Draft SOW.pdf
PDF 382 KB Posted
- Attached to
- Access Control Doors Federal contract opportunity
- Solicitation number
- N6426720Q0089
About this file
This statement of work outlines requirements for an access control system installation project at a Naval Surface Warfare Center facility. The contractor will provide materials and installation for active shooter lockdown systems, PIV card readers, and an access control system upgrade. Specifically, the contractor must install 47 HID RPK40 PIV card readers compatible with fiber optic cable, active shooter buttons, electrified doors, and upgrade the existing Lenel OnGuard software and Windows operating system. The contractor must also provide project management, installation, training, reliability testing, and building diagrams. The response is due within 30 days and the contractor must adhere to all applicable Navy security and safety regulations during the project.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Rev 3/31/16
Statement of Work
Access Control
1. INTRODUCTION
Naval Surface Warfare Center (NSWC) Corona Division has a requirement for materials and installation of security locks, locking mechanisms, software to control security card readers, and reinforcement of existing security control systems. NSWC Corona Division is a Navy Working
Capital organization that supports numerous federal entities in Research, Development, Test and
Evaluation.
2. BACKGROUND
Due to Defense Department and local policy guidance, all users are required to access the installation using a PIV that is approved via a specific software based system that is centralized and controlled by NSWC Corona Security. NSWC Corona is seeking the exact system structure currently in place, and upgrade currently identified deficiencies to the most recent version. The system must be compatible with existing access control system due to current cyber security accreditation.
3. SCOPE
Contractor will provide all materials and perform installation for numerous Johnson Controls related active shooter security control doorlock disabling systems. Additionally, contractor will install new infrastructure cabling to support expansion of current system at NSWC Corona
Division. Contractor will ensure all doors are currently in compliance with currently implemented system, as well as install additional PIV card readers. The contractor will provide a turnkey solution to correct existing deficiencies, as well as upgrade current operating system to
Windows 10 and upgrade Lenel software license to most current version. Lenel and Johnson
Controls products are the only approved products to be utilized for the software and hardware upgrades during this effort due to current contract in place, as well as current accreditation pending approval. The vendor will provide door locking security systems, electrified locking hardware, enclosures, commercial grade plenum rated low voltage cabling, active shooter locking systems, power supplies, onguard lockdown solution kits, card readers that may be identified during work to be performed, and replace miscellaneous parts that are necessary to ensure the above requirements are met. The vendor will provide all applicable engineering, and project management support, as well as technical expertise necessary to perform installation according to industry standard.
The contractor will provide onsite training to appointed NSWC Corona Division representatives.
Vendor will integrate existing equipment into newly installed equipment, as well as migrate data from existing system into newly installed system.
NSWC Corona has the requirement to install a fully operational turnkey 47 HIV PIV RPK40
CaC readers that are compatible with both SC and ST connectors, as well as single-mode and multimode fiber optic cable systems, active shooter buttons compatible with existing Lenel ACS to include turnstile connectivity to include software and hardware upgrades. The installation will include electrified doors compatible with NSWC Corona master key system, locksmith will re-utilized existing cores for every buildings. Card readers will be installed outside of building entrance and active shooter buttons will be installed inside the building with 10 feet of main exit door. Additionally, contractor will upgrade existing system to current Windows 10 and Lenel software versions, as well as migrate old system data and interconnections to newly installed system. The new system will be on a desktop based system with adequate RAM and storage to support system operability. The contractor will provide a backup laptop system that meets the same configuration as the desktop version. This backup laptop will have Windows 10 current version and most current version of Lenel software. Contract will not migrate current system data to the backup laptop. Data from existing system will only be migrated to newly installed desktop system. Contractor will provide 16 hours of onsite training for newly installed system over the course of one month to government and contract employees assigned to utilize the newly installed equipment. Contractor will provide all deliverables listed in CDRLS A001, A002, and A003 (Section 7. Deliverables) included with this effort.
All part numbers must be brand name or equivalent, and must be able to interface with existing doors and equipment. The only exception to this is that the software must be Lenel Onguard version 7.6, and the system operating system must be Windows 10 with cyber security NIST
STIGs implemented, with the system still working as designed, as well as Securitron Emergency
Lockdown Button must be brand name or equivalent, but must have a yellow face and the push button must be red “SEE EXAMPLE ON FIGURE 1” written, and a clear protective cover over the button . OnGuard Access Control Server software must be enabled to allow administrative access to the government, and no subscription service is required. No internet connectivity will be utilized for the software, so the license must be fully controlled by the government, and must be activated in full by the vendor upon installation.
Card reader project will include:
Securitron Emergency Lockdown Button (to match existing buttons on site (Figure 1)
Figure 1
Provide all required electronic locking hardware for all doors above that will have a reader/lockdown button installed. Provide all necessary access control panels/hardware needed for the installation of these readers. Provide all low-voltage and electrical cabling required for the installation of this access control hardware, and ensure all installed equipment is properly connected to a power source located within each building.
Upgrade OnGuard Software and operating system, and provide new desktop and backup laptop containing the new configurations to allow all additional installed readers on the system including additional licenses needed for the additional hardware. Below are the quantities of HID
RPK40 PIV card readers and lockdown buttons to be installed:
Equipment Qty
Readers 47
Universal Power Supply 18
Network Hub (CCL approved) 18
Lockdown Buttons 47
Magnetic Locking Systems Specifications
Instant release circuit - no residual magnetism
Both locks can be controlled as one or individually
Surface mounts easily with minimal tools
Fully sealed electronics - tamper proof and weatherproof
Mounted using steel machine screws into blind finishing nuts
Architectural brushed stainless steel finish (US32D/630)
All ferrous metal surfaces plated to MIL specification
Eighteen inches [45.7cm] of jacketed, stranded conductor for each lock
Automatic dual voltage - no field adjustment required
Lock options include BondSTAT magnetic bond sensor and integrated door position switch
Lifetime replacement, no fault warranty
Specification Data
Holding Force: 1200 lbs. [544 kg] per lock
Current Draw and Voltage: 250mA at 12VDC; 150mA at 24VDC per lock
Operating Temperature: -40 to +140F [-40 to +60C]
4. APPLICABLE DOCUMENTS
Are there any other applicable documents?
Example
Federal Standards: The contractor is required to adhere to all applicable standards and guidelines when applicable. In the absence of named standards, Department of the Navy (DON) standards, applicable Federal Information Processing Standards (FIPS), and broadly accepted professional standards shall prevail as related to the associated industries within the task identified in Section 5.0.
Document Type No./Version Title Date
SECNAV
M-5510.30 Department of the Navy Personnel Security
Program, http://doni.daps.dla.mil/secnavmanuals.aspx
June 2006
OPNAV 5510.60M Security Regulations for Offices Under the
Cognizance Of the Chief of Naval Operations
OPNAV 5300.23 Occupational Safety & Health Administration
(OSHA)
OPNAVINST 5090.1C Navy Environmental and Natural Resources
Program Manual
SECNAV M-5510.30 Navy Security Regulations
OPNAV Instruction 5510.60M Security Regulations for Offices Under the
Cognizance Of the Chief of Naval Operations
NSWCCORDIVINST 3070.1 Operations Security
SECNAV
M-5510.36 Department of the Navy Information Security
Program http://doni.daps.dla.mil/secnavmanuals.aspx
June 2006
NIST Special
Publication 800-171
800-171 Minimum cybersecurity standards
(DoDD) 8500.01E (DoDD)
8500.01E
(DoDD) 8500.01E 1 Oct 2019
OSHA 29 CFR
Standards for General Industry, and 29 CFR
1925 Safety and Health Standards for Federal
Service Contracts
5. REQUIREMENTS
Provide program, project and engineering support during this contract’s lifecycle. Perform onsite site survey of existing security posture. Identify applicable replacement parts for outdated equipment. Provide technicians to install numerous associated active shooter lockdown systems, PIV card readers and access control systems. Upgrade existing software to most current version.
Provide industry standard commercial warranty on all parts, labor and software. Provide a diagram (base wide floor plan) of locations and types of equipment installed. Work with local security posture team to ensure systems are working with existing system. Provide project installation schedule. Provide reliability test reports of newly installed systems.
The system will be Windows 10 based, and will have all necessary NIST 800 STIGs (Security
Technical Guides) activated per the Windows 10 required STIG, and the Lenel software must still work as designed. The access card readers must be compatible with both SC and ST fiber optic connectors, as well as compatible with single-mode and multi-mode fiber optic applications. All equipment must be Common Criteria List (CCL) approved or equivalent. All current hubs in the buildings listed above must be replaced with CCL approved hubs, and must be applicable cyber security controls.
The Lenel software application and Windows 10 system must be fully cyber security compliant.
The system must have administrative privileges fully invoked for government users to fully access, to include administrative privileges for the Lenel software application. The government must have the ability to add, remove, change users of the system, as well as add, remove, change user access to the exterior card readers. The system must be compliant with DoD PIV cards. The system must come with DoD approved anti-virus software, and operate as designed. This applies to both the desktop and laptop being provided for this effort. The system must operate in accordance with Minimum cybersecurity standards described in NIST Special Publication 800-
171 which are as follows:
6 DELIVERABLES
The contractor shall provide deliverables as described in the SOW and CDRLs. Format and delivery schedule for deliverables shall be outlined in CDRLs.
Number Name
A001 Project Installation Schedule and Management Plan
A002 System Reliability Test Reports
A003 Building Diagrams depicting installed equipment
A0004 Information Security (IS) Plan Of Action & Milestones (POA&M)
7. Security
7.1 Security Clearances and Investigations. All personnel must submit SECNAV 5512 to obtain and maintain background investigations and clearances appropriate to support contract performance. Clearances shall be maintained for the duration of this procurement. Personnel unable to successfully obtain or maintain an appropriate investigation or necessary clearance will immediately, upon notification from Facility Security Officer (FSO) NAVAL WEAPONS
STATION SEAL BEACH CORONA DETACHMENT PASS AND ID OFFICE, and will be expected to vacate the installation or performance location. The department manager, SME and security office will also be notified of any such vacancy.
7.2 Clearance Lists. A list of personnel and their security clearances shall be delivered to the
(NSWCCORDIV) security office SME no later than 20 business days following award and shall be updated with the monthly personnel listing deliverable and when personnel changes occur.
7.2.1 Personnel Lists. Contractor will provide government a personnel list on company letterhead signed by competent authority/manager of all (prime and sub) personnel performing on the contract. This list will also be reconciled and forwarded to the NSWCCORDIV security office as changes occur. A preferred template example not containing PII is available from the SME or security office.
7.3 Contractors will immediately notify the SME of any subcontracting.
7.4 General Security Compliance. Contractor personnel shall comply with all DoD, DoN, NAVSEA, NSWCCORDIV, and other performance location’s security instructions, policies, procedures and guidance. These requirements apply both on and off Government property at
NSWC Corona, remote sites or travel destinations, to include any established check-in / check-out procedures of personnel occupying Government facilities.
7.5 Government Facilities. Access to Government facilities is at the discretion of the
Government. The Government reserves the right to rescind access at any time. In each instance when employees no longer work for a company due to circumstances favorable or unfavorable, the FSO shall ensure the prompt return of the following materials:
#1 Government-owned keys to desks, offices, etc.
#2 CAC, except for CACs issued to retired military personnel and retired civil servants on that basis.
#3 Base Passes, except for passes issued to retired military personnel and retired civil servants on that basis
8. ON-SITE SAFETY AWARENESS
(a) In accordance with 29 CFR 1925 Safety and Health Standards for Federal Service Contracts, the contractor company shall strictly adhere to Federal Occupational Safety and Health
Administration (OSHA) Regulations, Environmental Protection Agency (EPA) Regulations, and all applicable state and local requirements. OSHA Directive CSP 03-01-003 Voluntary
Protection Programs (VPP) Policies and Protection Manual defines contractors into two categories.
1) Applicable Contractor. A contractor whose employees worked at least 1,000 hours for a VPP participant in any calendar quarter within the last 12 months and are not directly supervised by the applicant/participant.
2) Nested Contractor. Reference (a) does not specifically define this term. However, in discussing injury and illness data requirements for contractors, the OSHA guidance states that “nested contractors . . . are supervised by host site management”, and “are regularly intermingled with the owner’s employees and under direct supervision by management”.
(b) In accordance with OPNAVINST 5100.23(series) and OSHA Directive CSP 03-01-003, our command is to ensure that all contractor employees have read the NSWC Corona Divisions document entitled, “Commanding Officers Occupational Safety and Health Policy Statement” and “Occupational Safety and Health Administration (OSHA) Voluntary Protection Programs
(VPP) document” within 30 days of commencing performance. This document is available at https://intranet.crna.nmci.navy.mil/CMD/wwwroot2/ or you can contact your Contracting
Officer Representative (COR) or Subject Matter Expert (SME) for additional assistance/options.
(c) In accordance with OPNAVINST 5100.23(series) and OSHA Directive CSP 03-01-003, our command is to ensure that all nested contractor employees complete the Voluntary Protection
Program (VPP) Awareness Training within 30 days of commencing performance at NSWC
Corona Division. This document is available at https://intranet.crna.nmci.navy.mil/CMD/wwwroot2/ or you can contact your Contracting
Officer Representative (COR) ) or Subject Matter Expert (SME) for additional assistance/options.
(d) In accordance with 29 CFR 1904 and OSHA Directive CSP 03-01-003, the contractor company shall certify that all contractor employees have read the NSWC Corona Divisions document entitled “Commanding Officers Occupational Safety and Health Policy Statement” and “Occupational Safety and Health Administration (OSHA) Voluntary Protection Programs
(VPP) document” and all nested contractor employees have taken the Voluntary Protection
Program (VPP) awareness training within 30 days of commencing performance at NSWC
Corona Division. This can be accomplished by sending an e-mail to their Contracting Officer
Representative (COR) ) or Subject Matter Expert (SME) with a copy to Environmental, Safety and Health (ESH) Program Office (Code 013) (joseph.edgman@navy.mil). The document/e-mail shall include the employees name, work site, and contract number.
(e) In accordance with 29 CFR 1904 and OSHA Directive CSP 03-01-003, the contractor company shall submit their OSHA 300 Logs (injury/illness rates) within 30 days of commencing performance at NSWC Corona Division to their Contracting Officer Representative (COR) ) or
Subject Matter Expert (SME) with a copy to Environmental, Safety and Health (ESH) Program
Office for review by the ESH Manager (Code 013).
(f) In accordance with 29 CFR 1904 Standards for Recording and Reporting Occupational
Injuries and Illness, the contractor shall post their OSHA 300 Logs in a conspicuous place where employee notices are posted immediately upon commencing performance and at intervals as required by CFR.
(g) In accordance with 29 CFR 1904 and OSHA Directive CSP 03-01-003, require Contractor
Company to provide quarterly reports of recordable cases and hours worked so that site OSHA recordkeeping personnel can calculate and monitor contractor TCIR/DART rates. Only include cases and hours for work performed at the VPP participant's site.
(h) In accordance with OPNAVINST 5100.23(series) and OSHA Directive CSP 03-01-003, the applicable contractor company shall submit Total Case Incident Rate (TCIR) and Days Away, Restricted and Transfer (DART) rates for the past three years within 30 days of commencing performance at NSWC Corona Division to their Contracting Officer Representative (COR) with a copy to Environmental, Safety and Health (ESH) Program Office for review by the ESH
Manager (Code 013).
(i) In accordance with 29 CFR 1904 and OSHA Directive CSP 03-01-003, the contractor shall report all work-related injuries/illnesses that occurred while working at NSWC Corona Division to their Contracting Officer Representative (COR) ) or Subject Matter Expert (SME) and to
Environmental, Safety and Health (ESH) Program Office for review by the ESH Manager (Code
013).
(j) In accordance with 29 CFR 1925 and OSHA Directive CSP 03-01-003, the contractor shall ensure that all contractor employees working at NSWC Corona Division are briefed with the applicable sections of the Safety and Occupational Health (SOH) Program Manual
(NSWCCORDIVINST 5100.3(series)). This document is available at https://intranet.crna.nmci.navy.mil/CMD/wwwroot2/ or you can contact your Contracting
Officer Representative (COR) ) or Subject Matter Expert (SME) for additional assistance/options.
These are requirement from OSHA Code of Federal Regulations (CFR), 29 CFR 1910 Standards for General Industry, and 29 CFR 1925 Safety and Health Standards for Federal Service
Contracts, and from OPNAVINST 5090.1 (series).
10. ON-SITE ENVIRONMENTAL AWARENESS
In accordance with 29 CFR 1925 Safety and Health Standards for Federal Service Contracts, the contractor shall strictly adhere to Federal Occupational Safety and Health Administration
(OSHA) Regulations, Environmental Protection Agency (EPA) Regulations, and all applicable state and local requirements.
File details come from the government source that posted it. Updated .