DRFP Atch 1 SOW.pdf

PDF 877 KB Posted

Attached to
Draft RFP: Integrated Base Defense Security Systems (IBDSS) IDIQ Federal contract opportunity
Solicitation number
08152020
Issued by
Department of the Air Force United States Air Forces in Europe - Air Forces Africa

View the file

Other files for this federal contract opportunity

Other files attached to Draft RFP: Integrated Base Defense Security Systems (IBDSS) IDIQ, newest first.
File Type Posted
DRFP Atch 2 ITO.pdf PDF
DRFP Atch 3 Eval Criteria.pdf PDF
DRAFT Solicitation - FA564120R0008.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 1 of 44

Statement of Work

For

United States Air Force Europe

Integrated Base Defense Security

Systems

21 January 2020

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 2 of 44

Contents

1.0 Purpose………………………………………………………………………………...3

2.0 Applicable Documents………………………………………………………………...3

3.0 Performance Requirements…………………………………………………………..7

4.0 Section 508 Accessibility Standards………………………………………………...29

5.0 Contract Administration…………………………………………………………….30

6.0 Quality………………………………………………………………………………...31

7.0 Documentation and Deliverables…………………………………………………….33

8.0 Security…………………………………………………………………………….….35

9.0 Contractor Facilities………………………………………………………………….41

10.0 Contractor Acquired Property…………………………………………………

11.0 Safety Issues…………………………………………………………………….……42

12.0 Travel……………………………………………………………………………..…..42

13.0 Acceptance Plan…………………………………………………………………..….44

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 3 of 44

SECTION C – DESCRIPTION/SPECS/WORK STATEMENT

SPECIFICATIONS/STATEMENT OF WORK

Work under this performance-based contract shall be performed in accordance with (IAW) the following description/ specifications/ statement of work (SOW):

1.0 PURPOSE

1.1 BACKGROUND

The United States Air Force (USAF) Installation Mission Support Center (IMSC) Detachment 4 (Det

4) in response to initiatives promulgated by the United States Air Force Europe (USAFE) requires engineering development, design, procurement, fabrication, configuration, integration, installation, modernization, and logistics solutions for electronic security and emergency management deliverable products. These deliverable products will support the operational requirements of the USAFE where electronic security and emergency management are of high or vital interest. This SOW provides the general guidelines and specific requirements to design, develop, and deliver electronic security and emergency management deliverable products that protect our Nation's critical infrastructure, personnel, assets, and resources in the United States European Command (USEUCOM) area of responsibility (AOR).

1.2 SCOPE

The purpose of this contract is to provide streamlined delivery of electronic security and emergency management deliverable products to USAFE in the USEUCOM AOR. The scope of this contract covers the entire spectrum of outcomes associated with the full lifecycle of delivery and support of electronic security and emergency management deliverable product capabilities. This SOW covers requirements as it relates to electronic security and emergency management deliverable product experience with specific commercial off the shelf (COTS) solutions and variations of project environments that range in risk and complexity based on size and other factors. Support under this

SOW include supply requirements such as material, shipping, travel, project/program/engineering management, installation and other technical support associated with the development and delivery of

USAFE electronic security and emergency management deliverable products. The delivery location will be determined at the delivery order (DO) level.

2.0 APPLICABLE DOCUMENTS (AND DEFINITIONS)

All work shall be accomplished using the best commercial practices and current acceptable industry standards. The applicable references and standards invoked will vary within individual tasks and will be specifically called-out in each DO. IAW Defense Acquisition

Policy changes, maximum utilization of non-Government standards will be made wherever practical. Where backward compatibility with existing systems is required, selected interoperability standards will be invoked. The following documents are not exclusive;

however, the contractor shall meet those cited when applicable to the DO.

2.1 REQUIRED DOCUMENTS

The following instructional documents are mandatory for use. Unless otherwise specified, the document’s effective date of issue is the date on the request for proposal. Additional applicable documents may be included in specific DOs. The required documents are not limited to the outlined list below, and contractor is subject to any applicable required documentation inadvertently not included in the list. In addition, the contractor is required to use the most current version of the

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 4 of 44 documents, or in case document becomes obsolete, the replacement document, based on future updates.

Document Number Title a.

DoDM 5200.01 Department of Defense (DoD) Manual – Information

Security Program dtd 24 Feb 12

b. DoD 5220.22-M DoD Manual – National Industrial Security Program

Operating Manual (NISPOM) dtd 28 Feb 06

c. DoDI 5220.22 DoD Instruction – National Industrial Security

Program dtd 18 Mar 11

d. DoD 5200.2-R DoD Regulation – Personnel Security Program dtd Jan

e. DoDD 5205.02E DoD Directive – Operations Security (OPSEC)

Program dtd 20 Jun 12

f. DoD 5205.02-M DoD Manual – Operations Security (OPSEC)

Program Manual dtd 3 Nov 08

g. DoDI 6055.17 Installation Emergency Management Program, 13 Jan

h. DoDI 6055.06 Fire and Emergency Services Program, 21 Dec 2006

i. DoDI 6205.4 DoD Instruction, Immunization of Other Than U.S.

Forces (OTUSF) for Biological Warfare Defense

j. DoDI 8500.01 DoD Instruction – Cybersecurity dtd 14 Mar 14

k. DoDI 8510.01

DoD Instruction – Risk Management Framework

(RMF) for DoD Information Technology (IT) dtd 12

Mar 14

l. DoDD 8570.01 DoD Directive – Information Assurance Training, Certification, and Workforce Management dtd 15 Aug

m. DoD 8570.01-M

Information Assurance (IA) Workforce Improvement

Program dtd 19 Dec 05 with Change 3 dtd 24 Jan 12

n. ICD 705 Sensitive Compartmented Information Facilities

o. IC Tech Spec‐for ICD/ICS

Technical Specifications for Construction and

Management of Sensitive Compartmented

Information Facilities

p. ICS 705-1 Physical and Technical Security Standards for

Sensitive Compartmented Information Facilities

q. ICS 705-2 Standards for the Accreditations and Reciprocal Use of Sensitive Compartmented Information r.

NIST SP 800-Series National Institute of Standards and Technology

Special Publications 800 Series – Computer Security

Policies, Procedures, and Guidelines s CNSSAM TEMPEST/1-13 TEMPEST Accreditation for Sensitive

Compartmented Information Facilities

2.2 GUIDANCE DOCUMENTS

The following documents are to be used as guidance. Unless otherwise specified, the document’s effective date of issue is the date on the request for proposal. Additional applicable documents may be included in specific DOs. The guidance documents are not limited to the outlined list below, and are subject to any applicable guidance documentation inadvertently not included on the list. In addition, the contractor is required to use the most current version of the documents, or in case document becomes obsolete, the replacement document, based on future updates.

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 5 of 44

a. MIL-HDBK-61A Configuration Management

b. MIL-STD-130N Change

DoD Standard Practice – Identification Marking of US

Military Property

c. MIL-STD-881C Work Breakdown Structure for Defense Materiel Items

d. MIL-STD-1916 DoD Test Method Standard – DoD Preferred Methods for Acceptance Of Product

e. MIL-STD-129 DoD Standard Practice – Military Marking For

Shipment and Storage

f. MIL-STD-130 DoD Standard Practice – Identification Marking of US

Military Property

g. DoDI 2000.12 DoD Antiterrorism Program

h. DoDI 3020.41 DoD Instruction – Operational Contract Support

(OCS), of 20 Dec 10

i. DoDI 3020.52 Change 1 DoD Installation Chemical, Biological, Radiological, Nuclear, and High-Yield Explosive Preparedness

Standards 22 May 2017

h. DoDI 4161.02 DoD Instruction – Accountability and Management of

Government Contract Property, Apr 27,2012

i. DoDI 4650.10 Land Mobile Radio (LMR) Interoperability and

Standardization, 28 Jul 15

j. DoDD 5000.01 DoD Directive – The Defense Acquisition System

k. DoDI 5000.02 DoD Instruction – Operation of the Defense

Acquisition System

l. DoDI 5000.56 CE-01 Programming GEOINT, GI&S, Geodesy

Requirements for Developing Systems, 9 Jul 10

m. DoDI 8100.3 DoD Voice Networks, 16 Jan 04

n. DoDI 8100.04 DoD Unified Capabilities, 9 Dec 10

o. DoDI 8130.01 Installation Geospatial Information and Services

(GI&S), 9 Apr 15

p. DoDI 8530.01 Cybersecurity Activities Support to DoD Information

Network, 07 March 2016

q. APCO P25 SOR Project 25 (P25) Statement of Requirements, 3 Mar 10

r. APCO UCAD Unified Computer Aided Dispatch Functional

Requirements, Aug 2010

s. TIA-TSB-102 APCO P25 System and Standards Definition, 01

March 2016

t. NENA 02-010 Version 9 Standard Formats & Protocols for Automatic Location

Information (ALI) Data Exchange, ALI Response &

Geographic Information System (GIS) Mapping, 28

Mar 2011

u. NENA 02-014 Version 1 GIS Data Collection & Maintenance, 17 Jul 2007

v. NENA 08-502 Enhanced 9-1-1 (E9-1-1) Requirements Information

Document, 23 Jul 2004

w. NENA 71-001 Version 1 Next Generation 9-1-1 (NG9-1-1) Additional Data, 17

Sep 2009

x. NENA 71-501 Version

1.1

Synchronizing GIS with Master Street Address Guide

(MSAG) and ALI, 8 Sep 2009

y. NENA-STA-004.1-2014 Next Generation US Civic Location Data Exchange

Format (CLDXF), 23 Mar 2014

z. NENA-INF-014.1-2015 Development of Site/Structure Address Point GIS

Data for 9-1-1, 18 Sep 2015

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 6 of 44

aa. URISA United States Thoroughfare, Landmark, and Postal

Address Data Standard, Feb 2011

ab. USPS Publication 28 Postal Addressing Standards, May 2015

ac. UFC 3-580-01 Change 1 Telecommunications Building Cabling Systems

Planning and Design 28 Feb 2011

ad. UFC 4-101-03 Security Engineering: Physical Security Measures for

High Risk Personnel 08 Feb 2011

ae. UFC 4-010-01 Change 1 Unified Facilities Criteria DoD Minimum

Antiterrorism Standards for Buildings 09 Feb 2012

af. UFC 4-010-05 Change 1 Sensitive Compartmented Information Facilities

Planning, Design, and Construction 01 Feb 2013

ag. UFC 4-020-01 Security Engineering Facilities Planning Manual

ah. UFC 4-020-02FA Security Engineering: Concept Design (FOUO)

ai. UFC 4-020-03FA Security Engineering: Final Design (FOUO)

aj. UFC 4-021-01 Design and O&M: Mass Notification Systems

ak. UFC 4-021-02 Electronic Security Systems

al. UFC 4-022-01(Updated) Security Engineering Entry Control Facilities - Access

Control Points 27 July 2017

am. UFC 4-024-01 Security Engineering: Procedures for Designing

Airborne, Chemical, Biological, Radiological

Protection for Buildings

an. UFC 4-025-01 Security Engineering: Waterfront Security

ao. UFC 3-550-01 Exterior Electrical Power Distribution, 1 July 2012

ap. National Fire Protection

Association (NFPA) 70

National Electric Code

aq. NFPA 72-(latest version) National Fire Alarm and Signaling Code

ar. NFPA 101-(latest version)

The Life Safety Code

as. ISO 9001 (ANSI/ASQ

Q9001) (latest version)

International Organization for Standardization

(American National Standard Institute/American

Society for Quality) – Quality Management Systems, Requirements

at. ISO/IEC 12207 (latest version)

International Organization for Standardization/

International Electrotechnical Commission: Systems and Software Engineering – Software Life Cycle

Processes

au. ISO/IEC 15288 (latest version)

International Organization for Standardization/

International Electrotechnical Commission: Systems and Software Engineering – System Life Cycle

Processes

av. IEEE Std 12207-2008

(latest version)

Systems and Software Engineering – Software Life

Cycle Processes

aw. IEEE Standard 142-2007 Recommended Practice for Grounding of Industrial and Commercial Power Systems (Green Book)

ax. MIL-HDBK-419A-V-182 Grounding, Bonding and Shielding for Electronic

Equipment and Facilities

ay. MIL-STD-1472G ii DoD Design Criteria Standard, Human Engineering

az. MIL-STD-188-124B

(notice 4)

Interface Standard: Grounding, Bonding and

Shielding For Common Long Haul/Tactical

Communication Systems Including Ground Based

Communications-Electronics Facilities and Equipment

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 7 of 44

ba. 28 CFR Part 36 Code of Federal Regulation ADA Standards for

Accessible Design

bb. ANSI/EIA-748A

Revision D

America National Standards Institute/Electronic

Industries Alliance Standard – Earned Value

Management (EVM) Systems

bc. HSPD-12 Homeland Security Presidential Directive – Policy for a Common Identification Standard for Federal

Employees and Contractors, August 27, 2004

bd. DoDM-1000.13-M-V1 DoD Manual – DoD Identification Cards: ID card

Life-Cycle dtd 23 Jan 14

be. FIPS PUB 201-2 Federal Information Processing Standards Publication

201-2 – Personal Identity Verification (PIV) of

Federal Employees and Contractors, August 2013

bf. Form I-9, OMB No. 115-

US Department of Justice, Immigration and

Naturalization Services, Form I-9, OMB No. 115-

0136 – Employment Eligibility Verification bg.

N/A

National Institute of Standards and Technology

(NIST), Framework for Improving Critical

Infrastructure Cybersecurity. Version 1, dtd 12 Feb 14

bh. NIST Special Publication

800-53 Revision 4

Security and Privacy Controls for Federal Information

Systems and Organizations

bi. JAFAN 6/9 Change 1 Joint Air Force, Army, Navy 23 March 2004 bj.

AFI 31-401 Change 1

Department of the Air Force Information Security

Program Management bk.

DoD Manual 5100.76

Change 1

Physical Security of Sensitive Conventional Arms, Ammunition, and Explosives (AA&E), 17 April 2012

bl. AFI 31-101 Department of the Air Force Integrated Defense

bm. TIA/EIA Standard Commercial Building Telecommunications

Cabling Standard

bn. ANSI/TIA-606-B Administration Standard for Commercial

Telecommunications Infrastructure

bo. ASTM Standards (latest edition)

Copper Conductors for Electrical Power and

Electronic Hook-up Wiring

bp. NEMA 250-2008 Enclosures for Electrical Equipment

bq. FS W-C586 Conduit Outlet Boxes, Bodies, and Entrance

Caps, Electrical: Cast Metal

br. EIA 310-D Cabinets, Racks, Panels, and Associated

Equipment

bs. SOVT Preparation and Execution Guide (SPEG) v1.4 format

bt. DoD 5200.08-R Physical Security Program

bu. DoDI 5100.76 Safeguarding Sensitive Conventional Arms, Ammunition and Explosives (AA&E)

bv. N/A Non-Nuclear IDS Equipment Approval

2.3 SOURCE OF DOCUMENTS

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 8 of 44

The contractor shall obtain all applicable documents. Many documents are available from online sources.

All commercial and industrial documents can be obtained through the respective organization’s website.

3.0 PERFORMANCE REQUIREMENTS

The following paragraphs list anticipated required support requirements that shall be required throughout the contract life. The contractor shall provide deliverable products required by individual

DOs pursuant to the general requirements specified herein. All activities performed as part of this contract shall be performed IAW best commercial practices and Government standards, regulations, as described herein and within each DO. Each DO will define the user requirements, equipment, supplies, technical specifications, personnel requirements, travel, engineering, information assurance

(IA), project/program management, logistics, and any other requirements/support for completion of electronic security and emergency management deliverable products for the USAFE in the

USEUCOM AOR.

3.1. TECHNICAL CAPABILITIES

The contractor shall require capabilities with typical electronic security or emergency management deliverable products, vendors, and related certifications necessary to perform work under this SOW as specified below. DOs placed under this contract may require one (1) or more of the deliverable products listed in this section. This is not an all-inclusive list and does not limit the scope of this contract with regards to electronic security and emergency management deliverable products, chemical, biological, radiological, nuclear, and explosive (CBRNE), security and surveillance-type deliverable products.

3.1.1 Electronic Security and Emergency Management Equipment

The contactor shall provide functional and technical capabilities supporting of a wide range of access control, intrusion detection, video management, physical security information management (PSIM) and any other equipment and software associated with electronic security and emergency management deliverable products found on the U.S. Air Force IDS Equipment Approval (i.e.

Approved Product List (APL)). The APL may be revised/updated by the U.S. Air Force and is subject to change. These may include, but are not limited to:

a. AMAG Intrusion Detection, Access Control, and Video Management Solutions

b. LenelS2 Intrusion Detection, Access Control, and Video Management Solutions

c. Software House Intrusion Detection, Access Control, and Video Management Solutions

d. Honeywell Intrusion Detection, Access Control, and Video Management Solutions

e. Monitor Dynamics Intrusion Detection, Access Control, and Video Management Solutions

f. American Dynamics Cameras, Encoders/Decoders, Controllers, Recorders, and Video

Management Solutions

g. DMP Intrusion Detection Solutions

h. Advantor Systems Access Control and IDS

i. Hirsch Identiv Access Control Solutions

j. Fiber SenSys, Inc. Security Intrusion Detection Solutions

k. Future Fibre Technologies Perimeter Intrusion Detection Solutions

l. Southwest Microwave Intrepid Perimeter Security Solutions

m. Axis Cameras, Encoders/Decoders, Controllers, Recorders, and Video Management Solutions

n. Bosch Cameras, Encoders/Decoders, Controllers, Recorders, and Video Management Solutions

o. Pelco Cameras, Encoders/Decoders, Controllers, Recorders, and Video Management Solutions

p. Verint Cameras, Encoders/Decoders, Controllers, Recorders, and Video Management Solutions

q. Genetec Cameras, Encoders/Decoders, Controllers, Recorders, and Video Management

Solutions

r. Chameleon Closed Circuit Television (CCTV) Solutions

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 9 of 44

s. FLIR Thermal Cameras, Radar Solutions, and Cameleon Tactical Perimeter Intrusion Detection

t. Milestone System xProtect CCTV Cameras, Controllers, Recorders, and Video Management

System

u. Tactical Automated Security Systems

v. Proximex Physical Security Information Management Solutions

w. Security Information Systems Physical Security Information Management Solutions

x. Sensors and Command-Control solutions providing protection against chemical, biological, radiological, nuclear, and explosive threats.

y. Sensors and Command-Control solutions providing perimeter protection and early warning notification to respond to human and other physical threats in complex and challenging environments.

z. Eaton Cooper Notification Mass Notification Solutions (MNS)

aa. Federal Signal Mass Notification Solutions

ab. Northrop Grumman Command Point Computer Aided Dispatch (CAD)

ac. Enhanced 911 (E911) communication solutions

ad. Monaco Fire and Security Alarm Systems and Mass Notification System

ae. Whelen Mass Notification

af. Regional Alarm Monitoring Automated Systems

ag. Local Alarm Monitoring Automated Systems

ah. Geographic Information System (GIS)

ai. Management Information System (MIS)

aj. Records Management System (RMS)

ak. Athoc Interactive Warning System

al. CAD solutions

am. Enhanced 9-1-1 (E9-1-1)/Next Generation 9-1-1 (NG9-1-1) customer premise equipment

(CPE) call management solutions

3.1.2 CBRNE Equipment

The contactor shall have the ability to provide functional and technical expertise to respond to an evolving base of sensors being deployed for protection against CBRNE threats. A sample representative list of original equipment manufacturer (OEMs) of CBRNE sensors and command-control solutions that are used to support the USAFE in the USEUCOM are provided below (subject to revision), based on anticipated/future CBRNE requirements originating in the USEUCOM AOR :

a. ENSCO Inc. (Sentry Software, sensor fusion and decision support software development and support)

b. Liedos (development and service capabilities for the Radiation Portal Monitors)

c. Mesh Inc (software and sensor development)

d. KD Analytical (AirGard sensor repairs and sustainment)

e. FLIR (Sensor repairs and sustainment)

f. Canberra (Sensor repairs and sustainment)

g. Smith Detection (Sensor repairs and sustainment)

h. S3I for (Sensor development, repairs, and sustainment)

i. Sage Defense (Sensor development, repairs, and sustainment)

3.1.3 Equipment Certification

The contractor shall provide trained and certified integrator, partner, or similar certifications for

COTS OEM security solutions as applicable to individual DOs for equipment listed below (subject to revision) based on anticipated/future IDS requirements originating in the USEUCOM AOR. The contractor shall be certified as a Value Added Reseller (VAR) at the time of DO award for Lenel, Vindicator and AMX products, which will be used to develop the IDP at the 60%, 90%, and 100% levels.

a. AMAG Intrusion Detection, Access Control, and Video Management Solutions

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 10 of 44

b. LenelS2 Intrusion Detection, Access Control, and Video Management Solutions

c. Software House Intrusion Detection, Access Control, and Video Management Solutions

d. Honeywell Intrusion Detection, Access Control, and CCTV Solutions

e. Monitor Dynamics Intrusion Detection and Access Control Solutions

f. American Dynamics Cameras, Encoders/Decoders, Controllers, Recorders, and Video

Management Solutions

g. Axis Cameras, Encoders/Decoders, Controllers, Recorders, and Video Management Solutions

h. Bosch Cameras, Encoders/Decoders, Controllers, Recorders, and Video Management Solutions

i. Pelco Cameras, Encoders/Decoders, Controllers, Recorders, and Video Management Solutions

j. Verint Cameras, Encoders/Decoders, Controllers, Recorders, and Video Management Solutions

k. Genetec Cameras, Encoders/Decoders, Controllers, Recorders, and Video Management

Solutions

l. Proximex Physical Security Information Management Solutions

m. DMP Intrusion Detection Solutions

n. Eaton Cooper Notification Mass Notification Solutions

o. Federal Signal Mass Notification Solutions

p. Milestone Systems CCTV Recorders and Video Management Solutions q Security Information Systems Physical Security Information Management Solutions

r. AMX video systems (e.g. video decoders, wall mount touch panels, NETLINX controllers etc).

3.1.4 Information Assurance

The contractor shall provide DoD Risk Management Framework (RMF) artifacts for certification and accreditation of installed equipment for IA compliance of electronic security and emergency management deliverable products:

a. IA Management Support Tasks

b. IA RMF Execution

c. Development of the Certification and Accreditation Plan

d. Implementation of Applicable Security Technical Implementation Guides (STIGs)

e. IA tools: Enterprise Mission Assurance Support Service (eMASS), Marine Corps Certification and Accreditation Support Tool (MCCAST), Assured Compliance Assessment Solution

(ACAS), Security Content Automation Protocol (SCAP), Security Readiness Review (SRR) scripts, etc.

f. IA Collaboration

e. IA Testing and Validation

f. IA Sustainment: Vulnerability Remediation Asset Manager (VRAM), IAVMS (IA

Vulnerability Management System), etc.

3.2 DELIVERABLE PRODUCT ENVIRONMENT

DOs placed under this contract may require support in 1 or more of the complex environments listed below. This is a minimum list of unique environments and other conditions that adds to depth and complexity of product implementation. Additional environments can be introduced at the DO level.

The contractor shall provide resources with relevant knowledge and experience applicable to the following environments:

3.2.1 Information Assurance

The contractor shall support the development of artifacts (plans, schedules, diagrams, and other related artifacts), performing IA scans, configuring systems, and providing support to satisfy DoD

RMF certification and accreditation requirements. The contractor shall provide support designing, delivering, integrating, and supporting electronic security and emergency management deliverable products to meet or exceed all applicable network and interoperability certifications, security policies and accreditations as delineated in the specific DO. In some instances, the contractor shall be required to provide similar support for legacy electronic security and emergency management

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 11 of 44 deliverable products accredited under the DoD IA Certification and Accreditation Program

(DIACAP).

3.2.2 SCI Facilities

The contractor shall provide support designing, delivering, securing, integrating, and supporting systems/solutions in Sensitive Compartmented Information Facilities (SCIF) environments IAW

Intelligence Community Directive (ICD) 705, Intelligence Community (IC) Tech Spec‐for ICD/ICS

705, IC Standard Number 705-1, and IC Standard Number 705-2, CNSSAM TEMPEST/1-13 (latest edition).

3.2.3 Special Access Programs/Special Access Areas

The contractor shall provide support designing, delivering, integrating, and supporting electronic security and emergency management deliverable products in special access program spaces or special access areas. The contractor shall navigate the complex nature of planning and managing electronic security and emergency management deliverable product implementation and support in a highly complex, 24/7 operational environment to work around dynamic schedules, limited and extremely restricted hours of access due to sensitive nature of operations being conducted.

3.2.4 OCONUS-Logistics

The contractor shall provide support electronic security and emergency management deliverable products in the USEUCOM AOR. The contractor shall support the development of artifacts (plans, schedules, packages, etc.) as necessary to provide Secure and Classified systems overseas. This includes Construction Security Plans, Logistics Security Plans, Secure Shipment and Decertification, and Secure Storage Area operations.

3.2.5 OCONUS Resource Management

The contractor shall provide a technically capable workforce who meets contract personnel qualifications and any/all agreements, registrations, VISAs, foreign clearance guide (FCG), Status of

Forces Agreement (SOFA) status/Technical Expert Status Accreditation (TESA) (e.g. Germany) for work performed in the USEUCOM AOR.

The contractor must adhere to all country (e.g. Germany, Italy, Belgium, Greece, United Kingdom

(UK), Netherlands, Spain, Portugal, Kosovo, Turkey, Romania, etc.) specifications regarding deployment of personnel and work performance with regards to SOFA/TESA or technical status accreditation. The Government does not guarantee that personnel will receive TESA/SOFA or any other in-country approval technical status accreditation in any of the countries previously noted and/or listed in Section 12.1.

3.2.6 Virtualized IT Infrastructure

The contractor shall provide support executing electronic security and emergency management deliverable product design, install, configuration, and testing products in a virtualized environment.

The contractor shall implement, based on End User IT infrastructure, multiple components of systems in a virtual environment rather than stand-alone systems.

3.2.7 High Risk Applications

The contractor shall provide support executing electronic security and emergency management deliverable product design, material procurement, installation, configuration, testing, and other emergent support requirements for the protection of USAFE/Government facilities, missions, assets, and personnel that are determined to be a high risk target for terrorist or criminal activity based on their grade, mission, symbolic value, criticality, or a threat and vulnerability assessment. USAFE operates in an environment where a quick and effective response to a variety of threats or incidents must be provided.

3.2.8 Resource Escalation

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 12 of 44

The contractor shall provide scalable and surge support for designing, delivering, integrating, and supporting associated electronic security and emergency management deliverable products that include resource challenges based on variations in program/project size, schedule, and number of locations, requirement variations for single system distributed across multiple locations throughout the USEUCOM AOR. The periods for escalated support may be short in duration to respond to specific electronic security and emergency management deliverable product requirements or extended over a period of time to respond to broader threats to USAFE missions in the USEUCOM AOR.

3.3 DELIVERABLE PRODUCTS

This electronic security and emergency management deliverable products SOW considers the life cycle of any given system and its relationship with other systems, with the objective of obtaining supplies and incidental support services for deliverable products at the DO level. This system of systems approach will integrate functional and operational activities in the most technically proficient and cost-effective manner. These electronic security and emergency management deliverable products include primarily commercial systems as referenced in Para 3.1, but will also include modified commercial systems and military specification systems as required by the DO. The contractor shall ensure electronic security and emergency management deliverable products and all necessary actions for implementation to meet environmental requirements for transportation, storage and operation at USAFE wide locations under differing environmental conditions, as well as contingency and wartime missions as referenced in Para 3.2.

The contractor shall provide, as required under each DO, turn-key deliverable products to meet end-user needs. The contractor shall provide electronic security and emergency management deliverable products IAW the performance characteristics, interoperability, and interfaces as specified at the DO level. The contractor shall implement and maintain a quality control (QC) system for electronic security and emergency management deliverable products identified (but not limited to) in Para 3.1.

The work to be performed requires the contractor to have a broad technical understanding of electronic security and emergency management deliverable products to provide turn-key supply solutions.

3.3.1 Supplies

The following paragraphs describe and are representative, though not all encompassing, of the electronic security and emergency management deliverable products the contractor shall be required to produce or support in a DO awarded under this contract:

a. Intrusion Detection Deliverable Products

b. Access Control Deliverable Products

c. Video Surveillance Deliverable Products

d. Physical Security Information Management Deliverable Products

e. CBRNE Deliverable Products

f. CAD Deliverable Products

g. E9-1-1/NG 9-1-1 CPE Deliverable Products

h. Mass Notification Systems (MNS) Deliverable Products

3.3.1.1 Intrusion Detection Deliverable Products

When required at the DO level, the contractor shall survey, analyze, design, develop, procure, fabricate, integrate, deliver, install, test, and train intrusion detection deliverable products in the

USEUCOM AOR. This may include an expansion, upgrade, replacement, or the provision of a new intrusion detection/electronic security deliverable product.

3.3.1.2 Access Control Systems (ACS) Deliverable Products

fabricate, integrate, deliver, install, test, and train access control deliverable products in the

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 13 of 44

USEUCOM AOR. This may include an expansion or upgrade, replacement, or a new access control deliverable product.

3.3.1.3 Video Surveillance / CCTV Deliverable Products

fabricate, integrate and provide video surveillance/CCTV deliverable products in the USEUCOM

AOR. This may include an expansion or upgrade, replacement, or provide a new video surveillance/CCTV capability.

3.3.1.4 Physical Security Information Management (PSIM) Deliverable Products fabricate, integrate, install, test, and train PSIM deliverable products. This may include an expansion, upgrade, replacement, or a new PSIM deliverable product.

3.3.1.5 CBRNE Deliverable Products

fabricate, integrate, install, test, and train CBRNE deliverable products. This may include an expansion, upgrade of replacement of an existing CBRNE, or a new capability.

3.3.1.6 CAD Deliverable Products

fabricate, integrate, deliver, install, test, and train computer aided dispatch (CAD) deliverable products. This may include an expansion or upgrade, replacement, or development of a new CAD deliverable product.

3.3.1.7 E9-1-1/NG9-1-1 Deliverable Products

fabricate, integrate, deliver, install, test, and train E9-1-1/NG9-1-1 deliverable products. This may include an expansion or upgrade, replacement of an existing E9-11/NG9-1-1, or a new capability.

3.3.1.8 Mass Notification Deliverable Products

fabricate, integrate, deliver, install, test, and train Mass Notification deliverable products. This may include an expansion or upgrade, replacement or a new Mass Notification deliverable product.

3.3.2 Equipment and Material Support

As specified at the DO level, the contractor shall provide various equipment and material support that ranges from procurement, fabrication, integration and delivery.

The contractor shall adhere to all procurement requirements as directed on a DO basis. Requirements derived from policies (security, location, threat, etc.) could limit or increase required steps and approvals for procurement, handling, shipping and receiving.

The contractor shall be responsible for material logistical aspects (crating, agricultural inspection, insurance, customs (if applicable), inspection, secure shipment practices, shipping, etc.) of all contractor acquired property (CAP), contractor furnished equipment (CFE), and contractor furnished material (CFM) required at the DO level for electronic security and emergency management deliverable product provision for the USAFE in the USEUCOM AOR.

3.3.2.1 Equipment/Material Procurement

The contractor shall procure items specified as CAP (e.g. CFE and CFM) at the DO level. Unless otherwise noted, all items procured by the contractor shall be stored at the contractor’s facilities and integrated into a system or transported by the contractor as directed in each DO. As required, the

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 14 of 44 contractor shall be responsible for generating inventory as part of the Material Inspection and

Receiving Report/Inventory Tracking at the DO level. Deliverable documentation shall vary and be specified in each DO, if applicable.

The contractor shall procure items that conform to applicable product validation, identification, and tracking requirements. All procured equipment must be Trade Agreements Act (TAA) compliant

(when necessary).

(a) Product Certification – The contractor shall be a registered and certified integrator, partner, or value added reseller for electronic security and emergency management deliverable products at the level required by the DO or within the time stipulated by the request for proposal (RFP). The contractor shall maintain required partnerships throughout the length of the DOs (as required).

(b) Product Validation – The contractor shall certify that it purchases supplies from authorized resellers and/or distributers. Unless otherwise specified, the contractor shall warrant that the products are new, in their original box. The contractor shall obtain all manufacturer products submitted at the

DO level from authentic manufacturers or through legal distribution channels only, IAW all applicable laws and policies at the time of purchase. The contractor shall provide the Government with a copy of the end user license agreement, and shall warrant that all manufacturer software is licensed originally to Government as the original licensee authorized to use the manufacturer software. The contractor shall track the licensing information and have it available for Government review as needed.

(c) Cybersecurity/Computer Security Requirements – The contractor shall ensure that all products recommended and/or procured that impact cybersecurity or IA shall be selected from the

National Information Assurance Program (NIAP) Validated Products List. The contractor shall ensure the products chosen are based on the appropriate evaluated assurance level for the network involved, and utilized IAW latest Defense Information Systems Agency (DISA) policy at the DO

Level. The contractor shall store all product information and have it available for Government review as needed.

(d) Radio Frequency Identification (RFID) – IAW Under Secretary of Defense Memo Radio

Frequency Identification (RFID), July 30, 2004, the contractor shall mark applicable items with RFID

(as required).

A list of equipment and material anticipated (i.e. not all inclusive) for electronic security and emergency management deliverable product support as part of this SOW is provided as Attachment 1.

The contractor shall ensure that all equipment (excluding misc. materials etc.) procured to support

DOs initiated under this SOW shall be in compliance with the approved product list for electronic security and emergency management deliverable products as cited in Para 3.1 and 3.2 IAW

Attachment 2.

3.3.2.2 Property/Inventory Tracking

The contractor shall create and maintain internal records of all CAP at the DO level. The contractor shall record each item delivered and/or ordered in a Material Inspection and Receiving

Report/Inventory Tracking Report. At a minimum, the report shall track the following information:

item description, order date, serial number, model number, lot number, delivery location, and the manufacturer warranty period and expiration date, if applicable. The contractor shall have inventory report information available for Government review as needed, and the contractor shall ensure the report information has the ability to be sorted and manipulated by any of the input fields. Separate from the Government tracking system, the information in the contractor’s records is a backup to the

Government records; therefore, the Government shall own all data rights to the collected information.

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 15 of 44

3.3.2.3 Contractor Furnished On-site Storage Space

The contractor is responsible to furnish, deliver and setup their own work space and secure storage space at the installation site as required at the DO level.

Where equipment and materials are of a sensitive nature, equipment/material must be maintained and handled in an approved storage facility IAW ICD 705 (latest version/revision) documents, such as a construction security plan or logistics security plan, the contractor shall be responsible for providing a secure space, lease commercial space, and/or request and be authorized Government space that meets storage requirements at the DO level.

3.3.2.4 Warranty Tracking of Serialized Items

The contractor shall submit Electronic Warranty Tracking and Administration Information for

Serialized Items at the DO level. The contractor shall follow the requirements for any serialized item manufactured or acquired that comes with a warranty:

3.3.2.4.1 For Government specified warranty terms, the Government will complete certain fields on the Warranty Tracking Information (WTI) form (Attachment 1) and Warranty Source of Repair

Instructions (WSRI) form (Attachment 2) and electronically forwarded them to the contractor. The contractor shall complete the remaining sections of the WTI and WSRI and forward the forms to the

Contracting Officer (CO) and/or the Government Technical Point of Contact (TPOC) at time of delivery of the warranted serialized item(s).

3.3.2.4.2 For contractor/vendor specified warranty terms, the contractor shall complete all data elements for both the WTI and WSRI (Attachments 1 and 2) and shall forward the forms electronically to the TPOC. The WTI shall be returned to the CO and TPOC at the DO award. The

WSRI shall be returned to the CO and TPOC at contract/DO award or at time of delivery of the warranted serialized item(s).

3.3.2.4.3 For receipt and acceptance of items, the contractor shall comply with the following requirements:

(a) If the WTI and WSRI are submitted manually (as a PDF file), the contractor shall forward documents to the TPOC for review. As required, the contractor shall forward approved documents to

Government personnel responsible for posting the forms to electronic data access (EDA).

(b) If utilizing WAWF, the contractor shall ensure that the required warranty data is electronically submitted using the exhibit line item number (ELIN) functionality for the Material

Inspection and Receiving Report. If problems occur submitting warranty data electronically, the WTI and WSRI can be submitted manually (as a PDF file) with the TPOC concurrence. The contractor shall forward documents to TPOC for review and when approved, the Government will post forms to

Electronic Data Access (EDA).

3.3.2.4.4 For material management, the contractor shall make an inventory of all excess material and provide this inventory to the TPOC at the completion of the DO. This material shall be identified as ready for issue, repairable, or disposable.

3.3.2.5 Warranty Management

In support of warranty management for serial managed items not necessarily purchased as CAP or

CFP, the contractor shall ensure the appropriate WTI and WSRI are current and uploaded to the

WAWF Materiel Inspection and Receiving Report (or WAWF Reparable Receiving Report), as appropriate. As a backup to online warranty database, the contractor shall internally track items by contract/DO, serial numbers, and the information shall be updated monthly to identify the time left on the original warranty. The contractor shall provide the TPOC a copy of the warranty information in

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 16 of 44 an inventory tracking report, to include on all warranty and non-warranty actions taken during the preceding quarter.

3.3.2.6 Equipment / Systems Fabrication and Assembly

(a) The contractor shall fabricate electronic/electrical and mechanical assemblies, chassis, deployable equipment rooms, equipment and systems support platforms using drawings and reports specified at the DO level and provide all required material. The contractor and the TPOC shall test (if applicable) and/or perform QC inspections at the places of performance specified in the DO to ensure proper operation and reliability prior to shipment to the site for installation.

(b) The fabricated assemblies and units will be used to verify the accuracy of the installation design plan (IDP), standards and/or guidance design drawings. Lessons learned and conclusions shall be applied in future design improvements and standards.

3.3.3 Other Requirements

3.3.3.1 Program Management (PM)

The contractor shall provide PM support for the USAFE electronic security and emergency management program.

3.3.3.1.1 Program Support

Some programs shall require a contractor to work closely with the Government project manager and/or TPOC to support the needs of the program. As directed in DOs, coordination of meetings, developing agenda items, attending high-level meetings, generating minutes, and tracking action items shall be required.

3.3.3.1.2 Program Support Documentation

The contractor shall develop and draft project management (PM) Reports. At a minimum, the contractor shall provide the following typical PM Reports and documents:

(a) Economic Analyses, Comparative Cost Analyses, and Cost Estimation

(b) Meeting Agenda and Minutes

(c) Work Breakdown Structure (WBS)

(d) Staff Studies, Point Papers, Information White Papers, project/program/risk management plans, action briefs etc.

3.3.3.1.3 Plan of Objectives and Milestones (POA&M)

The contractor shall develop and update the POA&M at the DO level that addresses major milestones and overall detailed schedule for the DO. In the POA&M, the contractor shall identify performance schedule for all deliverable products including adequate response/cycle timelines (as dictated by DO) for Government responses and actions.

3.3.3.1.4 General Documentation/Technical Reports

The contractor shall provide the following reporting and deliverable requirements specified in individual DOs. The contractor shall submit these deliverables as General Documentation/Technical

Reports. The contractor shall maintain the General Documentation/Technical Reports throughout the period of performance of each DO. Examples include, but are not limited to, the following:

(a) Project Status Reports

(b) Technical Proposal

(c) Bill of Materials

(d) Engineering and Design review artifacts including:

i.Systems Engineering Plan

USAF IMSC Det 4 SOW Version 11.0 21 January 2020 17 of 44 ii.Project Management Plans, Configuration Management Plans, Risk Management Plans, Staffing Plans iii.Project Requirements Documents iv.System Requirement Documents v.Preliminary Design Review vi.Critical Design Review

(e) IA Documents

(f) Issues/Risks

(g) Investigation/Studies/Analysis

(h) Site Surveys, PSA, IDPs (Preliminary 30%, 60%, 90%, 100%, As-Builts etc.)

(i) Cutover and Transition Plan

(j) Test plans, evaluation plans, test reports, evaluation, lessons learned

(k) Pre-installation test and checkout

(l) Associated training materials/development

(m) System operation and verification test

(n) Project Support Agreement

3.3.3.1.5 Issues and Risks

Any potential issue or risk that impacts cost, quality, schedule or requirements of the DO shall be captured, quantified, and reported in the General Documentation/Technical Reports by the contractor to the Government TPOC as required at the DO level.

Where risks or issues are realized and project cost, quality, schedule, or requirements are impacted, the contractor shall provide detailed recommendations to the Government TPOC on how to correct and restore project variables to original intent/threshold.

3.3.3.2 System Engineering Support

3.3.3.2.1 Analysis, Planning and Preparation

The contractor shall analyze, and translate data into qualitative and quantitative technical requirements and architectures to allow for planning and project start-up at the DO level. This includes site surveys and analysis, identification of requirements, statement of existing systems/equipment/technologies, considerations and comparisons of candidate solutions, recommendations, scheduling and implementation schedule, WBS, logistics support, and cost. The contractor shall generate project management planning documents that will become the basis for further project management.

3.3.3.2.2 The contractor shall investigate and provide detailed analysis and/or studies as part of the General Documentation/Technical Reports to evaluate equipment or system components with regard to operational, standardization, and logistics considerations and make recommendations for improvement.

3.3.3.2.3 As part of delivery of electronic security and emergency management deliverable products cited in Para 3.1 and 3.2, and IAW individual DOs, the contractor shall integrate new equipment technologies into existing system architectures as specified at the DO level. The contractor shall apply a systems engineering approach to ensure that mission objectives and system criteria requirements are fulfilled. Emphasis shall be on the demonstration of clear and measurable improvements in the performance, logistics supportability, reliability and maintainability of the item.

3.3.3.3 Modeling & Simulation

The contractor shall apply a standardized, rigorous, structured methodology to create and validate a physical, mathematical, or otherwise logical representation of a system entity, phenomenon, or process. The contractor shall be able to use models, including emulators, simulators, and stimulators, USAF IMSC Det 4 SOW Version 11.0 21 January 2020 18 of 44 either statically or over time, to develop data as a basis for making managerial, technical, strategic, or tactical decisions.

3.3.3.4 Configuration Management

As outlined in MIL-HDBK-61A (latest edition/revision), the contractor shall apply engineering analytical disciplines to identify, document, and verify functional, performance, and physical characteristics of systems, to control changes and non-conformance, and to track actual configurations of systems and platforms. The contractor shall develop configuration management plans as directed in the DO as part of PM Reports.

3.3.3.5 Cybersecurity/IA

Cybersecurity/IA includes tasks that the contractor shall protect and defend information and information systems by ensuring their availability, integrity, authentication, confidentiality, and non-repudiation. This includes providing for restoration of information systems by incorporating protection, detection, and reaction capabilities.

The contractor shall provide technical expertise to support certification & accreditation (C&A) related activities and system security authorization agreement (SSAA) development/updates IAW DoDI

8510.01(latest edition/revision), DoD RMF for electronic security and emergency management deliverable products. The contractor shall provide support for the development and update of documentation in support of the RMF process for each phase of system life cycle. The contractor shall perform system security engineering analysis related to the integration and implementation of the required system and related interfaces. The contractor shall review the system hardware/software design and architecture documentation and prepare materials addressing security technical issues.

The contractor shall support RMF integrated product integrity analysis, development of security test plans, procedures, test reports as part of the RMF Artifacts, and provide to the Government TPOC as specified at the DO level. Additionally, the contractor shall prepare for independent Security Test &

Evaluation (ST&E) by creating and performing Internal Security Test Plans and Procedures (provided as part of the RMF Artifacts) to be executed in an integration test facility or operational site. The contractor shall provide cybersecurity subject matter expertise for the deployed instances of an accredited system as tasked, and will assist in the identification and assessment of site-specific…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .