown on the drawings.
· Credential reader/writers may be "single-package" type, combining controller, electronics, and antenna in one package, in the following configurations:
1. Mullion mount Reader, Mullion mount Reader/Writer + PIN, and Mullion mount Reader/Writer + Biometric fingerprint scanner. All models shall be able to mount to “single-gang” electrical boxes (USA) using an optional Single-Gang Mounting Kit.
2. All exterior readers shall be proximity/PIN (2-phase authentication) and on any BLM-designated secure areas (Maturity Level 2).
3. All interior readers shall be proximity only, unless space/equipment requires higher level access and then a 2- factor reader will be required.
4. Unless otherwise indicated for ABASS or other special requirement the reader shall be mounted at 42” AFF (bottom of reader) with protective/insulated plate between reader and wall/junction box.
5. Multi-technology capable of reading all technologies referenced in above and compatible with new system design as certified by the manufacturer and listed as a FIPS 201 certified product.
6. The reader shall be of potted, ABS material, sealed to a rating of (IP67).
7. The reader shall comply fully with ISO 14443 parts 1, 2, 3 and 4 open card standards to fully enable interoperability among suppliers of similar products.
8. The reader shall conform fully to ISO 14443 Part 3 - Anti-collision and Transmission Protocol and must be capable of identifying multiple credentials in a single field.
9. The reader must operate at the 13.56 MHz High Frequency band and have the capability of reading proximity cards and United States Government PIV cards at 125 KHz Frequency band.
10. The contactless reader/writer shall have an approximate read range of 1”- 2” when used with ISO 14443 access control badges.
11. The reader and card shall use challenge response mutual authentication.
12. The reader shall be capable of reading access control data from any ISO 14443 compliant contactless credential and transmitting that data in Wiegand format.
13. The reader shall be capable of reading the card serial number (CSN), a permanent, unique identification number, from any 15693 credential, and transmitting that data in Wiegand format.
14. The reader shall be capable of writing to any ISO 14443 compliant credential.
15. The reader shall have separate terminal control points for LED’s and for the audible indicator.
16. The reader shall have multiple LEDs for increased visibility.
17. All readers must be FIPS201 compliant.
18. BLM has standardized on reverse 64-bit encryption.
The reader naming convention shall follow:
Example: R10 WY0516 S0402-XXXXXXXXXXXXXXX R10 = Regional Designation (RXX) WY0516 = State and Building Number S04 = A-panel (to be sequenced (AXX) 02 = Second Reader on the Panel (XX) XXXXXXXXXXXXXXX = Custom filed text for each door (15 characters) Door Strikes
· Construction: Stainless steel, tamper resistant, internal solenoid.
· Opening Force: 1,900 pounds.
· Operation: Field reversible, plug-in connectors.
· Solenoid: Internally mounted to facilitate electric strike installation in hollow metal, concrete filled, and aluminum and wood jambs.
· Solenoid: Operated by direct current to provide silent operation.
· Electric Strike: Capable of operation with less than 30 pounds of force against keeper.
Magnetic Door Contact
· The contact shall be designed specifically for use in steel and wooden doors.
· The unit shall offer a sealed unibody construction, with flexible ribbed sides for quick secure installation without gluing.
· The electronic strike and magnetic lock shall provide remote release of a locked door or gate.
· All interior card reader doors (except stairwell doors) shall be fitted with fail safe hardware complying with all applicable safety standards, specifically including a manual door release button for egress.
Configuration:
· Contain hermetically sealed magnetic reed switch.
· Unobtrusive, flush with surface of doorframe and door.
· Contact and Magnet Housing: Snap-lock into 3/4 inch or 1-inch diameter hole.
· Color of Housings: Choose to match color of door frame.
· Snap-lock insulation bushing for tight fit.
· Overhead door contact shall be designed with a low-profile heavy cast aluminum housing with a wide operating gap of up to three inches.
Request to Exit Sensor Description: The sensor shall detect motion in its established coverage area and signal the ACP to either unlock a door or shunt door contact associated with coverage door.
Configuration:
· For single or double door use.
· Wall and ceiling mountable.
· Operate on 12 or 24 VAC or DC.
· Up to sixty (60) second adjustable latch time.
· Include selectable relay trigger mode.
· Selectable fail safe/fail secure mode of operation.
Additional specifications for the ACS systems
· Door Hardware
1. Exterior entrance doors shall be equipped with ACS hardware. Hinge pins and hasps shall be secured against unauthorized removal by using spot welds or preened mounting bolts. The exterior side of the door shall have a lock guard or astragal to prevent jimmying of the latch hardware. Doors used for egress only shall not have any operable exterior hardware. All security-locking arrangements on doors used for egress shall comply with requirements of NFPA 101.
2. Exit-only doors shall be equipped with loud buzzer which can only be disarmed by shutting the door or with a key located in the buzzer. The purpose is to prevent a security breach when exit-only doors are temporarily propped open.
· Reception Area
· Gates
1. If shown on the drawings, gates shall be equipped with an electronically controlled ACS hardware for ingress.
2. Two (2) three foot (3') wide personnel gates will be equipped with ACS hardware is shown on drawings.
Installation
· All card readers installed on the exterior of the building shall have keypads.
· The Contractor shall provide plywood backing mounted on the wall for the Access Control System equipment.
· Must be achieved in accordance with all applicable standards, the specifications within the executed contract, manufacturer’s design and installation guidelines. The Contractor shall:
1. Ensure maximum-pulling tensions of specified distribution cables not exceeded and cable bends maintain proper radius during placement of Security System Equipment.
2. Provide additional material and labor in timely fashion to properly rectify failure to follow requirements.
· Install materials and equipment in accordance with manufacturer’s recommendations, applicable standards, and contract specifications. Conflicts between manufacturer’s recommendations, specification, and/or contract documents must be reported in writing to the COR for resolution.
1. All conduits must be Electrical Magnetic Tubing (EMT) with a minimum size of ¾”.
2. All back boxes must be double gang with single gang mud ring and mounted at 42” to center.
3. Conduit must be run through the wall, up to the ceiling, and then into the secure side of each door.
4. All cable must be orange CAT5e or CAT6 plenum rated.
· Power Separation: ACS cabling shall not be installed alongside power lines, or share the same conduit, channel, or sleeve.
Transition to new ACS for replacement of existing systems:
· All work is to be conducted in a seamless and non-disruptive manner.
· The Contractor must provide advance notice in writing to the COR. The COR will establish a date and time for system cutover. The selected date and time will be after normal business hours to ensure the least disruption to building occupants.
· The Contractor will provide the necessary technical personnel On-Site to assist with legacy system deactivation, ACS activation, and any other issues.
· The existing ACS may only be phased out provided the Project Manager receives an approved phasing schedule. Seventy-two (72) hours advanced notice is required for any transition.
· The existing ACS will be shut down only when the Contractor communicates, in writing, that the new ACS is ready to be deployed and has certified HSPD-12 compliance. For existing reader locations, down time will not exceed three (3) hours during normal business hours or may require overtime. Overtime costs shall be at the expense of the Contractor and at no additional expense to the Government.
Initial set up programming for the system
· The Contractor shall program all initial cards in accordance with agency provided information for all employees.
· The Contractor shall provide for all system software updates for a period of five (5) years at no additional cost to the government.
A.3.5 Duress Alarm System (DAS) At the Project Site, the Contractor shall provide and install a DAS which, when pressed, will activate ceiling mounted blue strobe lights. These lights will be in each personal office and in locations that are visible from all workstations in all buildings on the Site; no strobe lights will be visible in or from the public areas.
Each building open area (warehouse, storage area, vehicle bay, etc.) should also have a minimum of one blue strobe light installed. The system will have multiple activation devices installed.
One each will be installed in the Reception Area and two each mobile activation devices for employees who interact with the public in the building. Locations of mounted buttons will be determined during the design phase. The system must be connected to either a security alarm company or the Government security monitoring system. Costs of the alarm company fees or Government monitoring fees and phone line connection to either system will be paid directly by Government under a separate contract. Provide hardware, wiring, any required computers or software, manuals, and training for operation of the DAS.
A.3.6 Door Hardware Some existing door hardware operates poorly, needs a new key system, tamperproof hardware (anti pry plates, deadbolts, etc.) and/or could be replaced with a mechanical numeric pad. The Contractor shall evaluate all doors and recommend upgrades. New hardware to be compatible with existing hardware required for all work.
A.3.7 Compatibility Unless current platforms are compatible, all legacy equipment will be replaced by enterprise equipment allowing the unification of CCTV, Access Control in order to leverage additional capabilities from the systems.
A.3.8 Training The Contractor shall provide On-Site training in the operation and maintenance of all system functions at the Project Site for up to three (3) BLM operators at the time of installation per Site. Training shall be hands-on, practical and developed for entry-level support staff for the CCTV and ACS systems The Contractor shall provide written training materials for each person trained documenting procedures and instruction. Written training materials shall be concise and easy to understand.
A.3.9 Support The Contractor will provide the Project Site with all pertinent software manuals, licensing and warranty information, to include all system, software, hardware, firmware and boot passwords for any and all hardware or software installed at the location for the CCTV and ACS Systems.
The Contractor will provide On-Site trouble shooting and system adjustments for a period of 90 days after installation is accepted by the Government. The Contractor will provide phone support for the system for a period of one year after installation is accepted by the Government, or for the length of the standard commercial warranty, whichever is longer.
The Contractor will include written warranty descriptions, descriptions of available user training and ongoing support, and pricing for system maintenance following the warranty period for the CCTV and ACS Systems for five (5) years.
B. CONTRACTOR FURNISHED SERVICES AND MATERIALS
The Contractor shall furnish all labor, equipment (desktop computers, servers, and DSL/Internet Services) supervision, transportation, travel, installation materials, data, and shipping.
The Contractor shall provide a Schedule that is updated at a minimum of monthly. The Schedule shall also be updated any time there is more than 3 days difference between the Schedule and the actual work. The Schedule shall include:
· Design timeframe
· Supply and installation at the Project Site
· Training at the Project Site
C. DELIVERABLES
Monthly Status Report: At a minimum, a brief monthly status report (1 to 2 pages) shall be e-mailed to the COR. This report shall list accomplishments, completed tasks and Site locations, identify issues, propose resolutions to the issues, and provide upcoming tasks to complete. If necessary, the BLM will provide a list of additional people to be e-mailed the progress reports, in addition to the COR. A suggested format for the progress report is provided below.
Suggested Progress Report Format (Monthly)
1. Period of Report.
2. Person Preparing the Report (Name, Phone #, and e-mail address).
3. Date Report Prepared.
4. Accomplishments.
5. Completed Tasks plus Cumulative Listing of Completed Tasks- Site locations.
6. Issues Identified.
7. Proposed Resolution to the Issues.
8. Upcoming (Near –Term) Tasks to Complete.
9. General Comments (if applicable).
Monthly payments for work accomplished for phase:
1. Design,
2. Each building a separate phase,
3. Quarterly payments for maintenance services
D. MINIMUM PERSONNEL REQUIRED
Electrician – Must be certified Electrician in the State of Wyoming Project Manager – Must have at least 5-years of experience with security systems All other key person for the Contractor shall be identified at the time of award.
If during performance, identified Contractor support resign or are terminated, the Contractor shall provide the CO within 15 business days the proposed substitute’s resume, as they should have comparable qualifications to the individual being replaced. All proposed substitutes will be subjected to a 90-day probationary period. Proposed replacements which do not satisfy the Government during the probationary period will be removed from the Order at no cost to the Government.
E. REGULATORY REQUIREMENTS
Project materials and execution shall comply with the following:
1. Americans with Disabilities Act (ADA)
2. All documents must be 508 Compliant
3. NFPA 70 - National Electrical Code (NEC)
4. NFPA 101 - National Life Safety Code
5. Federal Communications Commission (FCC)
6. FCC 47 CER 68
7. Department of Interior’s Manual 444, Chapter 3, Closed Circuit Television
8. Applicable laws, rules, mandates, directives and regulations of federal and state and local governmental agencies.
F. PROJECT SITE LOCATION
1. Rawlins Field Office, 1300 N Third, Rawlins, Wyoming
G. EXISTING CONDITIONS
The Project Site has a varying degree of an existing security system installed. All existing shall be removed at the Project Site. All existing equipment (devices) shall be provided to the Contracting Officer’s Representative (COR). Existing wiring may be left in place provided it does not interfere with the new equipment. The Contractor will indicate on the design drawings any need to modify the existing building structures (walls, ceilings, etc.) and the Contractor shall be responsible for such modifications. After installation of the new system(s) are completed, the Contractor shall also be responsible for returning such structures back to their original state by patching painting, etc., to match existing conditions.
IV. ADMINISTRATION DATA AND GENERAL REQUIREMENTS
A. PERIOD OF PERFORMANCE
The period of performance of this contract is for a 1-year base installation and maintenance, with 4 optional years for maintenance of systems on-site. The Government may cancel the contract/delivery order at any time by notifying the Contractor at least thirty (30) days in advance. Termination procedures for contracts are in accordance with Federal Acquisition Regulation Part 49 Terminations. Should the schedule contract expire during the period of performance, the order expires on the same date as the GSA schedule contract. The Contractor shall notify the CO no less than 60 days prior to the expiration of the Contractor's GSA Schedule contract that its contract is about to expire.
B. PLACE OF PERFORMANCE
The place of performance for services under this contract will be On-Site at the Wyoming Project Location listed above in section F. Meetings will be scheduled and conducted via conference call or another virtual method.
C. HOURS OF OPERATION
Performance of work is expected to be between 8:00 a.m. to 4:30 p.m., Monday through Friday (except for Federal holidays) at the designated "Place of Performance" location.
The Contractor shall work no more than 80 hours over a two-week period (10 business days). The Contractor may work greater or less than 8 hours per day, to allow flexible time and/or accommodate support requirements, so long as the total hours over the two-week periods does not exceed 80 hours. If the Contractor intends to use flextime, the COR must be notified and approved in advance. Modifications to duty hours may be required to accommodate unique circumstances, such as, inclement weather closures/delays.
D. SECURITY REQUIREMENTS
Background Investigations and Government issued personal identification cards The BLM requires the successful Contractor to have a Federal government-issued Personal Identity Verification (PIV) credential before being allowed unsupervised access to a DOI/BLM Facility and/or information system.
The Contractor will comply with the Contractor Personnel Security and Suitability Requirements below before being allowed unsupervised access to a DOI Facility and/or information system. The COR will be the sponsoring official, and will initiate the process for the following:
· Successfully adjudicated background investigation (BI)
· Security clearance
· Federal government-issued personal identification card
Within 5 calendar days following issuance of award, the Contractor must identify Contractor(s) and/or Sub-Contractor personnel who will require physical and/or logical access for performance of work under the Order. The Contractor must make their personnel available at the place and time specified by the COR in order to initiate screening and BIs. The following forms, or their equivalent, will be used to initiate the credentialing process:
· OPM Standard Form 86
· OF 306
· Fingerprinting (done electronically) (local procedures may require the fingerprinting to be done at a police station; in this case, any charges are to be borne by the Contractor) PIV Form.
Contractor employees are required to give, and to authorize others to give, full, frank, and truthful answers to relevant (within 5 years) and material questions needed to reach a suitability determination. Refusal or failure to furnish or authorize provision of information may constitute grounds for an unfavorable security and suitability decision and denial or revocation of credentials.
Government personnel may contact the Contractor personnel being screened or investigated in person, by telephone or in writing, and the Contractor agrees to make them available for such contact. Alternatively, if an individual has already been credentialed by another agency through OPM, and that credential has not yet expired, further investigation may not be necessary.
During performance of the Order, the Contractor will keep the COR apprised of changes in personnel to ensure that performance is not delayed by compliance with credentialing processes. Cards that have been lost, damaged, or stolen must be reported to the COR and Issuing Office within 24 hours. Replacement will be at the Contractor’s expense. If reissuance of expired credentials is needed, it will be coordinated through the COR.
When a Contractor employee is no longer working under the contract, the Contractor will ensure that all government property, hard copy records, and electronic files, are returned to the COR.
Privacy Act and Data: The Contractor shall be responsible for protecting all information used, gathered, or developed as a result of work. The Contractor shall protect all Sensitive but Unclassified (SBU) government data. All compiled or derived information, work papers, drafts, and final documents developed or accessed, or any product/system developed are the property of the United States Government. Information acquired or generated is subject to the Privacy Act.
E. POST AWARD CONFERENCE CALL
The Contractor and the BLM will participate in a post award conference call which will be scheduled within 10 days from award at a date and time mutually agreed upon. The Post Award Conference Call will be to introduce all parties, define roles and responsibilities (Government/Contractor), discuss contract administration, discuss a tentative schedule, and answer any technical questions.
V. ADMINISTRATIVE ACTIVITY CONTACTS
AUTHORIZED ADMNISTRATIVE ACTIVITY
The Authorized Administrative Activity responsible for the management of the order is:
Department of the Interior Bureau of Land Management, Wyoming State Office 5353 Yellowstone Road, Cheyenne, WY 82009
BLM Contracting Officer (CO):
Kelly Palmer, Wyoming State Office, 307-775-6057, kpalmer@blmgov
BLM Contracting Officer Representative (COR):
Andy Skordas, Rawlins Field Office, 307-328-4374, askordas@blm.gov
VI. PROVISIONS/CLAUSES
The following FAR provision is also incorporated in full…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .