SOW_-_DRAFT_to_Industry_20190308.pdf
PDF 206 KB Posted
- Attached to
- FPS4 Synopsis of Proposed Contract Action Federal contract opportunity
- Solicitation number
- FA873019R0005
About this file
This document provides draft request for proposal documents for the Force Protection Site Security System Solutions contract. Key details include that the contract will provide acquisition, upgrade and sustainment of physical and electronic security systems including fixed site electronic security systems, tactical security systems, delay/denial systems and counter-small unmanned aerial systems. The statement of work outlines the scope of work to include design, procurement, installation, integration, testing, delivery and sustainment of these security systems. Responses to the draft request for proposal documents are due by March 15, 2019. The agency involved is the Department of the Air Force Materiel Command Lifecycle Management Center located at Hanscom Air Force Base.
DRAFT FPS4 SOW
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FPS4BidderLibraryRequestForm.pdf | ||
| Section_L_-_DRAFT_to_Industry_20190308.pdf | ||
| Section_M_-_DRAFT_to_Industry_20190308.pdf | ||
| DRFP_CRM_FINAL_for_Industry.pdf | ||
| FPS4_RFP_Document_Review_v2.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FA8730-19-R-xxxx, Attachment #, Page 1
Force Protection Site Security System Solutions (FPS4)
Statement of Work (SOW)
Attachment xx xx March 2019
FA8730-19-R-xxxx, Attachment #, Page 2
TABLE OF CONTENTS
Page
1.0 INTRODUCTION
2.0 PURPOSE
2.1 Scope
2.2 Objectives
2.2.1 Design and Integration of Prime Mission Equipment and Systems
2.2.2 Equipment Purchase, Assembly/Manufacture, Delivery and Test
2.2.3 Systems Engineering
2.2.4 Support and Sustainment
2.2.5 Developmental Projects, Demonstrations, and Studies
2.2.6 Management
3.0 APPLICABLE DOCUMENTS
3.1 Government Specifications and Security Documents
3.2 Commercial Standards and Specifications
3.3 Other Government Documents
4.0 REQUIREMENTS
4.1 General
4.2 Detailed Tasks
4.2.1 Site Survey, Pre-Installation, Installation, and Integration Activities
4.2.2 Quality
4.2.3 Cybersecurity (DoD Cybersecurity Assessment and Authorization [A&A])
4.2.4 Sustainment Support …
4.2.5 Management…………………………...…………………………………………….15
4.2.6 Program Security
4.3 Travel Requirements………………………………………………………………………….19
5.0 ACRONYM LISTING…………………………………………………………………………….20
FA8730-19-R-xxxx, Attachment #, Page 3
1.0 INTRODUCTION
The Force Protection Site Security System Solutions (FPS4) contract provides for acquisition, upgrade and sustainment of a family of physical and electronic security systems including:
• Fixed site Electronic Security Systems (ESS), including, but not limited to:
o Intrusion Detection Systems (IDS) o Access Control Systems (ACS) o Automated Entry Control Systems (AECS) o Surveillance Systems
• Tactical security systems
• Delay/denial systems
• Counter-small Unmanned Aerial Systems (C-sUAS)
These systems provide capabilities to support and enhance security and assist Security Forces (SF) in protecting assets and personnel at fixed and tactical, nuclear and non-nuclear sites around the world. The goal is to provide SF with the capability to "See First, Understand First, and Act First."
Fixed site ESS projects are driven by unit requirements and are tailored to fit the requirements of assigned resources at each site where they are installed. These projects may be as simple as purchasing equipment to satisfy a user's needs or as complex as providing for design, installation, test, and sustainment of a system of hardware and software to protect an entire base. They provide an electronic means to accomplish area intrusion detection, alarm reporting and display, remote alarm assessment, access control, automated entry control, surveillance and alert SF to intrusions to enhance resource and facility protection. Fixed site systems are delivered as permanent security systems to protect high priority assets, with a focus on Protection Level (PL) 1 (nuclear and non-nuclear), 2, 3, and 4 resources such as aircraft, munitions, command and control centers, etc.
The FPS4 contract also provides for acquisition, upgrade and sustainment of tactical security systems to achieve a rapidly deployable, re-locatable and integrated security system designed as a "first-in" capability for a variety of force protection missions.
The FPS4 contract will also provide for acquisition, upgrade and sustainment of delay/denial systems.
The FPS4 contract will also provide for installation, upgrade and sustainment of C-sUAS systems. C-sUAS projects on the FPS4 contract will involve integrating and installing C-sUAS Government Furnished Equipment (GFE) into the Government-provided C-sUAS Command, Control and Display Equipment (CCDE), as well as providing the necessary infrastructure to accomplish this integration and installation work.
2.0 PURPOSE
This SOW describes the scope of effort that may be required by the Contractor via Delivery Orders (DOs) issued under the FPS4 contract. In support of the warfighter, the intent is to rapidly acquire and provide SF personnel with mission-critical, integrated security systems and equipment that neutralize or mitigate anticipated threats. The SOW also includes other related efforts such as services critical to system sustainment; identification, upgrade, insertion of technology; special studies, analyses and demonstrations; equipment qualification; and other efforts that support the acquisition and sustainment of a family of physical and electronic security systems including fixed site ESS, tactical security systems, delay/denial systems, and C-sUAS.
FA8730-19-R-xxxx, Attachment #, Page 4
2.1 Scope: The scope of this effort includes all activity and work required to design, procure, install, integrate, test, deliver, and sustain:
• Physical and electronic security systems including but not limited to:
o Fixed site ESS
IDS
AECS
Surveillance Systems
ACS
o Tactical systems o Delay/denial devices o C-sUAS
This scope also includes, but is not limited to:
• Contractor program management and subcontractor oversight
• Systems engineering
• System design and development
• Purchase of Commercial Off-the-Shelf (COTS) and ancillary equipment
• Necessary installation of, or upgrades to, supporting infrastructure
• Installation and systems integration of Contractor-provided equipment and/or infrastructure and
Government Furnished Property/Equipment (GFP/GFE) and infrastructure
• Support (upgrade, repair or replacement) of applicable GFP/GFE
• Preparation of technical orders and/or supplements to COTS equipment manuals
• Contractor Verification Testing (CVT)
• Technical Manual/Technical Order validation
• Equipment qualification testing
• COTS production qualification acceptance testing
• Contractor training of site and support personnel
• Contractor support of Government testing
• Interim Contractor Support (ICS) of installed systems
• Contractor Logistics Support (CLS) and/or operational readiness support of tactical and fixed site systems worldwide
• Special studies, analyses, and demonstrations
• Technical and other effort necessary to support system/project acquisition and/or sustainment
• Technology identification, upgrade, and insertion
• Acquisition of systems and associated support for Foreign Military Sales (FMS) customers and any other Government agency (such as the Department of State [DoS], Department of Energy [DoE]) or other DoD agencies/services, if ordered
• Other acquisition and/ or sustainment support as required
Other associated security capabilities such as fencing, lighting, power and ground communications systems, and related infrastructure improvements may also be required. The Contractor shall also improve security capability during the life of the contract through the identification and replacement of obsolete or end-of-life COTS equipment, and/or the development and insertion of technology to meet diverse and emerging security requirements. In doing so, the Contractor shall ensure that state-of-the-art equipment is available for the myriad of force protection missions.
2.2 Objectives: Any DO issued under this contract may contain any number and combination of the
FA8730-19-R-xxxx, Attachment #, Page 5 items listed below, utilizing sound systems engineering principles and management practices.
2.2.1 Design and Integration of Prime Mission Equipment and Systems: The Contractor may be required to design, acquire, install, integrate, test, deliver, sustain and/or upgrade or reconfigure fixed site ESS, tactical (such as TASS), delay/denial systems, or C-sUAS and equipment that meet the physical security compliance requirements of applicable DOs as defined in the DO SOW, Performance Work Statement (PWS), specification, or any other applicable DO documents and instructions. In the performance of this work, the contractor may also perform related tasks including, but not limited to, design, upgrade, construction, installation and integration of necessary supporting infrastructure, and site cleanup and restoration.
2.2.2 Equipment Purchase, Assembly/Manufacture, Delivery and Test
2.2.2.1 COTS/Government-off-the-Shelf (GOTS) Equipment: The Contractor may be required to procure non-developmental items (e.g. COTS and GOTS) equipment to support DO requirements.
Fixed Site ESS equipment may consist of already proven COTS equipment from the Air Force Security Forces Center (AFSFC) Approved Equipment List (AEL) (hereafter, simply referred to as “AEL”), or COTS equipment proposed by the Contractor. If the Contractor proposes non-AEL equipment, the Contractor shall qualify (test, or otherwise verify) the equipment to meet specified performance requirements and shall prove (through test or other verification methods) that the equipment is "certifiable" for use. Should non-AEL equipment be proposed, the contractor shall submit Cybersecurity Assessment and Authorization documentation as described in paragraph 4.2.3.
Tactical security system, delay/denial system and C-sUAS simple equipment purchases or equipment purchases to support these types of projects may consist of COTS or GOTS equipment and associated COTS ancillary equipment as may be required by the DO.
2.2.2.2 COTS/GOTS Test/Verification: With the exception of items on the AEL, the Contractor shall test or otherwise verify subsystems, equipment and components to validate that all systems, subsystems and equipment meet applicable performance specifications.
2.2.2.3 Item Unique Identifiers (IUIDs): The Contractor shall comply with the requirements of Defense Federal Acquisition Regulation Supplement (DFARS) 211.274, Item Identification and Valuation Requirements in the establishment and reporting of applicable IUID equipment.
2.2.2.4 Manufacturing Process Control: The Contractor shall perform manufacturing process control and quality control for any parts or equipment manufactured by the Contractor. The Contractor shall ensure that subcontractors or vendors implement sound manufacturing processes and quality control to ensure that delivered systems, subsystems and components meet specified DO performance and quality requirements.
2.2.2.5 Purchasing: The Contractor shall perform and implement sound material planning, purchasing, expediting, and control processes and activities to purchase or acquire required equipment, components, parts and software infrastructure materials. This includes ancillary components, parts and material that are required to comply with DO performance and schedule requirements.
2.2.2.6 Production Control: The Contractor may be required to perform production control tasks necessary to fabricate, manufacture, assemble, test and integrate equipment, components, parts and software as applicable. The Contractor may be required to also accomplish staging, packaging, packing, delivery and Government acceptance of systems and equipment required to satisfy DO requirements.
FA8730-19-R-xxxx, Attachment #, Page 6
2.2.3 Systems Engineering: The Contractor shall provide systems engineering and systems engineering management to continually ensure that:
• Applicable DO performance requirements are met
• Applicable designs are feasible and sound
• System integration and installation meet DO requirements
• System reliability, availability and maintainability is evaluated
• Delivered systems/equipment can be supported or sustained
2.2.3.1 System Architecture
2.2.3.1.1 System Architecture Design: The Contractor may be required to design security system installations at designated sites in accordance with (IAW) DO requirements. The Contractor shall also ensure that all systems, subsystems, equipment and/or components are designed IAW DoD Architecture Framework (DoDAF) guidance.
2.2.3.1.2 Security Equipment Integration Working Group (SEIWG): The Contractor may be required to support the DoD SEIWG through performing DoDAF-compliant studies, analyses, and producing architecture products IAW applicable DO requirements.
2.2.3.2 System Design
2.2.3.2.1 Design: The Contractor may be required to develop and prepare applicable equipment/sub-system/system/site designs for Government review and approval. These designs shall include, but not be limited to, equipment/sub-system/system design, infrastructure design, drawings, design/configuration of specific equipment or components, and site design. The Contractor shall also design systems that comply with DoDAF guidance, frequency spectrum requirements and installation siting criteria.
2.2.3.2.2 Design Reviews: The Contractor may be required to conduct design reviews, which require the preparation of design drawings and any associated documentation. The Contractor may be required to also accomplish tasks in support of design reviews, such as preparing agendas and recording and distributing meeting minutes.
2.2.3.2.3 Engineering Change Proposals (ECPs): Changes to system equipment that affect form, fit, function, or interface, shall be submitted to the Government as Class I ECPs. Class II ECPs do not affect form, fit, function or interface, and shall be submitted to the Government as advisory ECPs only. Class II ECPs do not require Government approval, unless the Government requests further information or justification.
2.2.3.2.4 Deviations: Contractor requests to deviate from Government standards, requirements, or regulations shall describe which major components are affected and shall include the rationale or justification for the deviation, as well as any impact on cost, schedule, performance or supportability.
2.2.3.2.5 Test/verification: The Contractor may be required to prepare installation test/verification plans and procedures, execute these plans and procedures, validate technical manuals, support Government test/verification activities to include documenting and correcting problems that are identified during testing, and perform systems development test and evaluation in accordance with specific DO requirements.
FA8730-19-R-xxxx, Attachment #, Page 7
2.2.3.2.6 Turnover: The Contractor may be required to prepare and deliver “as-built” drawings and documentation that will facilitate future sustainment, maintenance and modification of the system.
2.2.3.2.7 Regulatory Assistance: The Contractor may be required to assist the Government by providing information that is necessary to prepare Cybersecurity Assessment and Authorization (A&A) packages. In the event that new Radio Frequency (RF) Items are introduced, the Contractor shall support the Air Force Frequency Allocation process by submitting an updated DoD Directives Division (DD) Form 1494 within 45 days of DO award.
2.2.4 Support and Sustainment: As required by the Government the contractor may be required to provide sustainment support including ICS or CLS as part of a project DO or a separate DO. This support includes, but is not limited to, the following items:
• Supply chain and inventory management,
• Technical or commercial manuals, data and troubleshooting guides
• Organizational level training and training materials (operations, maintenance and system administration)
• Preventative maintenance and inspection
• On-site repair
• Management of repair or replacement of failed items depot level repair through the Original
Equipment Manufacturer (OEM)
• Management of warranties
• Technical support
• Software support
• Engineering analysis for security systems and equipment when requested, to include, but not limited to, the identification and resolution of reliability, availability, maintainability and technology obsolescence issues
• Resident field engineering, maintenance and/or operations system administration support
• Detailed analysis and/or data regarding Reliability, Availability, and Maintainability (RAM) of an installed system or its individual components
• Maintain the Cybersecurity configuration of the system IAW the System Security Plan (SSP).
2.2.5 Developmental Projects, Demonstrations, and Studies
2.2.5.1 Technical Studies: When directed by the Government, the Contractor may be required to perform system/project development efforts; conduct or support investigations; conduct testing;
conduct or perform demonstrations; and conduct special studies and/or technical analyses including but not limited to analysis of industrial and technological trends, advancements, or limitations, and their impact upon systems that are covered by the FPS4 contract. These efforts may include:
• Engineering analyses and studies
• Demonstrations
• Design & development
• Design reviews
• Insertion of hardware and software upgrades (including development and systems retrofit)
• Developing, upgrading, or assistance with the development of systems or interface specifications, architectural views, Government-provided Interface Control Documents, and other engineering documentation
FA8730-19-R-xxxx, Attachment #, Page 8
• Test and evaluation and deficiency reporting using Deficiency Reporting (DR) system for tracking and resolution of deficiencies that implements processes and methodologies consistent with Technical Order (TO)-00-35D-54 [United States Air Force (USAF) Deficiency Reporting and Investigating System] and allows portability of data into Government Joint Deficiency Reporting System
2.2.5.2 Technology Insertion: When directed by the Government, the Contractor shall:
• Provide, develop and/or integrate various hardware and software upgrades for FPS4 and/or legacy site security systems
• Utilize technology insertion as a means to add new capabilities
• Demonstrate that newly developed or upgraded components are interoperable, interchangeable, and backwards compatible
• Assist the Government in preparing Cybersecurity Assessment and Authorization (A&A)
Information Assurance (IA) Certification and Accreditation (C&A) packages
2.2.5.3 Equipment Qualification: If required, the Contractor will qualify new equipment for integration into systems, including:
• Providing a testing/verification capability that will be used to plan and perform tests or other methods of verification
• Reporting test/verification results
• Supporting and participating in Government Combined Test Force (CTF) activities
• Performing COTS qualification testing (including the development of test plans and procedures)
• Performing engineering analysis, to include market research if required, providing recommendations, and conducting/participating in test efforts to qualify and accept new COTS items either on separate DO or as part of a design/install DO under the FPS4 contract
• Deficiency Reporting (DR) using DR system for tracking and resolution of deficiencies that implements processes and methodologies consistent with TO-00-35D-54 (USAF Deficiency Reporting and Investigating System) and allows portability of data into Government Joint Deficiency Reporting System
• Assisting the Government in preparing Cybersecurity Assessment and Authorization (A&A) Information Assurance (IA) Certification and Accreditation (C&A) packages
2.2.6 Management
2.2.6.1 Effective Management: The Contractor shall use effective processes to direct and manage DO efforts, including direction and control of subcontractors.
2.2.6.2 Working Relationships: The Contractor shall establish a working relationship with the Government and other applicable contractors that fosters open communication and an atmosphere of cooperation. The Contractor shall also communicate with the Government regarding site status, issues and activities that may impact a project’s operational, cost and schedule requirements.
2.2.6.3 Risk Management: The Contractor shall apply sound risk management principles for the duration of the contract.
2.2.6.4 Personnel Qualification: The Contractor shall provide qualified personnel, and shall also
FA8730-19-R-xxxx, Attachment #, Page 9 ensure that subcontractor personnel are qualified to perform the work that they are hired to complete.
2.2.6.4.1 Cybersecurity Personnel Qualifications: Specific to cybersecurity, personnel involved in network design, administration, and/or maintenance shall have the following qualifications:
• Per DoD 8570.01-Manual, all personnel involved in network design shall have Information Assurance Technician Level III certification. In addition, network design personnel shall have specific OEM certifications for the type of equipment to be utilized (such as CCNP or equivalent).
• Per DoD 8570.01-Manual, installation/maintenance personnel having administrative credentials for the system shall have Information Assurance Technician Level II certification.
These personnel shall have OEM certifications for administration of the equipment utilized (such as CCNA or equivalent).
• Installation/maintenance personnel shall have OEM certification for FPS4 systems that are being installed or maintained
2.2.6.5 Purchasing: The Contractor shall utilize an ordering process that minimizes buying agency involvement and time to order and receive products.
2.2.6.6 Internal Management: The Contractor shall implement and utilize internal management processes to plan, schedule, budget, and monitor, manage and report cost, schedule, and technical performance.
3.0 APPLICABLE DOCUMENTS
3.1 General
The following documents are representative of the types of documents that may be cited in a DO and are applicable to this SOW to the extent specified herein. While every effort has been made to ensure the completeness of this list, the Contractor shall meet all specified requirements in this SOW and the specification whether or not they are listed in this section.
Where not specifically cited below, the contractor is responsible for compliance with applicable federal, state, local and base codes and regulations, as well as applicable base and industry architectural and construction standards during performance of this DO.
3.2 Government Documents
3.2.1 Specifications, Standards, and Handbooks: The following specifications, standards, and handbooks form a part of this document to the extent specified herein. Use the most current available version of the listed documents at the time of delivery order award.
ESE-SIT-0001 Standardized Electronic and Security Equipment Siting and Design Guidance for Permanent Installations
(Copies of above documents are available from AFLCMC/HBU, 3 Eglin Street, Bldg. 1612, FA8730-19-R-xxxx, Attachment #, Page 10
Hanscom AFB, MA 01731-2100.)
ITAR International Traffic and Arms Regulations
(Copies of above document are available at: http://www.ecfr.gov/cgi-bin/text-idx?gp=&SID=bd869596658d188a67e981389890d49c&mc=true&tpl=/ecfrbrowse/Title22/22CI subchapM.tpl)
MIL-HDBK-61 Configuration Management
Guidance
(Copies of above document are available at: http://www.product-lifecycle-management.com/mil-hdbk-61a-00.htm)
MIL-STD-61 DoD Standard Practices for
Configuration Management Guidance
MIL-STD-100 DoD Standard Practices for
Engineering Drawing
MIL-STD-129 DOD Standard Practice Military
Marking for Shipment and Storage
MIL-STD-130 DOD Standard Practice Identification
Marking of US Military Property
MIL-STD-461 DOD Standard Practice
Requirements for the Control of Electromagnetic Interference Characteristics of Subsystems and Equipment
MIL-STD-810 DOD Standard Practice
Environmental Engineering Considerations and Laboratory Tests
MIL-STD-881 DOD Standard Practice for Work breakdown Structure for Materiel Items
MIL-STD-882 DOD Standard Practice for System
Safety http://www.ecfr.gov/cgi-bin/text-idx?gp=&SID=bd869596658d188a67e981389890d49c&mc=true&tpl=/ecfrbrowse/Title22/22CIsubchapM.tpl http://www.ecfr.gov/cgi-bin/text-idx?gp=&SID=bd869596658d188a67e981389890d49c&mc=true&tpl=/ecfrbrowse/Title22/22CIsubchapM.tpl http://www.ecfr.gov/cgi-bin/text-idx?gp=&SID=bd869596658d188a67e981389890d49c&mc=true&tpl=/ecfrbrowse/Title22/22CIsubchapM.tpl http://www.product-lifecycle-management.com/mil-hdbk-61a-00.htm http://www.product-lifecycle-management.com/mil-hdbk-61a-00.htm
FA8730-19-R-xxxx, Attachment #, Page 11
MIL-STD-1472 DOD Standard Practice Design Criteria Standard for Human Engineering
MIL-STD-2073-1 DOD Standard Practice Standard
Practice for Military Packaging
(Copies of above documents are available at: http://everyspec.com/)
NIST Special Publication National Institute of Standards and 800-53, Revision 4 Technology, U.S.
Department of Commerce, Security and Privacy Controls for Federal Information Systems and Organizations, Information Security, SA-12
(Copies of above document are available at: http://www.nist.gov/itl/csd/soi/fisma.cfm)
UFC 3-301-01 Unified Facilities Criteria for
Structural Engineering
UFC 3-400-02 Unified Facilities Criteria for
Design, Engineering Weather Data
UFC 3-260-01 Unified Facilities Criteria for Airport and Heliport Planning and Design
UFC 4-021-02NF Unified Facilities Criteria for
Security Engineering Electronic Security Systems
(Copies of above documents are available at: https://www.wbdg.org/ffc/dod/unified-facilities-criteria-ufc)
UFGS Various Unified Facilities Guide
Specifications
(Copies of above documents are available at: https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs) http://everyspec.com/ http://www.nist.gov/itl/csd/soi/fisma.cfm https://www.wbdg.org/ffc/dod/unified-facilities-criteria-ufc https://www.wbdg.org/ffc/dod/unified-facilities-criteria-ufc https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs
FA8730-19-R-xxxx, Attachment #, Page 12
NTIA “Red Book” National Telecommunications and Information Administration Manual of Regulations and Procedures for Federal Radio Frequency. Chapter
(Copy of above document is available at: http://www.ntia.doc.gov/page/2011/manual-regulations-and-procedures-federal-radio-frequency-management-redbook)
3.2.2 Other Government Documents, Drawings, and
Publications. The following other Government documents, drawings, and publications, of the current revision level shown, form a part of this document to the extent specified herein. Use the most current available version of the listed documents at the time of delivery order award.
DEPARTMENT OF DEFENSE
DODI 3020.37 Continuation of Essential DoD Contractor Services During Crisis
DoDI 5210.83 DoD Unclassified Controlled
Nuclear Information
DoDI 8510.01 DoD Risk Management Framework
(RMF) for DoD Information Technology
DoDI 8910.1 DoD Information Collecting and reporting
DoDM 5200.01-V3 DoD Information Security Program:
Protection of Classified Information
DoD S-5210.41 DoD Nuclear Weapon Security
Program
DoD 5220.22 National Industrial Security Program
Operating Manual
DOD 8570.01- Information Assurance (IA)
Workforce Improvement Program
(Copies of above documents are available at: http://www.dtic.mil/whs/directives/) http://www.ntia.doc.gov/page/2011/manual-regulations-and-procedures-federal-radio-frequency-management-redbook http://www.ntia.doc.gov/page/2011/manual-regulations-and-procedures-federal-radio-frequency-management-redbook http://www.dtic.mil/whs/directives/
FA8730-19-R-xxxx, Attachment #, Page 13
AF LIFE CYCLE MANAGEMENT CENTER (AFLCMC), HANSCOM AFB
IBDSS/ESE Security Classification Guide Integrated Base Defense Security
Classification Guide System /Electronic Security Equipment (IBDSS/ESE) Security Classification Guide
Classification Guide Nuclear Weapons Security program
Classification Guide
Non-Nuclear IDS AEL Non-Nuclear Intrusion Detection
System Approved Equipment List
Nuclear IDS AEL Nuclear Intrusion Detection System
Approved Equipment List
Supply Chain Risk Integrated Base Defense Security
System Program Supply Chain Risk Management (SCRM) Plan
IBDSS SSP Integrated Base Defense Security
System Security Plan
SF Guide Security Forces Guide to
Cybersecurity for IBDSS
IDS Performance Specs Intrusion Detection System
Performance Specifications
TASS Performance Specs Tactical Automated Security System
(AN/USQ-139) Performance Specifications
(Copies of above documents are available from AFLCMC/HBU, 3 Eglin Street, Bldg. 1612, FA8730-19-R-xxxx, Attachment #, Page 14
AIR FORCE
AFI 31-101 Integrated Defense
(Copies of the above documents are available from AFLCMC/HBU, 3 Eglin Street, Bldg. 1612, AFI 23-101 Air Force Materiel Management
AFI 33-210 Air Force Certification and Accreditation (C&A) Program
(AFCAP)
AFI 63-101/20-101 Integrated Life Cycle Management
AFI 23-101 Air Force Material Management
AFH 23-123 Air Force Equipment Management
AFMAN 23-122 Materiel Management Procedures
AFMAN 24-204 Preparing Hazardous Materials
(HAZMAT) for Military Air Shipments
AFPAM 63-113 Program Protection Planning for Life
Cycle Management
AFPD 31-1 Integrated Defense
AFMAN 31-108 Air Force Nuclear Weapons Security
Manual
AFI 31-108 Air Force Nuclear Weapons Security
Program
(Copies of the above documents are available at: http://www.e-publishing.af.mil/index.asp)
T.O. 00-35D-54 Technical Manual USAF Deficiency
Reporting, Investigation, and Resolution
T.O. 00-5-1 AF Technical Order System http://www.e-publishing.af.mil/index.asp
FA8730-19-R-xxxx, Attachment #, Page 15
T.O. 31S9-4-99-1 Tactical Automated Security System (TASS) Technical Manual:
AN/USQ-139, Operational and Maintenance Instructions with Illustrated Parts Breakdown
(Copies of above document are available through:
http://www.tinker.af.mil/Portals/106/documents/AFD-151002-011.PDF)
ICS 705-1 Intelligence Community Standard
Number 705-1: Physical Security Standards for Sensitive Compartmented Information Facilities
ICS 705-2 Intelligence Community Standard
Number 705-2 Standards for the Accreditation and Reciprocal Use of Sensitive Compartmented Information
IC Tech Spec-ICD/ICS 705 Sensitive Compartmented
Information Facility (SCIF) for ICD/ICS 705 Security Guidance
(Copy of above document is available from AFLCMC/HBU, 3 Eglin Street, Bldg. 1612, 29 CFR 1910 Occupational Safety and Health, Safety and Health Regulations for General Industry
29 CFR 1926 Occupational Safety and Health, Safety and Health Regulations for Construction
(Copies of above document are available at: https://www.osha.gov/law-regs.html )
3.2.3 COMMERCIAL STANDARDS AND SPECIFICATIONS. The following referenced items, of the current revision listed below, form a part of this document to the extent specified herein.
Use the most current available version of the listed documents at the time of delivery order award.
NFPA 70 National Fire Protection Association, National Electrical Code http://www.tinker.af.mil/Portals/106/documents/AFD-151002-011.PDF https://www.osha.gov/law-regs.html
FA8730-19-R-xxxx, Attachment #, Page 16
NFPA 101 National Fire Protection Association, Life Safety Code
(Copies of above document are available at: https://www.nfpa.org/Codes-and-Standards/All- Codes-and-Standards/List-of-Codes-and-Standards)
IEEE 142 Grounding of Industrial and
Commercial Power Systems
IEEE C62.36 Standard Test Methods for Surge
Protectors used in Low Voltage Data, Communications, and Signaling Circuits
IEEE C62.41.2 Recommended Practice on
Characterization of Surges in Low Voltage (1000 Volts and less) Alternating Current (AC)
IEEE 1100 Powering and grounding Sensitive
Electronic Equipment
IEEE 12207.1 Guide for Information Technology –
Software Life Cycle Process – Life Cycle Data
IEEE 12207.2 Guide for Information Technology –
Software Life Cycle Process – Implementation Considerations
(Copies of above document are available at: https://standards.ieee.org/standard/)
EIA/ECA-310 Cabinets, Panels, Racks and
Associated Equipment
EIA-649 National Consensus Standard for
Configuration Management (Adopted by DoD, 1 Feb 99)
(Copies of above document are available through: http://standards.sae.org/eia649b )
UL 96 Underwriter’s Laboratories
Lightning Protection Components https://standards.ieee.org/standard/)
FA8730-19-R-xxxx, Attachment #, Page 17
UL 96A Underwriter’s Laboratories Installation Requirements for Lightning Protection Systems
UL 913 Underwriter’s Laboratories
Intrinsically Safe Apparatus and Associated Apparatus for Use in Class I, II, III, Division I, Hazardous (Classified) Locations
(Copies of above document are available at: https://standardscatalog.ul.com/ )
NEMA 250 Enclosures for Electrical Equipment
(Copies of above document are available at: https://www.nema.org/Standards/Pages/Enclosures-for-Electrical-Equipment.aspx)
ASME Y14.24 American Society of Mechanical
Engineers Standard for Types and Applications of Engineering Drawings
ASME Y14.35 American Society of Mechanical
Engineers standard for Revisions of Engineering Drawings and Associated Documents
ASME Y14.100 American Society of Mechanical
Engineers standard for Engineering Drawing practices
(Copy of above document is available at: https://www.asme.org/shop/standards )
SAE AS5553A SAE International Standard, AS5553, Counterfeit Electronic Parts: Avoidance, Detection, Mitigation, and Disposition
(Copy of above document is available at: http://standards.sae.org/as5553/) https://standardscatalog.ul.com/ https://www.nema.org/Standards/Pages/Enclosures-for-Electrical-Equipment.aspx https://www.nema.org/Standards/Pages/Enclosures-for-Electrical-Equipment.aspx https://www.asme.org/shop/standards http://standards.sae.org/as5553/
FA8730-19-R-xxxx, Attachment #, Page 18
ANSI-EIA-649 National Consensus Standard for Configuration Management
(Copy of above document is available at: http://standards.sae.org/eia649b/)
4.0 REQUIREMENTS
4.1 General: The Contractor shall accomplish each DO’s tasks IAW applicable codes, specifications, standards, and security documents as specified therein. DO tasks will typically fall under the general areas outlined in Section 4.2 but may differ depending on specific customer requirements.
4.2 Detailed Tasks: Each DO may require Contractor effort or Contractor support for Government efforts in the following areas:
4.2.1 Site Survey, Pre-Installation, Installation, and Integration Activities
4.2.1.1 Site Survey: After a DO is awarded, the Contractor shall conduct a thorough and comprehensive post-award site survey to gather all information necessary to complete designs, installation plans, and specifications. At a minimum, this survey shall include validation of site conditions and system requirements, identification of potential obstacles that could affect design or construction, and evaluation of the suitability of GFE/GFP for use/integration into the system. The Contractor shall immediately notify the Government of any deficiencies or potential problems that it identifies during the post-award site survey.
4.2.1.2 Pre-Installation Activities / Production Qualification and Acceptance: When proposed by the Contractor and approved by the Government as part of a DO, the Contractor shall acquire COTS equipment that is not on the AEL. The Contractor will then conduct production acceptance qualification testing to verify that equipment performance meets specified requirements. The Government will witness and participate in production acceptance qualification testing. The Contractor shall prepare applicable test/verification plans, procedures and reports for Government approval, and, as required, shall support and participate in a Government-led CTF activity to validate equipment performance. The contractor shall use a DR system for tracking and resolution of test deficiencies that implements processes and methodologies consistent with TO-00-35D-54 (USAF Deficiency Reporting and Investigating System) and allows portability of data into the Government Joint Deficiency Reporting System. Any deficiencies that are identified during production acceptance qualification testing/verification shall be corrected prior to equipment certification. Finally, the contractor may be required to submit Cybersecurity Assessment and Authorization documentation as described in paragraph 4.2.3. Once equipment is certified for use, it can be installed to satisfy DO requirements.
4.2.1.3 Installation: The Contractor shall perform all tasks necessary to install supportable systems that comply with DO requirements. The installation phase will include work that is required to prepare and install the system as well as site infrastructure to support system installation, including repair/restoration of any associated GFP/GFE. Prior to the start of installation, the Contractor shall be responsible for obtaining all requisite site authorizations/permits (such as airfield access and construction permits, installation permits, base access permits, confined space clearances, etc.)
necessary to install the system. The contractor shall perform required installation(s) IAW a Government-approved design. Contractor installation shall include all system equipment, trenching, http://standards.sae.org/eia649b/
FA8730-19-R-xxxx, Attachment #, Page 19 cabling, wiring, junction boxes, grounding, foundations, infrastructure, communications, power, supports, and ancillary equipment required to provide a complete and usable system. The Contractor shall ensure that installation at the site is accomplished without impact to site operations. Finally, the Contractor shall restore all areas that are disturbed by installation to a condition at least equal to the condition that existed prior to the project.
4.2.1.4 System Test and Turnover: The Contractor shall verify that installed systems comply with all requirements by conducting a comprehensive CVT process for security system installations. The CVT process shall include:
• Preparation of test plans and procedures
• Validation of technical manuals
• Functional, operational and system-level testing of system performance and stability
• Documentation of test results
• On-site support during the Government Acceptance Test (GAT)
The Contractor shall also support Government Functional Configuration Audits (FCAs) and Physical Configuration Audits (PCAs) as directed by the Government.
4.2.2 Quality
4.2.2.1 Quality Control (QC) Process: The Contractor shall establish and maintain a comprehensive QC program, including the development and maintenance of a QC Plan (QCP) that shall document all aspects of QC functions. The Contractor shall conduct inspections during system installation and report its findings to the Government. The Contractor shall ensure the following as part of this process:
• All equipment and/or components have been installed according to the design, OEM instructions, system specifications, all applicable Air Force Instructions, and government siting criteria
• All supporting infrastructure has been installed IAW applicable UFC and UFGS criteria
• All work and workmanship are compliant with site-specific, local, state and federal construction codes and requirements
4.2.2.2 Vendor and Subcontractor QC Management: The Contractor shall ensure that QC requirements apply to subcontractors and vendors. The Contractor shall monitor supplier activity to ensure adherence to contractual requirements and applicable standards and procedures. The Contractor shall work with vendors and subcontractors to identify root causes of quality deficiencies, and shall take corrective actions for non-conforming items that fail to meet Government requirements or specifications.
4.2.3 Cybersecurity (DoD Cybersecurity Assessment and Authorization [A&A])
4.2.3.1 AEL Equipment Cybersecurity: The SSP for the specific FPS4 equipment implements DoD and AF Cybersecurity requirements. The applicable SSPs impose additional requirements in support of Cybersecurity. The Contractor shall comply with the SSPs applicable to this project and shall design the system in a manner that does not invalidate the Government Approval to Operate (ATO). The Contractor shall install the system in a configuration IAW Section 3: Tailored DISA STIG Configuration of the approved Annunciator, VMS or Radar Platform SSP Annex. The Government will provide, as GFI, the SSPs and Annexes applicable to the individual project.
FA8730-19-R-xxxx, Attachment #, Page 20
4.2.3.2 Non-AEL Equipment Cybersecurity: The Contractor shall prepare, submit, and update for Government review and approval, A&A documentation for any Contractor-recommended equipment not currently certified and listed on the AEL. Supporting documentation will be specified in the applicable DO and shall include but not be limited to documents such as: System Security Design Specifications (SSDS), Ports, Protocols and Services (PPS) requirements, Functional Requirements Traceability Matrices, Application and Security Requirements Security Technical Implementation checklists, Security Functional Test Plans & Procedures, security design requirements, security requirement Verification and Validation (V&V), sensitivity of the data being processed, identification of system vulnerabilities, and identification of existing and planned countermeasures. Additional documentation will include User Guides, Administrator Reference Guides, Software Description Documents, Interface Control Description Documents, Government approved Training Packages, etc.
The Contractor shall also participate in design reviews as required by the Government for review and approval of Cybersecurity designs. The Contractor shall plan for the provision of Contractor recommended equipment and software to the Government IDS test site to allow for testing of system updates.
4.2.3.2.1 Cybersecurity Controls: The Contractor shall identify and document the applicable Cybersecurity controls of the latest versions of CNSSI 1253 and NIST 800-53, Revision 4 (or current) (Mission Assurance Category III, Sensitive) for the IBDSS Program or other Program/system as called out in the applicable DO. The Contractor shall use the systems engineering process to incorporate the applicable Cybersecurity controls into the requirements, design, integration, and testing processes.
4.2.3.2.2 DISA STIG Implementation: The contractor shall identify and document applicable DISA Security Technical Control Implementation Guides (STIGs) for this IBDSS system. The contractor shall incorporate DISA STIG implementation into all requirements design, integration and testing for qualification of the system.
4.2.4 Sustainment Support: The Contractor shall establish and maintain a sustainment support activity to sustain fielded systems worldwide consistent with the priority level of the site and the specifics of the delivery order. The Contractor shall maximize the use of automated systems in order to track and report all sustainment and logistics support functions. These systems shall also allow rapid query of fielded configurations and sustainment activities to facilitate field support, asset accountability, and technical refresh activities. Specific sustainment functions shall consist of, but not be limited to:
• Help Desk
• Organizational Level Maintenance (i.e., on-site)
• Depot Level Maintenance through management of OEM repair or replacement capability
• Sustainment engineering (to include identification and resolution of issues regarding technology obsolescence or RAM)
• Warehouse management
• Resident field engineering
• System administration
• Support equipment
• Technical manuals
• Sparing concepts
• Training
• Cybersecurity certification
FA8730-19-R-xxxx, Attachment #, Page 21
4.2.5 Management
4.2.5.1 FPS4 Post Award Conference: The Air Force Life Cycle Management Center, Digital Directorate, Force Protection Division (AFLCMC/HBU) will organize and host a meeting with FPS4 awardees at Hanscom Air Force Base (AFB). The Post Award Conference is a one-time effort to discuss future FPS4 DOs and projected workload over the five-year period of performance, and is intended to meet the contract’s minimum DO requirements. Additional objectives include gaining familiarity with the personnel associated with the FPS4 contract, and gaining an understanding of processes associated with DO development, fair opportunity selection, and DO implementation. At this event, Contractors shall present the Government with their organization structures for FPS4 management, including roles and responsibilities and contact information for key Contractor personnel. Contractors are responsible for their own travel and lodging arrangements.
4.2.5.2 Integrated Program Management: The Contractor shall:
• Use and maintain sound and disciplined integrated program management procedures and processes to plan, organize, staff, control and manage DO efforts
• Assess and report statuses regarding the achievement of contract requirements
• Provide integrated master schedules, contract work breakdown structures (to the lowest practical level), and other management data as required
• Conduct Program Management Reviews (PMRs) with the Government at a period to be determined upon the award of a DO
• Record the minutes of these PMRs, and make a draft of the minutes available to the Government prior to the adjournment of the PMR for mutual agreement between the Government and the Contractor
• Support other program reviews as requested by the Government
• Integrate and coordinate all activity required to execute the FPS4 contract
• Manage the timeliness, completeness, and quality of all deliveries
• Effectively manage subcontractors to ensure contract completion IAW FPS4 and DO requirements
• Provide early and comprehensive risk or issue identification
• Submit corrective action plans and proposals to mitigate risks or issues in a timely manner
4.2.5.3 Government/Contractor Integrated Product Team (IPT): The Contractor shall participate in Government-chaired DO project IPTs. IPT meetings will be weekly teleconferences and may be held in conjunction with other meetings or reviews. The Contractor shall provide program updates and/or information that will be used to determine the statuses of on-going projects or test/verification planning, and to discuss programmatic and technical issues. The Contractor shall respond to action items and shall use the IPT as a forum to propose action items for Government completion.
4.2.5.4 Management of Contracts and Subcontracts: The Contractor shall perform the following functions to facilitate contract and subcontract management:
• Furnish program management, labor, tools, supplies, and materials (except as provided by the
Government) necessary to perform the requirements contained in applicable DOs
• Establish processes and assign appropriate resources to effectively administer DO requirements
• Respond to Government requests for contractual actions in a timely fashion
• Establish a single point of contact between the Government and Contractor personnel who are assigned to support DOs
FA8730-19-R-xxxx, Attachment #, Page 22
• Implement subcontract management systems, processes and organizations that provide the “best value” in the purchase of goods and/or services under this contract
• Maintain responsibility for subcontractor performance and subcontract management necessary to integrate work performed on DOs
• Distribute work in a way that avoids Organizational Conflict of Interest (OCI) issues. Contractors may add subcontractors to their team after notifying the Procuring Contracting Officer (PCO) or Contracting Officer Representative (COR).
4.2.5.5 Reserved
4.2.5.6 Electronic Data Interchange: Each DO will require electronic data interchange to maximize the provision of program information through electronic media. The Government will distribute relevant information to contractors via electronic methods over the course of the contract.
4.2.5.7 Risk Management: The Contractor shall manage risk throughout the life of the contract to reduce or eliminate problems. The following table defines the risk levels to be used as a guide for identifying technical, schedule and cost risks associated with a DO. Additional guidance can be found in the Risk Management Guide for DoD Acquisition.
Risk Consequence Level Technical Performance/Life Cycle
Sustainment Schedule Cost
1 Minimal or no consequence to technical performance.
Minimal or no impact Minimal or no impact
2 Minor reduction in technical performance or supportability; can be tolerated with little or no impact on program.
Able to meet key dates Exceeds contract target cost (<1% of target for Fixed Price Incentive Fee (FPIF) or cost type orders)
3 Moderate reduction in technical performance or supportability with limited impact on program objectives.
Minor schedule slip; able to meet key milestones with no schedule float
Exceeds contract target cost (<5% of target for FPIF or cost type orders)
4 Significant degradation in technical Program critical path Exceeds contract target cost
Risk Likelihood Level Likelihood Probability of
Occurrence 5 Near Certainty ~ 90% 4 Highly Likely ~ 70% 3 Likely ~ 50% 2 Low Likelihood ~ 30% 1 Not Likely ~ 10%
FA8730-19-R-xxxx, Attachment #, Page 23 performance or major shortfall in supportability; may jeopardize program success.
affected (<10% of target for FPIF or cost type orders)
5 Severe gradation in technical performance; cannot meet specified performance or supportability requirements; will jeopardize program success.
Cannot meet key program milestones
Exceeds contract target cost (>10% of target for FPIF or cost type orders)
Contractors shall address risk in DO proposals and during on-going reviews, to include formal internal reviews and PMRs. Risk statuses shall be reported as directed in individual DOs.
4.2.5.8 Configuration Management (CM): The Contractor shall conduct and maintain CM and change control processes IAW guidelines within EIA-649B and MIL-HDBK-61A for all DO configuration items, including software computer program configuration items (CPCI). The contractor shall maintain the system IAW the most current documented system configuration.
4.2.5.9 Data Management: The Contractor shall establish, document and maintain a data management program IAW its internal procedures. The Contractor shall use logical methods to generate, acquire, identify, plan and control all technical data, management data and related information. The Contractor shall also have a method to update the Government on status of this data. The Contractor shall develop a Data Accession List (DAL), which is an index of released, non-deliverable, internal Contractor data that shall be made available for Government review at any time during contract performance. Data management shall include, but not be limited to:
• On-time data delivery
• Identification, marking and control of proprietary and classified data
• Data quality assurance (QA)
• Updates and corrections to submitted data
• Maximum use of electronic data exchange
4.2.6 Program Security
4.2.6.1 Contractor Security Program: The Contractor shall implement a security program that safeguards classified and sensitive…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .