Attachment 6_Chapter 9 AFI31-101.pdf
PDF 2 MB Posted
- Attached to
- FM9 DSL Upgrade Federal contract opportunity
- Solicitation number
- FA527023QA039
About this file
This is a solicitation for a Department of the Air Force contract to upgrade network switches, install panel boards and modems, and complete associated wiring and programming at a facility. Key requirements include replacing three network switches, installing 52 Vindicator 1500 panel boards and 104 DSL modems along with the necessary fiber and copper wiring. Additional tasks involve contractor management, system design, purchasing equipment, installation, integration with existing systems, verification and acceptance testing of non-approved equipment, training, site support, and assistance with government testing. Interim contractor support may also be ordered. All networking equipment must be licensed and approved for Windows 10, and all intrusion detection system work must be done by cleared US nationals with the proper certifications. While some line items specify brands, justification is provided for those in an attachment.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 9_Answers to Questions.pdf | ||
| 23QA039-0005_SF30.pdf | ||
| Attachment 1_Price list.xlsx | XLSX spreadsheet | |
| Attachment 8_CMD.pdf | ||
| Attachment 7_PACAFSUP.pdf | ||
| 0004_Extension due date.pdf | ||
| 0003 - Move the Site Visit.pdf | ||
| 0002_QA extension.pdf | ||
| 0001 - Site Visit.pdf | ||
| Attachment 3_DFAS Japan AF EFT Submission (NEW DEAMS 202201).pdf | ||
| FA527023QA039_COMBO_Final.pdf | ||
| Attachment 4_Brand Name Justification_Redacted.pdf | ||
| Attachment 5_SOW.pdf | ||
| Attachment 2_DEAMS EFT Enrollment Form Updated 10_2022.pdf | ||
| Attachment 1_Price list.xlsx | XLSX spreadsheet |
Show all 15
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
132 AFI31-101 25 MARCH 2020
FOR OFFICIAL USE ONLY
Chapter 9
INTRUSION DETECTION SYSTEMS
9.1. Overview. The Integrated Base Defense program directs the procurement, installation, deployment and logistics support of most AF IDS and situational awareness (SA) technologies.
Testing, approving, and procuring IDS/SA tools is a coordinated effort. Exception: For Secure
Room/Open Storage (of classified materials), the certification approval authority is the servicing
Information Protection office. For SCIFs, the accrediting official must approve interior IDS before purchase and installation, and is responsible for testing. (T-0). For SCIFs, the IDS standards must meet the requirements ICS 705-1, Physical and Technical Security Standards for Sensitive
Compartmented Information Facilities Annex B and IC Tech Specs for ICD/ICS 705, Tech
Specifications for Construction and Management of Sensitive Compartmented Information
Facilities and the MAJCOM SSO must be included in the planning process. (T-0). For more information on SCIFs requirements, refer to ICS 705-1, Annex B and Paragraph 10.6 of this instruction. For all SAPFs, follow guidance issued by the cognizant authority, DoD and AF Special
Access Program Central Offices. For the AF, SAF/AAZ is the oversight authority for all AF
Special Access Programs (SAPs) and SAPFs.
9.2. IDS Concepts and Planning. IDS/SA comprise a mix of equipment and components.
Components may include exterior sensor equipment (fence and clear zone), interior sensor equipment (facility), individual resource sensor equipment, integrated AECS, alarm data transmission equipment, assessment equipment (closed-circuit television and associated equipment), alarm annunciation and display equipment, blue force tracking, base assets status information, etc. IDS provide SF with the capability to assess SA information (alarms, tips, Position Location Information, etc.) and initiate responses in a manner that will aid in preventing damage, destruction, or unauthorized access to the resource. Exception: Do not replace IDS
(systems or components) that have already been purchased or installed only to meet this instruction's standards. Upgrade components when they deteriorate or as required to meet operational needs. Refer to Chapter 10 for additional requirements for PL-4 resources.
9.2.1. Concept. IDS provide an electronic means of accomplishing area intrusion detection, alarm reporting and display, remote alarm assessment, and alert SF to intrusions in order to enhance the protection of resources and facilities. These systems are a force multiplier and provide a detection capability not achievable by SF alone. SA tools provide overarching status of the base, including personnel and assets and mechanisms to provide IDS information to the most effective resource. Other security tools, such as fencing, lighting, ground communications systems, vehicle condition, facilities information, non-IDS sensors, and position location information (PLI) complement IDS and provide ID forces an essential technological advantage. Deterrence, by using items such as posted warning signs or visible sensors can also augment ID forces. IDS detects intruders and warns ID forces of intrusions by annunciating an alarm at the BDOC or alarm monitoring facility, alerting ID forces in the area of responsibility.
IDS also provides a tool for SF to locate and assess the detected threat so ID forces rapidly respond to defend assets and defeat or delay attack(s). SA information, provides a mechanism to quickly asses the state of the base, conceptualize available assets, and direct those assets effectively. The focal point for the operation of these systems is the installation Defense Force
Commander.
AFI31-101 25 MARCH 2020 133
9.2.1.1. When individual types of Intrusion Detection Equipment are properly applied around a restricted area boundary and inside a restricted area to support a specific resource, the result is an IDS which provides a detection capability not normally achievable by security forces alone. The types of IDS are categorized as exterior sensor systems, structure and shelter sensor systems, (entrance and interior), and individual resource systems.
Annunciator and display equipment and assessment equipment are part of the IDS.
Perimeter IDS primarily defends against the unskilled to semi-skilled intruder. While it achieves a competent detection capability against these two types of intruders it does not adequately address the skilled to highly-skilled threat. Hence, perimeter sensor systems must not be viewed in isolation, but rather as a subsystem of the security system.
9.2.1.2. Combined with Paragraph 9.2.1.1., active patrolling, delay and denial, interior sensors, physical security aids, and posted sentries combine to create a myriad of detection capabilities and obstacles once an intruder breaches the boundary of a restricted area.
Security Forces must be aware of the strengths and shortcomings of sensor systems. (T-1).
9.2.2. Planning. AFSFC utilizes Security System Project Descriptions developed and submitted by the site survey team (assembled by the agency responsible for install) to validate specific installation IDS project requirements. ANG units will submit Security System Project
Descriptions to ANG/A4SX, who will then forward to AFSFC. (T-3). The planning process decreases overall IDS vulnerability to countermeasures, environmental extremes, failure modes, and other emergencies. AFSFC must develop a pre-planned product improvement and replacement program to ensure long-term IDS support and sustainment. (T-1). System Project
Description templates can be obtained from AFSFC at afsfc.ibdss@us.af.mil. MAJCOMs will submit capability gaps to AFSFC and AF/A4S.
9.2.2.1. Objective planning requires SF to understand the strengths and weaknesses of
IDS. All sensor phenomenologies have weaknesses that may be exploited. AFLCMC/HBU can provide a list of vulnerabilities (classified and unclassified) for approved sensors. For example, boundary IDS primarily detect unskilled or semi-skilled intruder(s) but may not adequately detect the skilled or highly-skilled threat(s). For this reason, security planners use boundary sensor equipment as a component of the overall restricted area security system.
9.2.2.2. Units operating IDS shall document the technical capabilities of the components employed and show how other elements of the security system offset IDS limitations. (T-
3).
9.2.2.3. Use a holistic approach to ensure IDS plans are mutually supportive to those involving other effects, such as: active patrolling, sensors, security lighting, Military
Working Dog teams, posted sentries and physical obstacles to intrusion, such as fences, locks, and facility delay mechanisms.
9.2.2.4. The System Project Description describes the physical security capability a unit strives to achieve and prioritizes requirements to achieve that capability. It is the instrument used to document those requirements for physical security system installs/upgrades at fixed and/or deployed sites. The key elements of a System Project Description are specificity, clarity, and the verifiability of each requirement. As a minimum, the System Project
Description includes:
mailto:afsfc.ibdss@us.af.mil
134 AFI31-101 25 MARCH 2020
9.2.2.4.1. Scope. This is a clear and specific description of the operational capability sought, with a clear distinction between “required” and “desired” capabilities. A required capability can be directly traced to a requirements document (e.g. DoD
Instruction, AFI, AFMAN, etc.). A desired capability is one that may be developed by the local unit to counter a specific threat or compensate for a known vulnerability and is not directly addressed by a requirements document. Provide an overview of the resource(s), area(s) to be protected, and timeline. Phased approach considerations may be added as well.
9.2.2.4.2. An analysis of how the project will reduce risk using the IDRMP model.
9.2.2.4.3. A list of regulatory and reference documents applicable to the initiative.
9.2.2.4.4. Any special considerations.
9.2.2.4.5. Project points of contact (individual/office) at the installation
9.2.2.4.6. Maintenance, training, and a logistical support plan.
9.2.2.4.7. Any support required
9.2.2.4.8. Specific and prioritized requirements. The requirements should address the key capability categories desired (e.g. detection, assessment, etc.) not specific brands or products. Each requirement should include a brief rationale that explains the desired capability.
9.2.2.4.9. Illustrations, aerial photographs or facility drawings further describing capabilities and desired effects will be included.
9.2.2.5. System Performance Specifications are developed by Integrated Base Defense
Security System (IBDSS) applicable PEO in conjunction with AFSFC and the MAJCOM to detail the specific performance and operational capabilities requried for the physical security project as descrived in the System Project Description. The applicable PEO will forward a copy of the System Performance Specifications to AFSFC and the sponsoring
MAJCOM for review/approval prior to installing IDS or security systems. (T-3). Key performance parameters, thresholds, and objectives contained in the System Performance
Specifications and System Project Description are derived from the IBDSS Capabilities
Development Document.
9.2.2.6. When validation requirements for installed IDS or security equipment/system are not contained in ESE-TP-0023, Electronic Security Equipment Installation Acceptance
Test and Turnover Plan, the approved System Performance Specifications document may serve as the site-specific test and turnover plan used to conduct Government Acceptance
Testing and for testing throughtout the life of the system at an installed location.
9.2.2.7. AFSFC is also a resource for proof of concept for new sensor technology and mitigators. AF/A4S, AFSFC and AFLCMC will coordinate testing and fielding efforts.
Proposed actions which are not in line with existing Air Force or DoD policy must be vetted through the approval authority for the policy in question. (T-1).
9.2.3. Environmental Considerations. IDS operate worldwide under all climatic and environmental conditions, however, environmental effects on IDS cannot be overlooked. Use only approved rugged, corrosion-resistant components suitable for the local conditions.
AFI31-101 25 MARCH 2020 135
9.3. Testing IDS. In accordance with the PEO designation, the 46th Test Squadron (46 TS) conducts developmental test and evaluation or qualification test and evaluation per system requirements. AFSFC is responsible for conducting operational testing for SF acquisition category
III programs not on OSD test and evaluation Oversight in accordance with AFI 99-103, Capabilities-Based Test and Evaluation.
9.3.1. Develop Test and Evaluation, Qualification Test and Evaluation, and operational test and evaluation are required for systems and components and are done prior to procurement and installation at an operational location. This testing is typically accomplished at Test Site
C-3, Eglin AFB, FL, and the Cold Weather Test Site-Grand Forks AFB, ND, and may be conducted at other sites.
9.3.2. Tests not conducted by 46 TS must clearly indicate the testing provided equivalent levels of quality, control, objectivity, validity, and operational relevance as that provided by a
46 TS. (T-1). AFLCMC/HBU is responsible for verifying that the system being tested meets functional level requirements (Operational Safety, Suitability and Effectiveness). AFSFC is responsible for determining if the system being tested meets AF standards and operational level requirements.
9.3.3. Once a component is approved for follow-on deployment, additional testing may be required for different applications or configurations.
9.4. Approving IDS. AFSFC/CC approves IDS equipment and components used in restricted areas for detecting intruders, assessing intrusions, displaying intrusions, transmitting data, controlling entry, and delaying and denying entry. IDS equipment and components are approved when test data proves their effectiveness and suitability in the tested applications and configurations.
9.4.1. The responsible acquisition program office monitors the testing process for AF IDS and compiles test data packages and submits them to AFSFC. AFSFC assesses the data submitted by test agencies, obtains recommendations for approval or disapproval from these agencies, and evaluates all recommendations provided. As the OPR, AFSFC compiles this data, obtains appropriate staff coordination and publishes Intrusion Detection System Equipment List. The list identifies all sensor system (software and hardware) capabilities which are used for integrated defense detection systems.
9.4.2. Equipment approved and listed on the Intrusion Detection System Equipment List may be used in all successfully tested applications and configurations. AFSFC will periodically review and update the listing for outdated or obsolete IDS. In all cases involving SCI facilities, the accrediting official approves equipment for use.
9.4.3. The acquisition program office will semi-annually review the Intrusion Detection
System Equipment List and update AFSFC to ensure the equipment has not become obsolete.
When updating/signing a new Intrusion Detection System Equipment List, the AFSFC will forward the list to AFLCMC/HBU and AF/A4S to avoid confusion on approved IDS. (T-1).
9.5. Selecting IDS. IDS is used to enhance overall security or supplement in one or more aspects of security. For IDS normally supporting PL 1-4 resources, use only IDS from the Intrusion
Detection System Equipment List. Exception: Do not replace IDS (systems or components) that have already been purchased or installed only to meet this Instruction's standards. Upgrade components when they deteriorate or as required to meet operational needs. The Non-Nuclear
136 AFI31-101 25 MARCH 2020
Intrusion Detection System Equipment List may be obtained from AFSFC at afsfc.ibdss@us.af.mil. IDS is not required for PL 4 resources unless specified by higher headquarters, outlined in this chapter, or determined locally by the IDC. If required, IDS will be selected from the approved Intrusion Detection System Equipment List. (T-1). For all other resources requiring IDS governed by DoD instructions, installations are required to follow IDS guidelines outlined in those respective regulations. If the AF levies different IDS requirements than those of a higher headquarters, the most stringent IDS requirement will be followed.
9.5.1. When selecting IDS equipment and components, consider the following:
9.5.1.1. Maintenance, system administrator and operator training for the operational location.
9.5.1.2. Adequacy of T.O. and maintenance support for the operational location.
9.5.1.3. Complementing sensor phenomenologies to meet line of detection and situational awareness requirements.
9.5.1.4. Compatibility with already installed equipment at the operational location.
9.5.1.5. Known probability of detection rates and nuisance and false alarm rates.
9.5.2. Units will not rely on untested and unapproved IDS to meet existing installation security guidance. With the exception of defined period RT&E efforts coordinated with AF/A4S and
AFLCMC through C3, unapproved IDS will not be connected in any way, nor housed in similar housings/cabinetry with an approved system. Note: Security Forces are not required to respond to unapproved IDS alarms (T-3). Units that procure unapproved IDS are responsible for:
9.5.2.1. Supporting maintenance, logistics, and training requirements.
9.5.2.2. Meeting AF installation security standards.
9.5.2.3. Applying the deviation program where systems fail to meet established standards and compensatory measures are required.
9.5.2.4. The DFC may direct local Security Forces to respond to unapproved alarm systems in the furtherance of base, asset or personnel protection.
9.5.3. Other Considerations. The use of IDS are planned to meet actual protection requirements. In making a decision on the acquisition of any IDS, all factors must be considered that will affect its operation and usefulness. Some of these factors include:
9.5.3.1. The known capabilities and limitations of the equipment being considered.
9.5.3.2. The facility design and areas to be protected.
9.5.3.3. The effects of weather, air conditioning systems, air and ground traffic.
9.5.3.4. The effects of the system on the day-to-day operations of the facility.
9.5.3.5. Whether the system will be effective against any attempted intrusion from any reasonable approach into the structure or area.
9.5.3.6. When IDS malfunction, it must be designed to transmit a line fault message to the annunciator panel. (T-1).
9.5.3.7. The proposed configuration must lend itself to protection from tampering. (T-1).
mailto:afsfc.ibdss@us.af.mil
AFI31-101 25 MARCH 2020 137
9.6. IDS Characteristics. Basic IDS characteristics have been identified to ensure minimum protection standards. IDS will have the following features:
9.6.1. Capability of prompt detection of any attack on the area for which it is designed to detect.
9.6.2. Should have a high degree of salvage value so equipment may be removed and used elsewhere.
9.6.3. Consist of an open architecture and based on open standards to the greatest extent possible to ensure interoperability and innovation.
9.6.4. CONUS installations should operate on 110-120 volt, 50-60 Hertz AC power, and have a protected backup independent power source with automatic switchover capability to allow for continuous emergency operation for at least four hours. OCONUS should operate on local voltage.
9.6.5. An alarm annunciator located at the BDOC or other facility continuously manned by
SF capable of notifying response forces.
9.6.6. Flexibility to protect large and small areas with small cost differences.
9.6.7. Ability to register malfunctions.
9.6.8. Audible and visual alarm annunciation capabilities.
9.6.9. Line fault indicator if the system or subsystems fail.
9.6.10. On/off switches and access or secure switches located inside the alarmed area unless equipped with a keypad that may be located outside the facility.
9.6.11. Ability to distinguish which specific facility is being accessed, secured, requires a response or is indicating a duress situation. Alarm systems will not be tied together in a manner which prevents the monitoring facility from distinguishing the individual facility under alarm.
9.7. Procuring IDS. AFIMSC, through the AFSFC, manages centralized procurement of IDS in support of PL 1-4 resources.
9.7.1. Advocacy for program funding begins at the installation. AFSFC defines specific requirements for installation of new systems and AFIMSC ensures IBDSS program funds are adequate to facilitate system life cycles and upgrades as necessary. Among all other IBDSS funding concerns, particular attention needs to be paid to programming the costs involved in allied support and the potential for increased program cost growth based on infrastructure age.
AF/A4S and AFIMSC should invest in continual research and development to ensure IDS suites stay modern, take advantage of technological innovations, and review for new sensors and new phenomenologies providing cost savings and improved capabilities.
9.7.2. AFLCMC/HBU manages IDS procurement and logistics consistent with established priorities and funding.
9.7.3. Controlled Area IDS/SA. IDS funding for controlled areas is the responsibility of the owner or primary user of the facility requiring the IDS. Use of commercially leased or purchased IDS is permitted; however, the IDS must meet or exceed all DoD standards. (T-0).
All requests for acquisition or modification of alarm systems is coordinated through the IDC before contract tendering. (T-3). Coordinate all purchases of commercial IDS with the
138 AFI31-101 25 MARCH 2020
installation SF, CE Squadron and Communications Squadron to ensure compatibility. Most installation IDS maintenance contractors or personnel are not trained on commercial systems, so a maintenance contract with the IDS installer is highly encouraged.
9.8. Replacing IDS. The normal life of IDS are about ten years. Plan to replace IDS accordingly.
The IDC and/or Alarm Working Group shall provide AFSFC with a semi-annual system status report to help determine IDS health and scheduling of replacement. (T-2). Note: IDS or components that are being replaced are required to tie into the existing SF security system platform in which all other alarms are processed.
9.9. Detection Requirements. Each intrusion detection system for PL resources consists of a detection capability or one or more lines of detection using sensors that meet probability of detection and nuisance and false alarm rate requirements.
9.9.1. Establishing Lines of Detection. Use a sensor or sensors in combination when establishing a line of detection. A sensor or sensors in combination that constitute a line of detection are identified in the Intrusion Detection System Equipment List.
9.9.2. IDS Protection Requirements. IDS annunciators should be located inside the alarmed area, where possible. If the system includes a keypad, locate it outside the alarmed area. All
IDS must include a line supervisory capability and sensitivity commensurate with the PL resource being protected. (T-0).
9.9.3. Requirements for Lines of Detection and Detection Capability. Where a line of detection is employed, it must be installed, operated, and maintained as designed, tested, and approved. (T-3). A line of detection must detect all reasonable intrusion scenarios including surreptitious attempts to spoof and tamper with the line of detection. (T-3). A detection capability is defined as the ability to identify the presence of an intruder or unauthorized personnel prior to entering the restricted area. A detection capability may include, singularly or combined, the mechanical, physical, or procedural methods associated with securing protection level assets. Detection capability provides responsible commanders with operational and tactical flexibility so they can use the most cost effective and efficient method to meet protection requirements.
9.9.3.1. A line of detection installed on a fence must detect cutting, climbing upon, and lifting the fence fabric. Any attempt to cut a fence tie or clamp resulting in an alarm event satisfies the lifting requirement. (T-3).
9.9.3.2. A line of detection at the area perimeter must detect walking, running, rolling, crawling across, or jumping through the line of detection. (T-0).
9.9.3.3. A line of detection at a facility must detect intrusion attempts through likely avenues of approach such as doors, windows, walls, vents or roof. (T-0).
9.9.4. Probability of Detection. Probability of detection is tested and evaluated during
Operational Test and Evaluation to ensure no conditions exist where an intruder can predict successful penetration (exploit the system) using reasonable intrusion scenarios. These calculations are statistic in nature, driven by specific formulas and expressed as a percentage.
9.9.5. Approach Zone. The Approach Zone, ideally, should extend to the maximum threat range of the adversary’s assessed capability. This normally equates to at least 300 meters from the area boundary or first line of detection. However, Approach Zone specific guidance for
AFI31-101 25 MARCH 2020 139
security environments will be completed locally and placed in the IDP. (T-3). Wide Area
Detection Systems is used to detect vehicular and/or pedestrian movement in the Approach
Zone and will cover likely avenues of approach normally unoccupied. (T-3). Complete coverage of the Approach Zone is not required (unless deemed necessary by MAJCOM or installation). The objective is for enhanced situational awareness and Wide Area Detection
Systems capability is one element of a comprehensive intrusion detection and tracking scheme, but is not a line of detection or independent detection capability.
9.9.5.1. Detection of crawlers past 100 meters is not required.
9.9.5.2. Where Approach Zone coverage is mandated, it should be implemented to the maximum level possible regardless of terrain.
9.9.6. PL-1-3 Facility IDS Requirements. These requirements apply to PL-1-3 facilities.
9.9.6.1. Facilities manned 24-hours a day are not required to have IDS. However, they must have a duress alarm that terminates at the BDOC responsible for dispatching response elements. (T-1).
9.9.6.2. Facilities not manned 24-hours a day are required to have IDS. They must have a detection capability for all facility openings greater than 96-square inches that terminates at the BDOC responsible for dispatching response elements. (T-1).
9.9.7. PL-1 Asset Requirements. Establish one line of detection at the restricted area boundary and one line of detection at each facility or individually exposed resource. Lines of detection for PL-1 resources must meet a probability of detection of .95 at the 90 percent confidence level. (T-1).
9.9.8. PL-2 Asset Requirements. Establish one line of detection at the restricted area boundary and a detection capability at the individual facility or resource(s). The line of detection at the restricted area boundary must meet a probability of detection of .95 at the 90 percent confidence level. (T-1).
9.9.9. PL-3 Asset Requirements. Installations should utilize IDRMP to determine the most cost-effective means of protecting PL-3 assets. At minimum, establish a detection capability that is capable of detecting unauthorized personnel prior to entering the restricted area.
9.9.10. Interior IDS. Economically, IDS coverage of the entire interior of a facility is difficult to achieve. The AF allows unsensored areas, or dead zones, in facilities as long as they do not allow intruders approaching from doors, windows, walls, roofs or vents to reach the resource before setting off an alarm.
9.9.10.1. Substantially constructed facilities, such as storage buildings and aircraft hangars, are adequate to protect against covert penetration of floors, windows, walls, and roofs. In facilities of this type, IDS coverage detects an intruder entering through the doors and any openings that exceed 96-square inches with the smallest dimension greater than
6.4 inches. IDS detect intruders before they reach the resource. Exception: This does not apply to facilities used on a temporary basis such as aircraft maintenance or nose docks.
Aircraft nose docks and facilities that are permanent restricted areas and do not have substantially constructed walls and roof must have IDS coverage of the walls and roof. (T-
1).
140 AFI31-101 25 MARCH 2020
9.9.10.2. Stay Behind Threat. Due to the size of some facilities, interior motion detection may not detect the stay behind threat. In these situations, owners/users must be used to purge the facility before securing it to defeat this threat, and this check must be recorded in the SF blotter. (T-3).
9.9.11. Invalid Alarms. IDS are designed and must be maintained to minimize invalid alarms.
(T-2). The term invalid alarms incorporates nuisance and false alarms. False alarms are those for which no cause can be determined. Nuisance alarms are those caused by an influence the sensor was designed to detect such as an animal or an act of nature, but is not related to an intrusion. Valid alarms are all caused by an actual human (intrusion or testing) or when environmental conditions exceed operational parameters of the sensors. Valid alarms are not considered when calculating Nuisance Alarm Rate/False Alarm Rate (NAR/FAR). Note: The influence that caused the nuisance alarm must be clearly identifiable, short term, and followed by an immediate reset or it is considered a false alarm. The intent of tracking nuisance and false alarms is for the ESS NCO to investigate and address the root cause of these alarms when a negative performance trend is detected.
9.9.11.1. Nuisance and False Alarm Rates. Interior, exterior, and individual resource IDS nuisance and false alarms must be computed separately, and tracked over time. (T-1). If the alarms exceed the thresholds below, operators will open a work order for exceeding the
False Alarm Rate in accordance with local procedures. (T-1).
9.9.11.1.1. Interior IDS. Interior nuisance and false alarms should be extremely limited.
9.9.11.1.1.1. No more than one false alarm per individual sensor point within 30 calendar days is acceptable.
9.9.11.1.1.2. No more than three nuisance alarms per individual sensor point within 30 calendar days is acceptable.
9.9.11.1.2. Exterior IDS. Proactive measures such as animal control fences, wind filters, vegetation control, etc., may be required to maintain this standard.
9.9.11.1.2.1. No more than one false alarm per individual sensor point within the previous 24-hour period is acceptable.
9.9.11.1.2.2. No more than three nuisance alarms per individual sensor point within the previous 24-hour period is acceptable.
9.9.11.1.3. Individual Resource IDS. IDS configured to protect an individually exposed resource, such as an aircraft, must not have more than three false alarms or three nuisance alarms per individual sensor point within the previous 24-hour period.
(T-3).
9.9.11.1.4. Approach Zone IDS.
9.9.11.1.4.1. Due to the uncontrolled environment being monitored, Approach
Zone IDS alarms are either considered valid or false.
9.9.11.1.4.2. No more than 10 false alarms per individual sensor point or correlated zone within the previous 24 hours is acceptable.
AFI31-101 25 MARCH 2020 141
9.9.11.2. Compensatory Measures. Compensatory measures shall be implemented for IDS not meeting nuisance and false alarm rate standards. (T-3).
9.10. Annunciation and Display Requirements. The alarm annunciation and display subsystem can consist of the primary and sometimes a remote annunciator. In the future, a distributed alarm annunciation and display subsystem may be approved and deployed. IDS normally annunciate and display at a single location within the restricted area (alarm monitoring station, entry control points or BDOC). They display, audibly and visually, in alphanumeric fashion (e.g., Sector 21 or Bldg
5311, Bay 1), access and secure alarms states, and the changes from one state to another.
9.10.1. Annunciator Terminal. All resources protected by IDS annunciate at a location staffed
24-hours per day; for example, the BDOC, main gate, or separate alarm monitoring facility manned by SF personnel. Locate annunciator displays out of public view.
9.10.2. Primary Annunciators. A primary annunciator can operate on a laptop computer, a desktop computer, mobile device, or other alarm annunciation equipment. Primary annunciators must incorporate command, control and display components and have the following features: (T-3).
9.10.2.1. Command, control, and display subsystems must accommodate all on-site communications media. (T-3).
9.10.2.2. Display interior, exterior, approach zone and individual resource sensors.
9.10.2.3. Respond to operator inputs.
9.10.2.4. Allow operators to interact with AECS if installed.
9.10.2.5. Activate response devices.
9.10.2.6. Support other electronic security subsystems and components as required.
9.10.2.7. Maintain an electronic events file, capable of registering any/all alarms as they occur in real time, operator changeover (log-on/log-off) and system and operator initiated self-test. Units will ensure each events file data line shows the date, time, and location of event/alarm and alarm priority.
9.10.3. Map Displays. Indicators must be displayed as a point on a geographic map depicting the IDS layout in relation to the restricted area configuration. Additionally, geographic map displays must indicate roads, area perimeter and facilities in the area.
9.10.4. Data-Link Supervision. These audio and visual indicators show hardwire or non-wireline datalink supervision status, and should include warning of detected radio frequency jamming.
9.10.5. Self Tests. Annunciators must have a self-test capability for individual sensors to be tested. Computer-based systems with inherent capability of constant polling and status display meet the intent of self-test.
9.10.6. Systems with Single Central Processing Unit (CPU). The AF accepts the potential risks associated with CPU failure in systems with a single CPU. Develop compensatory measures in the event the single CPU fails.
9.10.7. Probability of Correct Annunciation. Annunciators must function with 99.9% accuracy.
142 AFI31-101 25 MARCH 2020
9.10.8. Computer Based Annunciator Alarm Event Priority. Computer-based IDS annunciators must display alarms in order of priority; however, the security response to alarm activations is determined by utilizing installation’s asset list produced during the IDRMP (to include prioritization within each category below). The required priority display of alarms is as follows:
9.10.8.1. Individual resource or facility intrusion alarms.
9.10.8.2. Individual resource or facility tamper alarms.
9.10.8.3. Boundary intrusion alarms.
9.10.8.4. Boundary tamper alarms.
9.10.8.5. AECS alarms.
9.10.8.6. Duress alarms.
9.10.8.7. Approach zone sensor alarms.
9.10.8.8. Other alarms on a first-in, first-out basis. (e.g. line supervision alarms, low battery, etc.)
9.10.9. Remote Annunciators. The remote annunciator, if installed, must have the same features as the primary and mirror the primary annunciator's functions by displaying alarm indicators, facilities, AECS status, map displays and other information that shows on the primary annunciator display.
9.10.9.1. The remote annunciator must also display the status of the primary annunciator.
9.10.9.2. The Remote Annunciator provides the remote system operator with the capability to take control of a sensored area from the primary. Taking control can be done either by operator command, or automatically upon failure of the primary annunciator.
9.10.9.3. Remote annunciators and administrative workstations must be secured in an identical fashion to the primary annunciator or secured as a controlled area, if not manned
24 hours per day by SF personnel.
9.10.9.4. If a distributed annunciator is filling the role of a remote annunciator, then it must meet all remote annunciator requirements.
9.10.10. Human Factors. IDS annunciators must have display and system control functions designed to permit the operator to change alarm status, acknowledge and reset alarms, and conduct self-tests of the circuit continuity with the maximum level of efficiency.
9.11. Transmission Line Security for PL 1-4 Resource IDS. Secure IDS data transmission equipment against tampering by using data transmission line supervision features, which are monitored by SF personnel. Use the following measures identified below to secure data transmission equipment. In addition, posted ID personnel will remain vigilant and watch for surveillance or possible attempts to impact these transmissions. This requirement does not apply to legacy PL-3/4 systems until replaced or funding becomes available. When an installation uses different types of data transmission links, they must interface with each other.
9.11.1. Control and Data Transmission Media. Protect control and data transmission media commensurate with the level of sensitivity of the information being communicated as
AFI31-101 25 MARCH 2020 143
determined by a risk management framework impact assessment for the Platform Information
Technology System. Control or data transmission media may include hardwired or optical fiber data transmission links or radio waves, both omni-directional (broadcast) and directional. Note:
Do not use radio waves if radio frequency interference affects IDS alarms causing them to fall below threshold probability of detection.
9.11.2. Encryption. All IDS data transmission lines shall be protected with a National Institute of Standards and Testing certified Advanced Encryption Standard encryption. Units must keep the certification on file for the life cycle of the system. Note: Current systems are grandfathered, however, any upgrades or newly installed systems will meet the requirements of this Paragraph.
9.11.3. Line Supervision. Systems using this type of supervision must comply with line supervision rules below (listed in Paragraphs 9.11.3.1 - 9.11.3.4.) in accordance with UL
1610 and UL 1635. Line Supervision is required regardless of PL designation. This alarm will be a separate and distinct annunciation, and will not have a like annunciator indication with other alarm points.
9.11.4. Physical Protection of Internal Cabling. Installations must protect the cabling between the sensors and the annunciator (called the detection loop) for the IDS. (T-3). IDS cabling may be routed in rigid pipe (e.g., metal conduit or polyvinyl chloride (PVC)), flexible semi-rigid conduit, or equivalent raceways. These materials must comply with national electric code standards.
9.11.5. Physical Protection of Exterior System Cabling. Physically protect permanently installed exterior communications cable data links and circuits using conduit, direct burial, or above-ground installation methods. Route exterior IDS cables not directly protected by sensors either through rigid pipe (e.g., metal conduit or PVC) or equivalent raceways buried to the normal depth as stated in the siting criteria or suspended at least 10 feet (3 meters) above the surface. . If this cabling is crossing a drainage conveyance of any kind, it will be placed in rigid pipe conduit, or flexible semi-rigid conduit and affixed to a rigid bridge structure. Direct-buried armored cable may be used for cross-installation connections between primary security systems and remote or redundant display areas. Ensure the cable selected prevents signal emanation.
9.11.6. Terminal and Junction Boxes. Permanent junction boxes, field distribution boxes, cable terminal boxes and cabinets/CCDE consoles (equipment that terminates, splices and groups interior or exterior IDS input or that could allow tampering, spoofing, bypassing or other system sabotage) must have tamper protection. As a minimum, locks or seals must be installed on equipment that is protected by sensors in continuous operation. (T-3). Tamper switches must be installed that provide tamper indication to the annunciator(s) on equipment that is not continuously protected by sensors. (T-3). All tamper switches for junction boxes shall be a dedicated alarm input to the annunciator, and will not be combined with other alarm points. (T-3). Communications infrastructure (e.g. servers, closets, etc.) used to transmit alarm signals must be protected to the same standards, and access must be strictly controlled. (T-3).
9.11.6.1. When equipment is protected by IDS, sensors must detect and set off an alarm before approaching individuals reach the equipment. In such cases, sealing or locking is sufficient.
144 AFI31-101 25 MARCH 2020
9.11.6.1.1. Use recessed socket wrench bolts, screws, locks, or other hardware.
9.11.6.1.2. Type II or Type I secondary padlocks must meet this requirement, if used.
9.11.6.1.2.1. Agencies responsible for sensor system maintenance secure, control, and account for keys to all locks used to secure IDS equipment and components.
(T-3).
9.11.6.1.2.2. Locks may be master keyed.
9.11.6.1.3. Pull boxes used during installation to prevent a break or termination in the wire and do not present the opportunity to spoof, bypass or otherwise defeat the system do not require tamper protection.
9.11.6.2. MAJCOMs may determine seal requirements, if used. FF-S-2738A, Federal
Specification, Seals, Anti-Pilferage, contains a list of seals by style and type, which may be used.
9.11.7. Radio Frequencies. For radio frequency data transmission links, the security system must operate in all worldwide frequency bands designated in the International
Telecommunications Union and National Telecommunications and Information
Administration, Table of Allocations. Coordinate with the installation Radio Frequency
Manager for approval before using radio frequencies. If a radio is used for both methods of data transmission, use different frequencies.
9.11.7.1. The security system must use defined and approved frequencies to transmit IDS alarm data.
9.11.7.2. The system must detect and report intentional and unintentional jamming.
9.11.7.3. Data transmission subsystems using radio frequency methods must transmit on one or more of the frequencies within the specified band. These transmissions must not interfere with any other IDS components or electronic systems nearby. When using different data transmission links they must be compatible with each other.
9.11.7.4. The system must transmit alarms sent by non-hardwire links even when they occur during "off-air" periods caused by maintenance or failure.
9.11.8. Radio Frequency Link Compatibility. Data transmission subsystems using radio frequency methods must transmit on one or more of the frequencies within the specified band.
These transmissions must not interfere with other IDS components or any electronic components within the area. Examples include, but are not limited to, electric circuits, motors, transformers, ignition systems, heating sources, static, weather, and other radio frequency signals.
9.11.9. Polling Systems. Radio communication data links use a half-duplex supervised polling system specifically designed for alarm data transmission. They display the result of polling queries only when a failure occurs. Polling response time and transmission data rate, data error rate, and equipment reliability must not degrade overall IDS alarm annunciation time and
Probability of Correct Annunciation.
9.11.10. Protecting Radio Frequency Data Transmission Equipment. Units will ensure radio communication data links use a half or full duplex supervised polling system specifically designed for alarm data transmission and display the result of polling queries only when a
AFI31-101 25 MARCH 2020 145
failure occurs. Radio frequency alarm data transmission equipment, including repeaters, must be protected at the same level of security given to the remaining alarm data communications network. Units will ensure polling response time and transmission data rate, data error rate, and equipment reliability do not degrade overall IDS alarm annunciation time and probability of correct annunciation . (T-3).
9.12. Protection of Badge Enrollment Systems. Enrollment systems operator stations must be tamper proof, protected by data-at-rest and data-in-transit encryption, and include line supervision.
(T-1). Enrollment subsystem servers and operator systems supporting SCIFs and SAPFs shall be protected in accordance with ICS 705-1 and the IC Tech Specs.
9.13. Alternate Power Supplies. IDS components requiring a primary power source such as commercial power must also have an alternate power source using stand-by generators and/or battery backup. closed-circuit television and perimeter lighting components are not required to have battery backup.
9.13.1. Batteries. Batteries must maintain satisfactory operation of sensors and annunciation equipment for a minimum of 8 hours.
9.13.2. Switchover. Switchover to alternate power sources must ensure uninterrupted operation. The annunciator must display the switchover as exactly that, and not register it as an intrusion alarm. Alarm panels will report an “AC Power Loss” alarm, or similar upon loss of primary power.
9.13.3. Low-Battery Message. All annunciators and data transmission subsystem components must transmit a "low-battery" message before their functions degrade. This requirement also applies to exterior and interior sensors having this capability. Low-battery messages must display on all primary annunciators, remote annunciators, hand-held annunciators, and hand-held monitors used. Some exterior and interior sensor components generate sporadic alarms due to low power conditions.
9.14. Relocatable Sensors. Ideally, at deployed locations wherever practical, the AF uses sensors that can be relocated instead of fixed or permanent-fixed sensors. Portable components are to be designed to allow for quick assembly and configuration without sophisticated tools or support equipment. These sensors must meet the IDS requirements in this chapter.
9.14.1. Hand-Held Annunciators s. Hand-held annunciatorss are portable sensor alarm data transceivers that provide the same basic functions as primary or remote annunciators, and are used primarily with relocatable sensor systems in support of deployed PL resources. When used as the primary annunciator, hand-held annunciators must meet the requirements stated above for primary annunciators. Exception: hand-held annunciators do not require area display maps. Additionally, hand-held annunciators used as a primary annunciator must have the following features and capabilities:
9.14.1.1. Operate for a minimum of 12 hours on a single charge.
9.14.1.2. Operate from a vehicle 12- or 24-volt charging system, if necessary.
9.14.1.3. Not interfere with other base communication systems.
9.14.2. Hand-Held Monitors. Mobile SF response elements or fixed security posts use these portable alarm data receivers to enhance alarm response capabilities. Note: Hand-held
146 AFI31-101 25 MARCH 2020
monitors may not be used to perform the functions of primary, remote, or hand-held annunciators.
9.15. Immediate Visual Assessment. All permanent restricted areas must employ an IDS concept of operations that provides Immediate Visual Assessment of exterior alarms. (T-3). SF perform assessment in near-real time to determine the cause of an alarm and initiate an appropriate response. Note: Near-real time is defined as that period of time between notification of an event, such as an alarm, and the assessment of the event. The time should be as close to instantaneous as possible.
9.15.1. Accomplishing Assessment or Surveillance. Assessment or surveillance is accomplished either by the IDS operator using electronic video imaging equipment or ID forces posted in the restricted area. Electronic imaging equipment provides assessment and surveillance functions which enable the operator to conduct visual observations during alarm and non-alarm situations. Any newly installed units (and any installed in the past with the capability), will ensure automatic display upon alarm activation and will be available for manual request by the operator. Video-playback will show a minimum of three to five seconds of pre and post alarm video to assist in determining the cause of the alarm. Systems utilizing radar are not considered sufficient for assessment, but may be used as detection devices.
9.15.1.1. Assessment. Assessment occurs when imagers that provide near real-time video coverage associated with an alarm condition or sensor activation are used. Operators utilize assessment devices to conduct Immediate Visual Assessment of alarmed sectors and direct response forces to potential threats within the area. Assessment devices can encompass analog or digital systems. Systems used for assessment may also be used for surveillance, if capable.
9.15.1.2. Surveillance. Surveillance occurs when imagers are used to provide near real-time video coverage not associated with alarm condition or sensor activation. Surveillance devices can encompass analog or digital systems.
9.15.2. SF Response. SF must be dispatched immediately when the IDS operator cannot determine the cause of an alarm via Immediate Visual Assessment or posted sentry. (T-3).
9.15.3. Protection of the Electronic Video Imaging Equipment is as follows:
9.15.3.1. Analog Systems. Where analog systems are used to conduct assessment or surveillance functions, protection from tampering, spoofing, bypassing or system sabotage must be provided when the image device is not located within the sensored area. (T-3).
Protect the equipment supporting the system’s capability (permanent junction boxes, field distribution boxes, cable termination boxes) by in-place sensors or installation of a switch that provides tamper indication to the operator before an intruder can gain physical access to the components and perform meaningful work.
9.15.3.2. Digital Systems. Where digital equipment is used to conduct assessment or surveillance functions, protection from tampering, spoofing, bypassing or system sabotage must be provided, regardless of where the image device is located. (T-3). Use of physical tampers or network activity monitoring software may be used to detect malicious activity.
If network activity monitoring software is used, it must immediately lock out any suspected compromised data ports and report as a tamper alarm through the ESS annunciator. (T-3).
If physical tamper switches are used, install a switch that provides a tamper indication to
AFI31-101 25 MARCH 2020 147
the operator before an intruder can gain physical access to the components and perform meaningful work.
9.16. Test and Turnover. Testing is subdivided into three phases. Phase I, II, and III testing are based on the Electronic Security Equipment (ESE) Master Installation Acceptance Test and in accordance with the most current version of Test Plan. AFLCMC/HBU typically conducts Phase
I and Phase II testing, while units conduct Phase III testing. Units can obtain the current test plan
(TP-0023) from AFLCMC/HBU, 3 Eglin Street, Bldg. 1612, Hanscom AFB, MA 01731-2100 via email at AFLCMC.HBU.workflow@us.af.mil.
9.16.1. Phase I Testing. Phase I testing must demonstrate that all installed equipment and components are performing according to system specifications and operational requirements.
(T-1). AFLCMC/HBU and the base organization responsible for the IDS conduct this test phase. For PL-4 IDS testing, base organizations will coordinate with AFSFC. Phase I acceptance testing consists of the following:
9.16.1.1. Intrusion tests.
9.16.1.2. Tamper tests.
9.16.1.3. Correct annunciation test.
9.16.1.4. Correct assessment test.
9.16.1.5. AC power loss test.
9.16.1.6. Line supervision test.
9.16.1.7. Sensor system self-tests, where capable.
9.16.1.8. Access control, where capable.
9.16…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .