Appendix_D_SABER_Specifications_Vol_04.pdf

PDF 3 MB Posted

Attached to
FY19-24 Davis-Monthan SABER Solicitation Federal contract opportunity
Solicitation number
FA487719RA017
Issued by
Department of the Air Force Air Combat Command

About this file

This document provides specifications for cybersecurity requirements related to facility-related control systems for a project at Davis-Monthan Air Force Base in Tucson, Arizona. The specifications cover access control, auditing, identification and authentication, and other cybersecurity measures for control systems including HVAC, electronic security, communications, and other systems. Requirements address topics such as user accounts, unsuccessful login attempts, system use notifications, wireless access, documentation, software updates, and cybersecurity during construction and warranty periods. The specifications reference applicable STIGs, SRGs, and other cybersecurity guidance and must be followed in conjunction with specifications for the relevant control systems.

SOW Appendix D

View the file

Other files for this federal contract opportunity

Other files attached to FY19-24 Davis-Monthan SABER Solicitation, newest first.
File Type Posted
Solicitation_Amendment_FA487719RA0170002_SF_30_(1).pdf PDF
SABER_Re-Compete_Consolidated_RFI_Responses.pdf PDF
2012-06_Asbestos_Survey.pdf PDF
04300-009-001.PDF PDF
04300-016-020.pdf PDF
04300-016-014.pdf PDF
2004-11_Asbestos_Survey.pdf PDF
1996-01-11_Asbestos_Survey.pdf PDF
04300-016-013.pdf PDF
1995-01_Asbestos_Survey.pdf PDF
1992-04_Asbestos_Survey.pdf PDF
Seed_Project_FBNV180044-SABER_AF_Form_66.pdf PDF
04300-016-004.pdf PDF
04300-016-009.pdf PDF
04300-009-002.PDF PDF
1987-07_Asbestos_Survey.pdf PDF
FBNV180044_SABER_Statement_of_Work_26_Aug_19.pdf PDF
GDN_AZ20190032_-_AZ32_-_Building.pdf PDF
04300-016-015.pdf PDF
1996-08_Asbestos_Survey.pdf PDF
GDN_AZ20190002_-_AZ02_-_Residential.pdf PDF
Solicitation_-_FA487719RA017.pdf PDF
04300-016-019.pdf PDF
04300-016-008.pdf PDF
2003-07_Air_Sampling.pdf PDF
Scanned_As_Built_Abatement_2004.pdf PDF
04300-016-005.pdf PDF
Base_Access_Request_-_Event_EAL.xls XLS spreadsheet
04300-016-002.pdf PDF
1996-05_Asbestos_Survey.pdf PDF
Appendix_B_SABER_Specifications_Vol_02.pdf PDF
GDN_AZ20190006_-_AZ06_-_Heavy_Dams.pdf PDF
GDN_AZ20190018_-_AZ18_-_Heavy.pdf PDF
2001-08_Asbestos_Survey.pdf PDF
04300-013-005.PDF PDF
04300-016-018.pdf PDF
04300-014-001.PDF PDF
2001-10_Asbestos_Shipment.pdf PDF
Attachment_2_Non_Pre-Priced_Item_Bid_Sheet.pdf PDF
04300-012-003.PDF PDF
04300-013-002.PDF PDF
04300-016-006.pdf PDF
2000-07_Air_Sampling.pdf PDF
Attachment_6_-_Past_Performance_Questionaire.docx DOCX document
04300-013-001.PDF PDF
Seed_Project_FBNV180044_Conceptual_Sketch_Drawing.pdf PDF
Contractor_Environmental_Guide_(15_May_2019).pdf PDF
GDN_AZ20190008_-_AZ08_-_Highway.pdf PDF
2003-04_Asbestos_Survey.pdf PDF
1998-06_Asbestos_Survey.pdf PDF
Show all 50

FY19-24 Davis-Monthan SABER Solicitation has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

APPENDIX D

SPECIFICATIONS

(Volume 04)

FOR

SIMPLIFIED ACQUISITION

OF

BASE ENGINEER REQUIREMENTS

(SABER)

AT

DAVIS-MONTHAN AIR FORCE BASE

TUCSON, ARIZONA

11 February 2019

Table of Contents-1

TECHNICAL PROVISIONS OF SPECIFICATIONS

SABER Contract (Volume 04)

Contractor to furnish all labor, equipment, appliance and materials and perform all operations in connection with all Task Orders issued under the SABER contract at Davis-Monthan AFB, Arizona, in strict accordance with these specifications.

TABLE OF CONTENTS

SECTION AND TITLE

DIVISION 25 – INTEGRATED AUTOMATION

25 05 11 Cybersecurity for Facility-Related Control Systems

25 08 10 Utility Monitoring and Control System Testing

25 10 10 Utility Monitoring and Control System (UMCS) Front End and Integration

DIVISION 26 – ELECTRICAL

26 00 00.00 20 Basic Electrical Materials and Methods

26 09 23.00 40 Lighting Control Devices

26 24 16.00 40 Panelboards

26 51 00 Interior Lighting

26 52 00.00 40 Emergency Lighting

26 53 00.00 40 Exit Signs

26 56 00 Exterior Lighting

DIVISION 27 – COMMUNICATIONS

27 05 29.00 10 Protective Distribution System (PDS) for SIPRNET Communication Systems

27 51 23.10 Intercommunication System

DIVISION 28 – ELECTRONIC SAFETY AND SECURITY

28 23 23.00 10 Closed Circuit Television Systems

28 31 64.00 10 Fire Detection and Alarm System, Addressable

DIVISION 31 – EARTHWORK

31 23 00.00 20 Excavation and Fill

Table of Contents-2

DIVISION 32 – EXTERIOR IMPROVEMENTS

32 12 16 Hot-Mix Asphalt (HMA) for Roads

32 17 23.00 20 Pavement Markings

32 31 13 Chain Link Fences and Gates

DIVISION 33 – UTILITIES

33 11 00 Water Distribution

USACE / NAVFAC / AFCEC / NASA UFGS- 25 05 11 ( November 2017) Pr epar i ng Act i v i t y: USACE

UNI FI ED FACI LI TI ES GUI DE SPECI FI CATI ONS

Ref er ences ar e i n agr eement wi t h UMRL dat ed Oct ober 2018

SECTI ON TABLE OF CONTENTS

DI VI SI ON 25 - I NTEGRATED AUTOMATI ON

SECTI ON 25 05 11

CYBERSECURI TY FOR FACI LI TY- RELATED CONTROL SYSTEMS

11/17

PART 1 GENERAL

1. 1 CONTROL SYSTEM APPLI CABI LI TY

1. 2 RELATED REQUI REMENTS

1. 3 REFERENCES

1. 4 DEFI NI TI ONS

1. 4. 1 Comput er

1. 4. 2 Net wor k Connect ed

1. 4. 3 User Account Suppor t Level s

1. 4. 3. 1 FULLY Suppor t ed

1. 4. 3. 2 MI NI MALLY Suppor t ed

1. 4. 3. 3 NOT Suppor t ed

1. 4. 4 User I nt er f ace

1. 4. 4. 1 Li mi t ed Local User I nt er f ace

1. 4. 4. 2 Ful l Local User I nt er f ace

1. 4. 4. 3 Remot e User I nt er f ace

1. 5 ADMI NI STRATI VE REQUI REMENTS

1. 5. 1 Coor di nat i on

1. 6 SUBMI TTALS

1. 7 QUALI TY CONTROL

1. 7. 1 Regul at or y Requi r ement s

1. 7. 2 [ Cer t i f i cat i ons] [ Qual i f i cat i ons]

1. 7. 3 Pr e- Const r uct i on Test i ng

1. 8 DELI VERY, STORAGE, AND HANDLI NG

1. 9 CYBERSECURI TY DOCUMENTATI ON

1. 9. 1 Cyber secur i t y I nt er connect i on Schedul e

1. 9. 2 Net wor k Communi cat i on Repor t

1. 9. 3 Cont r ol Syst em I nvent or y Repor t

1. 9. 4 Sof t war e Recover y and Reconst i t ut i on I mages

1. 9. 5 Cyber secur i t y Ri ser Di agr am

1. 9. 6 Cont r ol Syst em Cyber secur i t y Document at i on

1. 9. 6. 1 Sof t war e Appl i cat i ons

1. 9. 6. 2 For HVAC Cont r ol Syst em Devi ces

1. 9. 6. 2. 1 HVAC Cont r ol Syst em Devi ces FULLY Suppor t i ng User

Accounts

1. 9. 6. 2. 2 Al l Ot her HVAC Cont r ol Syst em Devi ces

1. 9. 6. 3 [ _____] Cont r ol Syst em Devi ces

SECTI ON 25 05 11 Page 1

1. 9. 6. 4 Def aul t Requi r ement s f or Cont r ol Syst em Devi ces

1. 10 SOFTWARE UPDATE LI CENSI NG

1. 11 CYBERSECURI TY DURI NG CONSTRUCTI ON

1. 11. 1 Cont r act or Comput er Equi pment

1. 11. 1. 1 Oper at i ng Syst em

1. 11. 1. 2 Ant i - Mal war e Sof t war e

1. 11. 1. 3 Passwor ds and Passphr ases

1. 11. 1. 4 Cont r act or Comput er Cyber secur i t y Compl i ance St at ement s

1. 11. 2 Tempor ar y I P Net wor ks

1. 11. 2. 1 Net wor k Boundar i es and Connect i ons

1. 11. 3 Gover nment Access t o Net wor k

1. 11. 4 Tempor ar y Wi r el ess I P Net wor ks

1. 11. 5 Passwor ds and Passphr ases

1. 11. 6 Cont r act or Tempor ar y Net wor k Cyber secur i t y Compl i ance

Statements

1. 12 CYBERSECURI TY DURI NG WARRANTY PERI OD

PART 2 PRODUCTS

PART 3 EXECUTI ON

3. 1 ACCESS CONTROL REQUI REMENTS

3. 1. 1 User Account s

3. 1. 1. 1 Comput er s

3. 1. 1. 2 For HVAC Cont r ol Syst em Devi ces

3. 1. 1. 3 [ _____] Cont r ol Syst em Devi ces

3. 1. 1. 4 Def aul t Requi r ement s f or Cont r ol Syst em Devi ces

3. 1. 2 Unsuccessf ul Logon At t empt s

3. 1. 2. 1 Devi ces MI NI MALLY Suppor t i ng Account s

3. 1. 2. 2 Devi ces FULLY Suppor t i ng Account s

3. 1. 2. 3 Hi gh Avai l abi l i t y I nt er f aces Exempt f r om Unsuccessf ul Logon

At t empt s Requi r ement s

3. 1. 3 Syst em Use Not i f i cat i on

3. 1. 3. 1 User I nt er f ace Banner Schedul e

3. 1. 4 Per mi t t ed Act i ons Wi t hout I dent i f i cat i on or Aut hent i cat i on

3. 1. 5 Wi r el ess Access

3. 1. 5. 1 Wi r el ess I P Communi cat i ons

3. 1. 5. 2 Non- I P Wi r el ess Communi cat i on

3. 1. 5. 3 Wi r el ess Communi cat i on Request

3. 1. 5. 4 Wi r el ess Communi cat i on Test i ng

3. 2 CYBERSECURI TY AUDI TI NG

3. 2. 1 Audi t Event s, Cont ent of Audi t Recor ds, and Audi t Gener at i on

3. 2. 1. 1 Comput er s

3. 2. 1. 1. 1 Audi t ed Event s

3. 2. 1. 1. 2 Audi t Event I nf or mat i on To Recor d

3. 2. 1. 2 For HVAC Cont r ol Syst em Devi ces

3. 2. 1. 2. 1 HVAC Cont r ol Syst em Devi ces FULLY Suppor t i ng User

Accounts

3. 2. 1. 2. 2 Ot her HVAC Cont r ol Syst em Devi ces

3. 2. 1. 3 [ _____] Cont r ol Syst em Devi ces

3. 2. 1. 4 Def aul t Requi r ement s f or Cont r ol Syst em Devi ces

3. 2. 1. 4. 1 Devi ces Whi ch FULLY Suppor t Account s

3. 2. 1. 4. 1. 1 Audi t ed Event s

3. 2. 1. 4. 1. 2 Audi t Event I nf or mat i on To Recor d

3. 2. 1. 4. 2 Devi ces Whi ch Do Not FULLY Suppor t Account s

3. 2. 2 Audi t St or age Capaci t y and Audi t Upl oad

3. 2. 2. 1 Devi ce Audi t Recor d Upl oad Sof t war e

3. 2. 3 Response t o Audi t Pr ocessi ng Fai l ur es

SECTI ON 25 05 11 Page 2

3. 2. 4 Ti me St amps

3. 2. 4. 1 Comput er s

3. 2. 4. 2 For HVAC Cont r ol Syst em Devi ces

3. 2. 4. 3 [ _____] Cont r ol Syst em Devi ces

3. 2. 4. 4 Def aul t Requi r ement s f or Cont r ol Syst em Devi ces

3. 3 REQUI REMENTS FOR LEAST FUNCTI ONALI TY

3. 3. 1 Non- I P Cont r ol Net wor ks

3. 3. 2 I P Cont r ol Net wor ks

3. 4 SAFE MODE AND FAI L SAFE OPERATI ON

3. 5 I DENTI FI CATI ON AND AUTHENTI CATI ON

3. 5. 1 User I dent i f i cat i on and Aut hent i cat i on

3. 5. 1. 1 HVAC Cont r ol Syst ems Devi ces

3. 5. 1. 2 El ect r oni c Secur i t y Syst em Devi ces

3. 5. 1. 3 [ _____] Cont r ol Syst em Devi ces

3. 5. 1. 4 Def aul t Requi r ement s f or Cont r ol Syst em Devi ces

3. 5. 2 Aut hent i cat or Management

3. 5. 2. 1 Aut hent i cat i on Type

3. 5. 2. 1. 1 For HVAC Cont r ol Syst em Devi ces

3. 5. 2. 1. 2 [ _____] Cont r ol Syst em Devi ces

3. 5. 2. 1. 3 Def aul t Requi r ement s f or Cont r ol Syst em Devi ces

3. 5. 2. 2 Passwor d- Based Aut hent i cat i on Requi r ement s

3. 5. 2. 2. 1 Passwor ds f or Comput er s

3. 5. 2. 2. 2 Passwor ds f or Non- Comput er Devi ces FULLY Suppor t i ng

Accounts

3. 5. 2. 2. 3 Passwor ds f or Web I nt er f aces

3. 5. 2. 2. 4 Passwor ds f or Devi ces Mi ni mal l y Suppor t i ng Account s

3. 5. 2. 2. 5 Passwor d Conf i gur at i on and Repor t i ng

3. 5. 2. 3 Har dwar e Token- Based Aut hent i cat i on Requi r ement s

3. 5. 3 Aut hent i cat or Feedback

3. 5. 4 Devi ce I dent i f i cat i on and Aut hent i cat i on

3. 5. 4. 1 For HVAC Cont r ol Syst em Devi ces

3. 5. 4. 2 [ _____] Cont r ol Syst em Devi ces

3. 5. 4. 3 Def aul t Requi r ement s f or Cont r ol Syst em Devi ces

3. 5. 5 Cr ypt ogr aphi c Modul e Aut hent i cat i on

3. 6 EMERGENCY POWER

3. 7 DURABI LI TY TO VULNERABI LI TY SCANNI NG

3. 7. 1 HVAC Cont r ol Syst em Devi ces Ot her Than Comput er s

3. 7. 2 [ _____] Cont r ol Syst em Devi ces Ot her Than Comput er s

3. 7. 3 Def aul t Requi r ement s f or Cont r ol Syst em Devi ces

3. 8 FI PS 201- 2 REQUI REMENT

3. 9 DEVI CES WI TH CONNECTI ON TO MULTI PLE I P NETWORKS

3. 10 SYSTEM AND COMMUNI CATI ON PROTECTI ON

3. 10. 1 Deni al of Ser vi ce Pr ot ect i on, Pr ocess I sol at i on and Boundar y

Protection

3. 10. 2 Cr ypt ogr aphi c Pr ot ect i on

3. 11 SYSTEM AND I NTEGRATI ON I NTEGRI TY

3. 11. 1 Mal i c i ous Code Pr ot ect i on

3. 11. 2 I nf or mat i on Syst em Moni t or i ng

3. 12 FI ELD QUALI TY CONTROL

3. 12. 1 Test s

- - End of Sect i on Tabl e of Cont ent s - -

SECTI ON 25 05 11 Page 3

USACE / NAVFAC / AFCEC / NASA UFGS- 25 05 11 ( November 2017) Pr epar i ng Act i v i t y: USACE

UNI FI ED FACI LI TI ES GUI DE SPECI FI CATI ONS

Ref er ences ar e i n agr eement wi t h UMRL dat ed Oct ober 2018

SECTI ON 25 05 11

CYBERSECURI TY FOR FACI LI TY- RELATED CONTROL SYSTEMS

11/17

NOTE: Thi s gui de speci f i cat i on cover s t he r equi r ement s f or cyber secur i t y f or f aci l i t y- r el at ed cont r ol syst ems.

Adher e t o UFC 1- 300- 02 Uni f i ed Faci l i t i es Gui de Speci f i cat i ons ( UFGS) For mat St andar d when edi t i ng t hi s gui de speci f i cat i on or pr epar i ng new pr oj ect speci f i cat i on sect i ons. Edi t t hi s gui de speci f i cat i on f or pr oj ect speci f i c r equi r ement s by addi ng, del et i ng, or r evi s i ng t ext . For br acket ed i t ems, choose appl i cabl e i t em( s) or i nser t appr opr i at e i nf or mat i on.

Remove i nf or mat i on and r equi r ement s not r equi r ed i n r espect i ve pr oj ect , whet her or not br acket s ar e present.

Comment s, suggest i ons and r ecommended changes f or t hi s gui de speci f i cat i on ar e wel come and shoul d be as a Cr i t er i a Change Request ( CCR) .

Not e: Faci l i t y- r el at ed cont r ol syst ems ar e a subset of cont r ol syst ems t hat ar e used t o moni t or and cont r ol equi pment and syst ems r el at ed t o DoD r eal pr oper t y f aci l i t i es ( e. g. , bui l di ng cont r ol syst ems, ut i l i t y cont r ol syst ems, el ect r oni c secur i t y syst ems, and f i r e and l i f e saf et y syst ems) . Thi s sect i on i ncl udes Cyber secur i t y r equi r ement s t o be i ncl uded on ever y DOD pr oj ect whi ch i ncl udes a f aci l i t y- r el at ed cont r ol syst em. Thi s Sect i on does not pr ovi de gener al r equi r ement s f or a cont r ol syst em, nor ar e t he r equi r ement s i n t hi s sect i on suf f i c i ent t o pr ocur e a cont r ol syst em. Thi s sect i on must be used i n conj unct i on wi t h anot her cont r ol s syst em speci f i cat i on. For exampl e, f or a HVAC cont r ol s pr oj ect , t hi s sect i on shoul d be used i n conj unct i on wi t h Sect i on 23 09 00 and r el at ed sections.

SECTI ON 25 05 11 Page 4

Requi r ement s and act i v i t i es i n t hi s sect i on must be coor di nat ed wi t h t he ot her r el evant cont r ol speci f i cat i on sect i ons.

Thi s sect i on i nc l udes r equi r ement s i n suppor t of t he DOD Ri sk Management Fr amewor k ( RMF) f or i mpl ement i ng cyber secur i t y. Ref er t o UFC 4- 010- 06, Cyber secur i t y f or Faci l i t y- Rel at ed Cont r ol Syst ems f or r equi r ement s on i ncor por at i ng cyber secur i t y i nt o cont r ol syst em desi gn and f or gener al i nf or mat i on on t he RMF pr ocess as i t appl i es t o cont r ol syst ems.

Assi st ance f or cont r ol syst em cyber secur i t y i s avai l abl e f r om t he f ol l owi ng Ser v i ce or gani zat i ons:

Ar my: Cont r ol Syst em Cyber secur i t y Cent er of Expertise, Hunt svi l l e Engi neer i ng and Suppor t Cent er

Navy: Naval Faci l i t i es Engi neer i ng Command, Command I nf or mat i on Of f i ce ( CI O)

Ai r For ce: Ci v i l Engi neer Mai nt enance, I nspect i on, and Repai r Team ( CEMI RT) I CS Br anch, Tyndal l AFB

Mar i ne Cor ps: Cont act Navy POC f or Mar i ne Cor ps POC i nf or mat i on

Si nce t hi s Sect i on cover s a wi de r ange of cont r ol syst ems, and t hose syst ems of t en have di f f er ent capabi l i t i es and r equi r ement s, t her e ar e r equi r ement s i dent i f i ed i n t hi s Sect i on whi ch need ext ensi ve desi gner i nput or deci s i ons.

Many desi gner sel ect i ons i n t hi s Sect i on wi l l r equi r e coor di nat i on wi t h t he pr oj ect s i t e, Syst em Owner , Aut hor i z i ng Of f i c i al or a subj ect mat t er exper t i n t he speci f i c cont r ol syst ems bei ng i nst al l ed.

NOTE: Thi s Sect i on i s f or use on cont r ol syst ems wi t h no i mpact r at i ng hi gher t han LOW. I f t he pr oj ect i ncl udes syst ems wher e t her e syst ems wi t h i mpact r at i ngs of MODERATE or HI GH, t hi s speci f i cat i on must be modi f i ed t o i ncl ude t hose addi t i onal r equi r ement s.

Syst ems of di f f er ent t ypes at t he same i mpact l evel may have di f f er ent r equi r ement s based on t he speci f i c needs and capabi l i t i es of t he cont r ol syst em. Thi s i s addr essed i n t hi s Gui de Speci f i cat i on by i ndi cat i ng when r equi r ement s appl y t o a speci f i c syst em t ype.

Syst ems of t he same t ype may have di f f er ent r equi r ement s. Thi s may be due t o t hose syst ems havi ng di f f er ent i mpact l evel s or due t o syst em- speci f i c r equi r ement s f or syst ems at t he same

SECTI ON 25 05 11 Page 5 i mpact l evel .

I f a pr oj ect i nc l udes mul t i pl e syst ems, i t ' s cr i t i cal t hat i t be c l ear whi ch r equi r ement s appl y t o whi ch syst ems. Thi s can be done by a) usi ng a s i ngl e Sect i on and speci f y i ng t he appl i cabi l i t y of r equi r ement s or b) usi ng mul t i pl e Sect i ons. Whi ch appr oach t o empl oy depends on t he needs of t he pr oj ect and t he pr ef er ences of t he speci f i er and pr oj ect manager . I f usi ng mul t i pl e sect i ons use t he f our t h l evel speci f i cat i on number i ng t o di f f er ent i at e t he Sect i ons and i ndi cat e i n each whi ch syst ems t he Sect i on appl i es t o.

NOTE: Thi s speci f i cat i on makes use of SpecsI nt act Tai l or i ng Opt i ons.

Ser vi ces t ai l or i ng opt i ons:

Ar my Ai r For ce

Cont r ol syst em t ype t ai l or i ng opt i ons:

HVAC Cont r ol Syst ems El ect r oni c Secur i t y Syst ems ( ESS)

PART 1 GENERAL

NOTE: Thi s subpar t poi nt s t he cont r act or t o t he l ocat i ons of STI Gs and SRGs, as t hi s Sect i on r equi r es t he cont r act or t o meet avai l abl e STI Gs or SRGs. I t ' s not necessar y f or t he desi gner / speci f i er t o r evi ew t he STI Gs or SRGs f or appl i cabi l i t y . The cont r act or i s r esponsi bl e f or det er mi ni ng whi ch STI Gs or SRGs ar e appl i cabl e and f or meet i ng t he r el evant r equi r ement s.

Many subpar t s i n t hi s Sect i on cont ai n t ext i n cur l y br aces ( " { " and " } " ) i ndi cat i ng whi ch cyber secur i t y cont r ol and cont r ol cor r el at i on i dent i f i er ( CCI ) t he r equi r ement s of t he subpar t r el at e t o. The t ext i nsi de t hese cur l y br aces i s f or Gover nment r ef er ence onl y, and enabl es coor di nat i on of t he r equi r ement s of t hi s Sect i on wi t h t he RMF pr ocess t hr oughout t he desi gn and const r uct i on pr ocess. Text i n cur l y br aces ar e not cont r act or requirements.

Thi s Sect i on r ef er s t o Secur i t y Requi r ement s Gui de ( SRGs) and Secur i t y Techni cal I mpl ement at i on Gui de ( STI Gs) . STI Gs and SRGs ar e ar e avai l abl e onl i ne at t he I nf or mat i on Assur ance Suppor t Envi r onment ( I ASE) websi t e at http://iase.disa.mil/stigs/Pages/index.aspx . Not al l cont r ol syst em component s have appl i cabl e STI Gs or SRGs.

SECTI ON 25 05 11 Page 6

[ 1. 1 CONTROL SYSTEM APPLI CABI LI TY

NOTE: I f mul t i pl e ver si ons of t hi s Sect i on ar e used on a s i ngl e pr oj ect , keep t hi s subpar t and l i s t al l t he syst ems t o whi ch t hi s speci f i c ver si on of t he Sect i on appl i es.

Ther e ar e mul t i pl e ver si ons of t hi s Sect i on associ at ed wi t h t hi s pr oj ect .

Di f f er ent ver si ons have r equi r ement s appl i cabl e t o di f f er ent cont r ol syst ems. Thi s speci f i c Sect i on appl i es onl y t o t he f ol l owi ng cont r ol syst ems: [ _____] .

] 1. 2 RELATED REQUI REMENTS

Al l Sect i ons cont ai ni ng f aci l i t y- r el at ed cont r ol syst ems or cont r ol syst em component s ar e r el at ed t o t he r equi r ement s of t hi s Sect i on. Revi ew al l speci f i cat i on sect i ons t o det er mi ne r el at ed r equi r ement s.

1. 3 REFERENCES

NOTE: Thi s par agr aph i s used t o l i s t t he publ i cat i ons c i t ed i n t he t ext of t he gui de speci f i cat i on. The publ i cat i ons ar e r ef er r ed t o i n t he t ext by basi c desi gnat i on onl y and l i s t ed i n t hi s par agr aph by or gani zat i on, desi gnat i on, dat e, and t i t l e.

Use t he Ref er ence Wi zar d' s Check Ref er ence f eat ur e when you add a RI D out s i de of t he Sect i on' s Ref er ence Ar t i c l e t o aut omat i cal l y pl ace t he r ef er ence i n t he Ref er ence Ar t i c l e. Al so use t he Ref er ence Wi zar d' s Check Ref er ence f eat ur e t o updat e t he i ssue dat es.

Ref er ences not used i n t he t ext wi l l aut omat i cal l y be del et ed f r om t hi s sect i on of t he pr oj ect speci f i cat i on when you choose t o r econci l e r ef er ences i n t he publ i sh pr i nt pr ocess.

The publ i cat i ons l i s t ed bel ow f or m a par t of t hi s speci f i cat i on t o t he ext ent r ef er enced. The publ i cat i ons ar e r ef er r ed t o wi t hi n t he t ext by t he basi c desi gnat i on onl y.

AMERI CAN SOCI ETY OF HEATI NG, REFRI GERATI NG AND AI R- CONDI TI ONI NG

ENGI NEERS ( ASHRAE)

ASHRAE 135 ( 2016) BACnet —A Dat a Communi cat i on Pr ot ocol f or Bui l di ng Aut omat i on and Cont r ol Net wor ks

I NSTI TUTE OF ELECTRI CAL AND ELECTRONI CS ENGI NEERS ( I EEE)

I EEE 802. 1x ( 2010) Local and Met r opol i t an Ar ea

SECTI ON 25 05 11 Page 7

Net wor ks - Por t Based Net wor k Access Control

NATI ONAL I NSTI TUTE OF STANDARDS AND TECHNOLOGY ( NI ST)

NI ST FI PS 201- 2 ( 2013) Per sonal I dent i t y Ver i f i cat i on ( PI V) of Feder al Empl oyees and Cont r act or s

U. S. DEPARTMENT OF DEFENSE ( DOD)

DODI 8551. 01 ( 2014) Por t s, Pr ot ocol s, and Ser vi ces Management ( PPSM)

DTM 08- 060 ( 2008) Pol i cy on Use of Depar t ment of Def ense ( DoD) I nf or mat i on Syst ems - St andar d Consent Banner and User Agr eement

1. 4 DEFINITIONS

1. 4. 1 Computer

As used i n t hi s Sect i on, a comput er i s one of t he f ol l owi ng:

a. a devi ce r unni ng a non- embedded deskt op or ser ver ver si on of Mi cr osof t Windows

b. a devi ce r unni ng a non- embedded ver si on of MacOS

c. a devi ce r unni ng a non- embedded ver si on of Li nux

d. a devi ce r unni ng a ver si on or der i vat i ve of t he Andr oi d OS, wher e Andr oi d i s consi der ed separ at e f r om Li nux

e. a devi ce r unni ng a ver si on of Appl e i OS

1. 4. 2 Net wor k Connect ed

A component i s net wor k connect ed ( or " connect ed t o a net wor k" ) onl y when t he devi ce has a net wor k t r anscei ver whi ch i s di r ect l y connect ed t o t he net wor k and i mpl ement s t he net wor k pr ot ocol . A devi ce l acki ng a net wor k t r anscei ver ( and accompanyi ng pr ot ocol i mpl ement at i on) can never be consi der ed net wor k connect ed. Not e t hat a devi ce connect ed t o a non- I P net wor k i s st i l l consi der ed net wor k connect ed ( an I P connect i on or I P addr ess i s not r equi r ed f or a devi ce t o be net wor k connect ed) .

Any devi ce t hat suppor t s wi r el ess communi cat i on i s net wor k connect ed, r egar dl ess of whet her t he devi ce i s communi cat i ng usi ng wi r el ess.

1. 4. 3 User Account Suppor t Level s

The suppor t f or user account s i s cat egor i zed i n t hi s Sect i on as one of t hr ee l evel s:

1. 4. 3. 1 FULLY Suppor t ed

Devi ce suppor t s conf i gur abl e i ndi v i dual account s. Account s can be cr eat ed, del et ed, modi f i ed, et c. Pr i v i l eges can be assi gned t o account s.

SECTI ON 25 05 11 Page 8

1. 4. 3. 2 MI NI MALLY Suppor t ed

Devi ce suppor t s a smal l , f i xed number of account s ( per haps onl y one) .

Account s cannot be modi f i ed. A devi ce wi t h onl y a " User " and an " Admi ni st r at or " account woul d f i t t hi s cat egor y. Si mi l ar l y, a devi ce wi t h t wo PI Ns f or l ogon - one f or r est r i c t ed and one f or unr est r i c t ed r i ght s woul d f i t her e ( i n ot her wor ds, t he account s do not have t o be t he t r adi t i onal " user name and passwor d" st r uct ur e) .

1. 4. 3. 3 NOT Suppor t ed

Devi ce does not suppor t any Access Enf or cement t her ef or e t he whol e concept of " account " i s meani ngl ess.

1. 4. 4 User I nt er f ace

Gener al l y, a user i nt er f ace i s har dwar e on a devi ce al l owi ng user i nt er act i on wi t h t hat devi ce v i a i nput ( but t ons, swi t ches, s l i der s, keyboar d, t ouch scr een, et c. ) and a scr een. Ther e ar e t hr ee t ypes of user i nt er f aces def i ned i n t hi s Sect i on: Li mi t ed Local User I nt er f ace, Ful l Local User I nt er f ace and Remot e User I nt er f ace. I n t hi s Sect i on, when t he t er m " User I nt er f ace" i s used wi t hout speci f y i ng whi ch t ype, i t r ef er s onl y t o Ful l Local User I nt er f ace and Remot e User I nt er f ace ( NOT t o Li mi t ed Local User I nt er f ace) .

1. 4. 4. 1 Li mi t ed Local User I nt er f ace

A Li mi t ed Local User I nt er f ace i s a user i nt er f ace wher e t he i nt er act i on i s l i mi t ed, f i xed at t he f act or y, and cannot be modi f i ed i n t he f i el d. The user must be physi cal l y at t he devi ce t o i nt er act wi t h i t .

Exampl es of Li mi t ed Local User I nt er f ace i ncl ude t her most at s ( Space Sensor Modul es as def i ned i n Sect i on 23 09 13 I NSTRUMENTATI ON AND CONTROL DEVI CES

FOR HVAC) .

1. 4. 4. 2 Ful l Local User I nt er f ace

A Ful l Local User I nt er f ace i s a user i nt er f ace wher e t he i nt er act i on and di spl ays ar e f i el d- conf i gur abl e.

Exampl es of a Ful l Local User I nt er f ace i ncl ude l ocal appl i cat i ons on a computer and user i nt er f aces t o Var i abl e Speed Dr i ves.

1. 4. 4. 3 Remot e User I nt er f ace

A Remot e User I nt er f ace i s a user i nt er f ace on a Cl i ent devi ce al l owi ng user i nt er act i on wi t h a di f f er ent Ser ver devi ce. The user need not be physi cal l y at t he Ser ver devi ce t o i nt er act wi t h i t .

Exampl es of Remot e User I nt er f aces i ncl ude web br owser s and Local Di spl ay Panel s as def i ned i n Sect i on 23 09 00 I NSTRUMENTATI ON AND CONTROL FOR HVAC.

1. 5 ADMI NI STRATI VE REQUI REMENTS

1. 5. 1 Coordination

NOTE: Thi s subpar t deal s wi t h coor di nat i on r equi r ement s f or t he cont r act or , and does not

SECTI ON 25 05 11 Page 9 i ndi cat e coor di nat i on t hat must be done by t he desi gner / speci f i er . I n addi t i on t o t he nor mal pr oj ect coor di nat i on, aut hor i zat i on f or wi r el ess use, al t er nat e account l ock per mi ssi ons and devi ces wi t h mul t i pl e I P connect i ons may be i mpact ed by s i t e ( or Ser vi ce) pol i c i es and need t o be coor di nat ed wi t h t he appr opr i at e Gover nment r epr esent at i ves bef or e aut hor i zat i on i s pr ovi ded.

Coor di nat e t he execut i on of t hi s Sect i on wi t h t he execut i on of al l ot her Sect i ons r el at ed t o cont r ol syst ems as i ndi cat ed i n t he par agr aph RELATED REQUI REMENTS. I t ems t hat must be consi der ed when coor di nat i ng pr oj ect ef f or t s i ncl ude but ar e not l i mi t ed t o:

a. I f r equest i ng per mi ssi on f or wi r el ess communi cat i on, t he Wi r el ess Communi cat i on Request submi t t al must be appr oved pr i or t o cont r ol syst em devi ce sel ect i on and i nt egr at i on.

b. I f r equest i ng per mi ssi on f or al t er nat e account l ock per mi ssi ons, t he Devi ce Account Lock Except i on Request must be appr oved pr i or t o cont r ol syst em devi ce sel ect i on and i nt egr at i on.

c. I f r equest i ng per mi ssi on f or t he use of a devi ce wi t h mul t i pl e I P connect i ons, t he Mul t i pl e I P Connect i on Devi ce Request must be appr oved pr i or t o cont r ol syst em devi ce sel ect i on and i nt egr at i on.

d. Wi r el ess t est i ng may be r equi r ed as par t of t he cont r ol syst em t est i ng. See r equi r ement s f or t he Wi r el ess Communi cat i on Test Repor t submittal.

e. I f t he Devi ce Audi t Recor d Upl oad Sof t war e i s t o be i nst al l ed on a comput er not bei ng pr ovi ded as par t of t he cont r ol syst em, coor di nat i on i s r equi r ed t o i dent i f y t he comput er on whi ch t o i nst al l t he sof t war e.

f . Cyber secur i t y I nt er connect i on Schedul e must be coor di nat ed wi t h ot her wor k t hat wi l l be i nt er connect ed t o, and i nt er connect i ons must be appr oved by t he Gover nment bef or e r el y i ng on t hem f or syst em functionality.

g. Cyber secur i t y t est i ng suppor t must be coor di nat ed acr oss cont r ol syst ems and wi t h t he Gover nment cyber secur i t y t est i ng schedul e.

h. Passwor ds must be coor di nat ed wi t h t he i ndi cat ed cont act f or t he pr oj ect s i t e.

i . I f appl i cabl e, HTTP web ser ver cer t i f i cat es must be obt ai ned f r om t he i ndi cat ed cont act f or t he pr oj ect s i t e.

j . Cont r act or Comput er Cyber secur i t y Compl i ance St at ement s f or each cont r act or usi ng cont r act or owned comput er s.

1. 6 SUBMITTALS

NOTE: Revi ew Submi t t al Descr i pt i on ( SD) def i ni t i ons i n Sect i on 01 33 00 SUBMI TTAL PROCEDURES and edi t t he f ol l owi ng l i s t t o r ef l ect onl y t he submi t t al s r equi r ed f or t he pr oj ect .

SECTI ON 25 05 11 Page 10

The Gui de Speci f i cat i on t echni cal edi t or s have desi gnat ed t hose i t ems t hat r equi r e Gover nment appr oval , due t o t hei r compl exi t y or cr i t i cal i t y , wi t h a " G. " Gener al l y, ot her submi t t al i t ems can be r evi ewed by t he Cont r act or ' s Qual i t y Cont r ol Syst em. Onl y add a " G" t o an i t em, i f t he submi t t al i s suf f i c i ent l y i mpor t ant or compl ex i n cont ext of t he pr oj ect .

For submi t t al s r equi r i ng Gover nment appr oval on Ar my pr oj ect s, a code of up t o t hr ee char act er s wi t hi n t he submi t t al t ags may be used f ol l owi ng t he " G" desi gnat i on t o i ndi cat e t he appr ovi ng aut hor i t y.

Codes f or Ar my pr oj ect s usi ng t he Resi dent Management Syst em ( RMS) ar e: " AE" f or Ar chi t ect - Engi neer ; " DO" f or Di st r i c t Of f i ce ( Engi neer i ng Di v i s i on or ot her or gani zat i on i n t he Di st r i c t Of f i ce) ; " AO" f or Ar ea Of f i ce; " RO" f or Resi dent Of f i ce; and " PO" f or Pr oj ect Of f i ce. Codes f ol l owi ng t he " G" t ypi cal l y ar e not used f or Navy, Ai r For ce, and NASA pr oj ect s.

An " S" f ol l owi ng a submi t t al i t em i ndi cat es t hat t he submi t t al i s r equi r ed f or t he Sust ai nabi l i t y eNot ebook t o f ul f i l l f eder al l y mandat ed sust ai nabl e r equi r ement s i n accor dance wi t h Sect i on 01 33 29 SUSTAI NABI LI TY REPORTI NG. Locat e t he " S" submi t t al under t he SD number t hat best descr i bes t he submi t t al i t em.

Choose t he f i r st br acket ed i t em f or Navy, Ai r For ce and NASA pr oj ect s, or choose t he second br acket ed i t em f or Ar my pr oj ect s.

NOTE: Al l submi t t al s i n t hi s Gui de Speci f i cat i on r equi r e Gover nment appr oval and must have a " G" designation.

Gover nment r evi ew of submi t t al s i n t hi s Sect i on i mpact Cyber secur i t y, and must be coor di nat ed wi t h t he appr opr i at e Cyber secur i t y exper t s t o ensur e appr opr i at e r evi ew and t he i dent i f i cat i on of i ssues or concer ns t hat may af f ect t he cyber secur i t y post ur e of t he syst em or t he abi l i t y of t he syst em t o r ecei ve an RMF aut hor i zat i on.

Gover nment appr oval i s r equi r ed f or submi t t al s wi t h a " G" desi gnat i on;

submi t t al s not havi ng a " G" desi gnat i on ar e [ f or Cont r act or Qual i t y Cont r ol appr oval . ] [ f or i nf or mat i on onl y. When used, a desi gnat i on f ol l owi ng t he " G" desi gnat i on i dent i f i es t he of f i ce t hat wi l l r evi ew t he submi t t al f or t he Gover nment . ] Submi t t al s wi t h an " S" ar e f or i ncl usi on i n t he Sust ai nabi l i t y eNot ebook, i n conf or mance wi t h Sect i on 01 33 29 SUSTAI NABI LI TY REPORTI NG. Submi t t he f ol l owi ng i n accor dance wi t h Sect i on

01 33 00 SUBMI TTAL PROCEDURES:

SECTI ON 25 05 11 Page 11

SD- 01 Pr econst r uct i on Submi t t al s

Wi r el ess Communi cat i on Request ; G[ , [ _____] ]

Devi ce Account Lock Except i on Request ; G[ , [ _____] ]

Mul t i pl e I P Connect i on Devi ce Request ; G[ , [ _____] ]

Cont r act or Comput er Cyber secur i t y Compl i ance St at ement s; G[, Cont r act or Tempor ar y Net wor k Cyber secur i t y Compl i ance St at ement s; G

SD- 02 Shop Dr awi ngs

User I nt er f ace Banner Schedul e; G[ , [ _____] ]

Net wor k Communi cat i on Repor t ; G[ , [ _____] ]

Cyber secur i t y Ri ser Di agr am; G[ , [ _____] ]

Cont r ol Syst em I nvent or y Repor t ; G[ , [ _____] ]

Cyber secur i t y I nt er connect i on Schedul e; G[ , [ _____] ]

SD- 03 Pr oduct Dat a

Cont r ol Syst em Cyber secur i t y Document at i on; G[ , [ _____] ]

SD- 06 Test Repor t s

Wi r el ess Communi cat i on Test Repor t ; G[ , [ _____] ]

SD- 07 Cer t i f i cat es

Sof t war e Li censes; G[ , [ _____] ]

SD- 11 Cl oseout Submi t t al s

Passwor d Summar y Repor t ; G[ , [ _____] ]

Sof t war e Recover y And Reconst i t ut i on I mages; G[ , [ _____] ]

Devi ce Audi t Recor d Upl oad Sof t war e; G[ , [ _____] ]

1. 7 QUALI TY CONTROL

[ 1. 7. 1 Regul at or y Requi r ement s

NOTE: I f t her e ar e r egul at or y r equi r ement s r el at ed t o a cont r ol syst em, speci f y t hose i n t he cont r ol syst em speci f i cat i on. I f t her e ar e r egul at or y r equi r ement s r el at ed t o cyber secur i t y f or a cont r ol syst em t hey can be speci f i ed her e.

Regul at or y r equi r ement s speci f i ed her e must i ndi cat e whi ch syst em or syst ems t hey appl y t o, DO NOT

SECTI ON 25 05 11 Page 12 i nc l ude r equi r ement s her e t hat ar e not di r ect l y l i nked t o a speci f i c cont r ol syst em.

For t ypi cal UMCS or bui l di ng cont r ol syst em pr oj ect s t her e wi l l not be r equi r ement s t o i ncl ude her e.

For t he [ _____] cont r ol syst em: [ _____] .

][ 1. 7. 2 [Certifications][Qualifications]

NOTE: I f t her e ar e cont r act or qual i f i cat i on or cer t i f i cat i on r equi r ement s r el at ed t o t he cont r ol syst em, speci f y t hose i n t he cont r ol syst em speci f i cat i on. I f t her e ar e cont r act or qual i f i cat i ons or cer t i f i cat i ons speci f i cal l y r el at ed t o cyber secur i t y t hey can be speci f i ed her e.

Use car e when i ncl udi ng r equi r ement s her e, as many cyber secur i t y cer t i f i cat i ons ar e I T- cent r i c and do not appl y t o cont r ol syst ems.

Requi r ement s speci f i ed her e must i ndi cat e whi ch syst em or syst ems t hey appl y t o, DO NOT i ncl ude r equi r ement s her e t hat ar e not di r ect l y l i nked t o a speci f i c cont r ol syst em.

For t ypi cal UMCS or bui l di ng cont r ol syst em pr oj ect s t her e wi l l not be r equi r ement s t o i ncl ude her e.

For t he [ _____] cont r ol syst em: [ _____] .

][ 1. 7. 3 Pr e- Const r uct i on Test i ng

NOTE: I f t her e ar e cyber secur i t y Pr e- Const r uct i on Test i ng r equi r ement s, i ncl ude t hem her e.

For a LOW- LOW- LOW I mpact syst em pr e- const r uct i on t est i ng wi l l gener al l y not be r equi r ed. For syst ems wi t h a MODERATE or HI GH i mpact t her e may be some pr e- const r uct i on t est i ng r equi r ement s based on t he speci f i c needs of t he pr oj ect s i t e.

Requi r ement s speci f i ed her e must i ndi cat e whi ch syst em or syst ems t hey appl y t o, DO NOT i ncl ude r equi r ement s her e t hat ar e not di r ect l y l i nked t o a speci f i c cont r ol syst em.

For t he [ _____] cont r ol syst em: [ _____] .

SECTI ON 25 05 11 Page 13

] [ 1. 8 DELI VERY, STORAGE, AND HANDLI NG

NOTE: I f t her e ar e del i ver y, st or age or handl i ng r equi r ement s, i ncl ude t hem her e.

For a LOW- LOW- LOW I mpact syst em del i ver y, st or age and handl i ng r equi r ement s wi l l gener al l y not be needed. For syst ems wi t h a MODERATE or HI GH i mpact t her e may be some r equi r ement s based on t he speci f i c needs of t he pr oj ect s i t e.

] 1. 9 CYBERSECURI TY DOCUMENTATI ON

[ 1. 9. 1 Cyber secur i t y I nt er connect i on Schedul e

NOTE: The Cyber secur i t y I nt er connect i on Schedul e i s used i n t wo si t uat i ons:

1) The cont r ol syst em communi cat es wi t h a separ at el y aut hor i zed syst em or an unaut hor i zed syst em. I n t hi s case, i ncl ude a Cyber secur i t y I nt er connect i on Schedul e i n t he desi gn showi ng t he f ol l owi ng i nt er connect i on det ai l s : Name/ descr i pt i on of ot her syst em, POC f or t he ot her syst em, t ype of data/information.

2) The cont r ol syst em i s a sub- par t of a l ar ger syst em and wi l l communi cat e wi t h and i nt egr at e t o t he l ar ger syst em ( and wi l l be par t of t he same aut hor i zat i on as t he l ar ger syst em) . I n t hi s case, t he cont r ol syst em desi gn must i ncl ude r equi r ement s f or t he expect ed communi cat i on bet ween t he sub- syst em and t he l ar ger syst em. The Cyber secur i t y I nt er connect i on Schedul e wi l l not be a desi gn dr awi ng, but wi l l s t i l l be a cont r act or submi t t al .

I f nei t her of t hese s i t uat i ons appl y ( i f t he syst em i s st and- al one wi t h no connect i on or i nt egr at i on t o anot her syst em) , r emove t he br acket ed t ext r equi r i ng t he Cyber secur i t y I nt er connect i on Schedul e, and r emove t he Cyber secur i t y I nt er connect i on Schedul e f r om t he SUBMI TTALS par agr aph of t hi s Sect i on.

I f Case 1 appl i es, keep t he br acket ed t ext r ef er r i ng t o For ei gn Dest i nat i on and POC f or Dest i nat i on, ot her wi se r emove t hi s t ext .

I n s i t uat i ons wher e bot h cases appl y, a s i ngl e submi t t al wi l l ser ve bot h pur poses.

Not e t hat t hi s submi t t al does not cr eat e a r equi r ement f or i nt er connect i ons, but document s i nt er connect i on det ai l s i n accor dance wi t h ot her

SECTI ON 25 05 11 Page 14 requirements.

{ For Ref er ence Onl y: Thi s subpar t ( and i t s subpar t s) r el at es t o CA- 3( b) , CCI-00258}

Pr ovi de a compl et ed Cyber secur i t y I nt er connect i on Schedul e document i ng connect i ons bet ween t he i nst al l ed syst em and ot her syst ems. Pr ovi de t he f ol l owi ng i nf or mat i on f or each devi ce communi cat i ng bet ween syst ems: Devi ce I dent i f i er , Devi ce Descr i pt i on, Tr anspor t l ayer Pr ot ocol , Net wor k Addr ess, Por t ( i f appl i cabl e) , MAC ( Layer 2) addr ess ( i f appl i cabl e) , Medi a, Appl i cat i on Pr ot ocol , Ser vi ce ( i f appl i cabl e) , Descr i pt i ve Pur pose of communi cat i on. [ For communi cat i on wi t h ot her aut hor i zed syst ems al so pr ovi de t he For ei gn Dest i nat i on and POC f or Dest i nat i on. ] I f ot her cont r ol syst em Sect i ons used on t hi s pr oj ect i ncl ude submi t t al s document i ng t hi s i nf or mat i on, pr ovi de copi es of t hose submi t t al s t o meet t hi s r equi r ement .

I n addi t i on t o t he r equi r ement s of Sect i on 01 33 00 SUBMI TTAL PROCEDURES, pr ovi de t he Cyber secur i t y I nt er connect i on Schedul e as an edi t abl e Mi cr osof t Excel f i l e ( a t empl at e Cyber secur i t y I nt er connect i on Schedul e i n Excel f or mat i s avai l abl e at http://www.wbdg.org/FFC/NAVGRAPH/graphtoc.pdf .)

] 1. 9. 2 Net wor k Communi cat i on Repor t

NOTE: Cont r ol syst em speci f i cat i ons shoul d i ncl ude r equi r ement s r el at ed t o pr ot ocol and document at i on.

I n t he desi gn cyber secur i t y document at i on r equi r ed by t he UFC, document what , i f any, pr ot ocol r equi r ement s ar e i ncl uded i n t he cont r ol syst em speci f i cat i on ( CCI - 002103) . Al so document any r equi r ement s or submi t t al s r el at ed t o net wor k communi cat i on, such as Poi nt s Schedul es

(CCI-002105).

{ For Ref er ence Onl y: Thi s subpar t ( and i t s subpar t s) r el at es t o CA- 9;

CCI - 002102, CCI - 002103, CCI - 002104, CCI - 002105 and al so t he submi t t al r equi r ement s associ at ed wi t h CM- 6, CM- 7 and SC- 41}

Pr ovi de a net wor k communi cat i on r epor t . For each net wor ked cont r ol l er , document t he communi cat i on char act er i st i cs of t he cont r ol l er i ncl udi ng communi cat i on pr ot ocol s, ser vi ces used, and a gener al descr i pt i on of what i nf or mat i on i s communi cat ed over t he net wor k. For each cont r ol l er usi ng I P, document al l TCP and UDP por t s used. I f ot her cont r ol syst em Sect i ons used on t hi s pr oj ect i ncl ude submi t t al s document i ng t hi s i nf or mat i on, pr ovi de copi es of t hose submi t t al s t o meet t hi s r equi r ement .

I n addi t i on t o t he r equi r ement s of Sect i on 01 33 00 SUBMI TTAL PROCEDURES, pr ovi de t he Net wor k Communi cat i on Repor t as an edi t abl e Mi cr osof t Excel file.

1. 9. 3 Cont r ol Syst em I nvent or y Repor t

NOTE: Sel ect whet her t he i nvent or y r epor t must i ncl ude non- net wor ked devi ces.

SECTI ON 25 05 11 Page 15

Unl ess speci f i cal l y r equi r ed by t he pr oj ect , keep t he f i r st br acket ed t ext t o r equi r e i nvent or y of onl y net wor ked devi ces and r emove t he l at er br acket ed t ext r equi r i ng i nvent or y of non- net wor ked devi ces, i nput devi ces and out put devi ces.

{ For Ref er ence Onl y: Thi s subpar t ( and i t s subpar t s) r el at es t o CM- 8( a) , CP- 12, SI - 17, I A- 3; CCI - 000389, CCI - 000392, CCI - 000398, CCI - 002855, CCI - 002856, CCI - 002857, CCI - 002773, CCI - 002774, CCI - 002775, CCI - 000777, CCI - 000778, CCI - 001958}

Pr ovi de a Cont r ol Syst em I nvent or y r epor t usi ng t he I nvent or y Spr eadsheet l i s t ed under t hi s Sect i on at ht t p: / / www. wbdg. or g/ FFC/ NAVGRAPH/ gr apht oc. pdf document i ng al l [ net wor ked devi ces, i ncl udi ng net wor k i nf r ast r uct ur e devi ces] [ devi ces, i ncl udi ng net wor ked devi ces, net wor k i nf r ast r uct ur e devi ces, non- net wor ked devi ces, i nput devi ces ( e. g. sensor s) and out put devi ces ( e. g. act uat or s) ] . For each devi ce pr ovi de al l appl i cabl e i nf or mat i on f or whi ch t her e i s a f i el d on t he spr eadsheet i n accor dance wi t h t he i nst r uct i ons on t he spr eadsheet .

I n addi t i on t o t he r equi r ement s of Sect i on 01 33 00 SUBMI TTAL PROCEDURES, pr ovi de t he Cont r ol Syst em I nvent or y Repor t as an edi t abl e Mi cr osof t Excel file.

1. 9. 4 Sof t war e Recover y and Reconst i t ut i on I mages

NOTE: Thi s r equi r ement cover s di sk i mages t o al l ow r ecover y and r econst i t ut i on of appl i cat i ons on comput er s. As descr i bed i n UFC 4- 010- 06 Cyber secur i t y f or Faci l i t y- Rel at ed Cont r ol Syst ems, as- bui l t document at i on ( i ncl udi ng copi es of cust om pr ogr ammi ng and devi ce set t i ngs) must be r equi r ed i n t he Sect i on speci f y i ng t he cont r ol syst em i t sel f .

Thi s r equi r ement cover s comput er s onl y. I f r ecover y i mages of ot her cont r ol syst em devi ces ( cont r ol l er s) ar e needed, t hat shoul d be speci f i ed i n t he r el evant cont r ol syst em Sect i on or added her e. Use caut i on when addi ng a r equi r ement f or cont r ol l er s her e as not al l syst ems have t he same capabi l i t i es and a gener al r equi r ement her e coul d r esul t i n a conf l i c t i ng or i mpr act i cal r equi r ement .

I f t he cont r act or i s i nst al l i ng sof t war e on a Gover nment Fur ni shed comput er t o whi ch t hey may not have suf f i c i ent per mi ssi ons, i ncl ude t he br acket ed t ext and i ndi cat e a POC f or assi st ance wi t h cr eat i ng t he i mage.

{ For Ref er ence Onl y: Thi s subpar t ( and i t s subpar t s) r el at es t o CP- 10;

CCI - 000550, CCI - 000551, CCI - 000552}

For each comput er on whi ch sof t war e i s i nst al l ed under t hi s pr oj ect , pr ovi de a r ecover y i mage of t he f i nal as- bui l t comput er . Thi s i mage must

SECTI ON 25 05 11 Page 16 al l ow f or bar e- met al r est or e such t hat r est or at i on of t he i mage i s suf f i c i ent t o r est or e syst em oper at i on t o t he i maged st at e wi t hout t he need f or r e- i nst al l at i on of sof t war e. [

I f addi t i onal user per mi ssi ons ar e r equi r ed t o meet t hi s r equi r ement , coor di nat e t he cr eat i on of t he i mage wi t h [ _____] . ]

1. 9. 5 Cyber secur i t y Ri ser Di agr am

NOTE: Sel ect or speci f y t he f or mat f or t he r i ser diagram.

{ For Ref er ence Onl y: Thi s subpar t ( and i t s subpar t s) r el at es t o PL- 2( a) ;

CCI - 003051, CCI - 003053}

Pr ovi de a cyber secur i t y r i ser di agr am of t he compl et e cont r ol syst em i ncl udi ng al l net wor k and cont r ol l er har dwar e. I f t he cont r ol syst em speci f i cat i ons r equi r e a r i ser di agr am submi t t al , pr ovi de a copy of t hat submi t t al as t he cyber secur i t y r i ser di agr am. Ot her wi se, pr ovi de a r i ser di agr am i n [ one- l i ne f or mat ] [ one- l i ne f or mat over l ayed on a f aci l i t y schemat i c] [ t abul ar f or mat ] [ _____] .

1. 9. 6 Cont r ol Syst em Cyber secur i t y Document at i on

NOTE: The f ol l owi ng enumer at es ver y det ai l ed r equi r ement s f or document at i on; r equi r ement s t hat woul d be i mpossi bl e t o meet f or some cont r ol devi ces. The r equi r ement s ar e br oken out i n t he sub paragraphs:

1) Requi r ement s t o be met by al l sof t war e r unni ng on comput er s

2) Requi r ement s t o be met by HVAC cont r ol devi ces

3) Requi r ement s t o be met by [ f i l l i n t he bl ank] cont r ol devi ces

4) Def aul t r equi r ement s f or cont r ol syst em devi ces ( when not cover ed i n 1- 3 above)

I f t he pr oj ect i ncor por at es devi ces ot her t han HVAC devi ces, and t he gener al r equi r ement s i n sub- par agr aph 4 ar e not sat i sf act or y, add r equi r ement s t o subpar agr aph 3. I f mul t i pl e di f f er ent r equi r ement s ar e needed ( e. g. t he pr oj ect i ncor por at es a mi cr o- gr i d and and an el ect r oni c secur i t y syst em, bot h wi t h speci f i c r equi r ement s) add addi t i onal par agr aphs s i mi l ar t o par agr aph 3.

Leave t he " devi ces not ot her wi se cover ed" at t he end of t he l i s t and do not edi t t hose r equi r ement s.

Not e t hat wi t hi n HVAC devi ces, a f ur t her di st i nct i on i s made bet ween devi ces t hat FULLY suppor t account s and t hose t hat do not . Thi s di st i nct i on i s a sur r ogat e t o account f or t he r ange of capabi l i t i es and compl exi t y among var i ous HVAC cont r ol devi ces.

SECTI ON 25 05 11 Page 17

Thi s subpar t ( and i t s subpar t s) r el at es t o SA- 5 ( a) , ( b) , ( c) ; CCI s:

CCI - 003124, CCI - 003125, CCI - 003126, CCI - 003127, CCI - 003128, CCI - 003129, CCI - 003130, CCI - 003131}

Pr ovi de a Cont r ol Syst em Cyber secur i t y Document at i on submi t t al cont ai ni ng t he i ndi cat ed i nf or mat i on f or each devi ce and sof t war e appl i cat i on.

1. 9. 6. 1 Sof t war e Appl i cat i ons

For al l sof t war e appl i cat i ons r unni ng on comput er s pr ovi de:

a. admi ni st r at or document at i on t hat descr i bes secur e conf i gur at i on of t he sof t war e { r el at es t o CCI - 003124}

b. admi ni st r at or document at i on t hat descr i bes secur e i nst al l at i on of t he sof t war e { r el at es t o CCI - 003125}

c. admi ni st r at or document at i on t hat descr i bes secur e oper at i on of t he sof t war e { r el at es t o CCI - 003124}

d. admi ni st r at or document at i on t hat descr i bes ef f ect i ve use and mai nt enance of secur i t y f unct i ons or mechani sms f or t he sof t war e { r el at es t o CCI - 003127}

e. admi ni st r at or document at i on t hat descr i bes known vul ner abi l i t i es r egar di ng conf i gur at i on and use of admi ni st r at i ve ( i . e. pr i v i l eged) f unct i ons f or t he sof t war e { r el at es t o CCI - 003128} f . user document at i on t hat descr i bes user - accessi bl e secur i t y f unct i ons or mechani sms i n t he sof t war e and how t o ef f ect i vel y use t hose secur i t y f unct i ons or mechani sms { r el at es t o CCI - 003129}

g. user document at i on t hat descr i bes met hods f or user i nt er act i on whi ch enabl es i ndi v i dual s t o use t he sof t war e i n a mor e secur e manner { r el at es t o CCI - 003130}

h. user document at i on t hat descr i bes user r esponsi bi l i t i es i n mai nt ai ni ng t he secur i t y of t he sof t war e { r el at es t o CCI - 003131}

1. 9. 6. 2 For HVAC Cont r ol Syst em Devi ces

1. 9. 6. 2. 1 HVAC Cont r ol Syst em Devi ces FULLY Suppor t i ng User Account s

For al l HVAC Cont r ol Syst em Devi ces whi ch FULLY suppor t user account s, provide:

a. Document at i on t hat descr i bes secur e conf i gur at i on of t he devi ce { f or r ef er ence onl y: r el at es t o CCI - 003124}

b. Document at i on t hat descr i bes secur e oper at i on of t he devi ce { f or r ef er ence onl y: r el at es t o CCI - 003124}

c. Document at i on t hat descr i bes ef f ect i ve use and mai nt enance of secur i t y f unct i ons or mechani sms f or t he devi ce { f or r ef er ence onl y: r el at es t o

CCI-003127}

d. Document at i on t hat descr i bes known vul ner abi l i t i es r egar di ng conf i gur at i on and use of admi ni st r at i ve ( i . e. pr i v i l eged) f unct i ons f or t he devi ce { f or r ef er ence onl y: r el at es t o CCI - 003128}

SECTI ON 25 05 11 Page 18

e. Document at i on t hat descr i bes user - accessi bl e secur i t y f unct i ons or mechani sms i n t he devi ce and how t o ef f ect i vel y use t hose secur i t y f unct i ons or mechani sms; or a speci f i c i ndi cat i on t hat t her e ar e no user - accessi bl e secur i t y f unct i ons or mechani sms i n t he devi ce { f or r ef er ence onl y: r el at es t o CCI - 003129} f . Document at i on t hat descr i bes met hods f or user i nt er act i on whi ch enabl es i ndi v i dual s t o use t he devi ce i n a mor e secur e manner { f or r ef er ence onl y: r el at es t o CCI - 003130}

1. 9. 6. 2. 2 Al l Ot her HVAC Cont r ol Syst em Devi ces

For al l HVAC Cont r ol Syst em Devi ces whi ch do not FULLY suppor t user account s, pr ovi de:

a. Document at i on t hat descr i bes secur e conf i gur at i on of t he devi ce; or a speci f i c i ndi cat i on t hat t her e ar e no secur e conf i gur at i on st eps t hat appl y { f or r ef er ence onl y: r el at es t o CCI - 003124}

b. Document at i on t hat descr i bes ef f ect i ve use and mai nt enance of secur i t y f unct i ons or mechani sms f or t he devi ce; or a speci f i c i ndi cat i on t hat t her e ar e no secur i t y f unct i ons or mechani sms i n t he devi ce { f or r ef er ence onl y: r el at es t o CCI - 003127}

c. For devi ces whi ch i ncl ude a user i nt er f ace, document at i on t hat descr i bes met hods f or user i nt er act i on whi ch enabl es i ndi v i dual s t o use t he devi ce i n a mor e secur e manner { f or r ef er ence onl y: r el at es t o

CCI-003130}

[ 1. 9. 6. 3 [ _____] Cont r ol Syst em Devi ces

NOTE: Use t hi s br acket ed subpar t i f needed t o add r equi r ement s f or a speci f i c cont r ol syst em t ype ( e. g. l i ght i ng, el ect r i cal di st r i but i on et c) , s i mi l ar t o how HVAC cont r ol syst em devi ces ar e cover ed above.

I f addi ng a new cont r ol syst em t ype, submi t a Cr i t er i a Change Request wi t h t he r el evant r equi r ement s t o have t hat syst em i ncl uded i n t he publ i shed UFGS.

] 1. 9. 6. 4 Def aul t Requi r ement s f or Cont r ol Syst em Devi ces

NOTE: Do not edi t t hese r equi r ement s. I f t hese r equi r ement s do not appl y t o a speci f i c cont r ol syst em used on t he pr oj ect , i ncl ude r equi r ement s f or t hat cont r ol syst em usi ng t he br acket ed subpar t pr ovi ded above.

For cont r ol syst em devi ces wher e Cont r ol Syst em Cyber secur i t y Document at i on r equi r ement s ar e not ot her wi se i ndi cat ed i n t hi s Sect i on, pr ovi de:

SECTI ON 25 05 11 Page 19

a. Document at i on t hat descr i bes secur e conf i gur at i on of t he devi ce { f or r ef er ence onl y: r el at es t o CCI - 003124}

b. Document at i on t hat descr i bes secur e i nst al l at i on of t he devi ce { f or r ef er ence onl y: r el at es t o CCI - 003125}

c. Document at i on t hat descr i bes secur e oper at i on of t he devi ce { f or r ef er ence onl y: r el at es t o CCI - 003124}

d. Document at i on t hat descr i bes ef f ect i ve use and mai nt enance of secur i t y f unct i ons or mechani sms f or t he devi ce { f or r ef er ence onl y: r el at es t o

CCI-003127}

e. Document at i on t hat descr i bes known vul ner abi l i t i es r egar di ng conf i gur at i on and use of admi ni st r at i ve ( i . e. pr i v i l eged) f unct i ons f or t he devi ce { f or r ef er ence onl y: r el at es t o CCI - 003128} f . Document at i on t hat descr i bes user - accessi bl e secur i t y f unct i ons or mechani sms i n t he devi ce and how t o ef f ect i vel y use t hose secur i t y f unct i ons or mechani sms { f or r ef er ence onl y: r el at es t o CCI - 003129}

g. Document at i on t hat descr i bes met hods f or user i nt er act i on whi ch enabl es i ndi v i dual s t o use t he devi ce i n a mor e secur e manner { f or r ef er ence onl y: r el at es t o CCI - 003130}

h. Document at i on t hat descr i bes user r esponsi bi l i t i es i n mai nt ai ni ng t he secur i t y of t he devi ce { f or r ef er ence onl y: r el at es t o CCI - 003131}

1. 10 SOFTWARE UPDATE LI CENSI NG

NOTE: The i nst al l at i on may pr ocur e i t s own sof t war e updat e l i censi ng or cont r act and t hus needs l ess t han 5 year s. Al t er nat i vel y t he i nst al l at i on may r equi r e l onger t han f i ve year s ( al t hough t hi s wi l l l i kel y i ncr ease t he cost s s i gni f i cant l y) .

Coor di nat e wi t h t he i nst al l at i on t o det er mi ne i f t hey have any…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .