Bidders Library JITC Instructions - JITCI 240-110-04.pdf
PDF 985 KB Posted
- Attached to
- TEC II Services RFP Federal contract opportunity
- Solicitation number
- HC102821R0006
- Issued by
- Defense Information Systems Agency
About this file
This is a solicitation for Test, Evaluation, and Certification (TEC) II services to support the Defense Information Systems Agency's Joint Interoperability Test Command. The solicitation seeks proposals for services including test planning, execution, analysis, and reporting across all domains to ensure joint, coalition, and national interoperability. Offerors should demonstrate experience in developmental testing, certification testing, information assurance testing, and other test services. Proposals are due by June 15, 2021 and the period of performance is a five-year base period with five one-year options. The place of performance is Fort Huachuca, Arizona with the potential for some work to be performed at other locations based on customer requirements.
View the file
Other files for this federal contract opportunity
Show all 50
TEC II Services RFP has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
JOINT INTEROPERABILITY TEST COMMAND
P.O. BOX 12798
FORT HUACHUCA, ARIZONA 85670-2798
IN REPLY
REFER TO:
JITC INSTRUCTION 240-110-04* 12 March 2020
SECURITY
Information System Continuity of Operations Plan
1. Purpose. The purpose of this Information System (IS) Continuity of Operations Plan (COOP) is to provide the guidance and procedures necessary to recover Joint Interoperability Test Command (JITC) ISs in the event of an emergency and/or natural disaster causing disruption of normal operations. Individual system documentation, IS Standing Operating Procedures (SOP) and JITC Instructions (JITCI) supplement this plan. These documents deal with the normal day-to-day operations and procedures of the organization. This plan assigns responsibilities and tasks to IS users and supervisors to ensure personnel safety and the safeguarding of critical data, equipment, and facilities.
2. Applicability. This IS COOP has been prepared for use by all IS supervisors, operators, and users at the JITC.
3. Authority. This plan is published in accordance with (IAW) the authority contained in Department of Defense (DoD) Directive 3020.26, DoD Continuity Policy, 14 February 2018 and DoD Instruction (DoDI) 8500.01, Cybersecurity, 1 March 2014.
4. References.
4.1 DoDI 3020.42, Defense Continuity Plan Development, 17 February 2006.
4.2 DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT), 12 March 2014.
4.3 Defense Information Systems Agency (DISA) Instruction 630-230-19, Cybersecurity, 8 August 2017.
4.4 DISA Instruction 300-50-08, Continuity Program, 14 November 2018.
5. Responsibilities. A Contingency Notification Roster is located in Supplement 1 of this Contingency Plan. It presents the chain of command's formal reporting structure for emergencies and other problems affecting the IS. This chain of command must be followed in carrying out the provisions of this COOP. The roster will be prepared according to, and substituted for, the outline roster contained in Supplement 1.
* This Instruction supersedes JITCI 240-110-04, dated June 2019
OPR: JT2B
DIST: All JITC Civilian, Military, and Contractor Personnel.
ii
JITCI 240-110-04
6. Policy
6.1 This COOP was developed for the JITC IS Laboratories (Programs of Record) which are categorized as Availability = LOW impact systems, IAW Federal Information Processing Standards 199 – Standards for Security Categorization of Federal Information and Information Systems. JITC IS Laboratories (Programs of Record) are considered non-mission essential and downtime will have little or no impact on the overall JITC mission or the DoD defense mission.
Procedures in this COOP are for Low-impact systems and designed to recover JITC IS Laboratories within five days. As JITC IS Laboratories are a Low-impact system, alternate data storage and alternate site processing are not required.
6.2 This plan does not address replacement or purchase of new equipment, short-term disruptions lasting less than one day or loss of data at the onsite facility or at the user-desktop levels. Also, this COOP does not address key support information systems provided by the DISA Network (DISANet) Local Area Network (LAN) which include electronic mail, office automation applications, data, and print serving, as well as several business/process and financial management applications. The DISANet LAN is a DISA operated and maintained asset.
6.3 This plan contains the detailed actions required of JITC personnel in response to 10 specific emergencies. The actions are intended to save lives, limit damage, and maintain the capability to continue JITC operations in the face of emergency conditions. The specific emergencies covered by this plan are:
• Fire/Smoke in JITC Facility
• Extended Power Outage
• Air Conditioning Failure
• Flooding/Water Pipe Breakage
• Hostile Intruder/Hostage Situation/Disgruntled Employee
• Civil Disturbance/Threat Conditions
• Bomb Threat/Alert/Letter or Package Bomb
• Severe Storm/Warnings
• Earthquakes
• Hazardous/Toxic Spills
6.4 Each emergency is addressed individually. Within the chapter dealing with that emergency, detailed responsibilities and actions are assigned to the following specific individuals:
• JITC management - as a group or specific managers/supervisors
• IS operators/technicians
• IS users
• All JITC personnel iii
7. Delegation of Authority. The JITC Commander has delegated to the Information System Security Manager the responsibility of DISA Instruction implementation/compliance and the establishment of the JITC Cybersecurity program.
SHAWN ROBERTS
CAPTAIN, USN
Commander
SUMMARY OF SIGNIFICANT CHANGES: This instruction reflects changes in references and annual document review. Added section for Health Protection levels Normal through Delta iv
TABLE OF CONTENTS
BASIC INSTRUCTION Page
1. Purpose i
2. Applicability i
3. Authority i
4. References i
5. Responsibilities i
6. Background ii
7. Delegation of Authority iii
C1 CHAPTER 1. INTRODUCTION
C1.1 INTRODUCTION 1-1
C1.2 SCOPE AND USE OF THIS PLAN 1-1
C1.3 PLAN ORGANIZATION 1-1
C1.4 EMERGENCY INFORMATION 1-1
C1.5 EMPLOYEE BRIEF 1-2
C1.6 CHAIN OF COMMAND NOTIFICATION 1-2
C1.7 AFTER ACTION REPORTS 1-2
C1.8 CRITICAL ASSUMPTIONS 1-2
C2 CHAPTER 2. EMERGENCY RESPONSE AND
EVACUATION PROCEDURES
C2.1 REFERENCE 2-1
C2.2 THE CARDINAL RULE 2-1
C2.3 EMERGENCY RESPONSE 2-1
C2.4 JITC Emergency Evacuation Procedures 2-2
C3 CHAPTER 3. PROCEDURES AND PRACTICES
C3.1 EMERGENCY MANAGEMENT 3-1
C3.2 SECURITY 3-1
C3.3 SECURITY AWARENESS AND TRAINING 3-2
C4 CHAPTER 4. DAMAGE ASSESSMENT
C4.1 GENERAL 4-1
v
C4.2 ACTIONS REQUIRED IF THE USERS ARE DENIED
INFORMATION OR SERVICE
4-1
C4.3 PROGRAMMING 4-1
C4.4 OFF-PREMISES STORAGE 4-2
C4.5 SALVAGE 4-2
C4.6 NOTIFICATION 4-2
C5 CHAPTER 5. FIRE
C5.1 FIRE PREVENTION 5-1
C5.2 FIRE DETECTION AND SUPPRESSION 5-1
C5.3 SMOKE IN IS FACILITY 5-1
C5.4 FIRE DRILLS 5-1
C5.5 FIRE EMERGENCY RESPONSE 5-1
C6 CHAPTER 6. EXTENDED POWER OUTAGE
C7 CHAPTER 7. AIR CONDITIONING FAILURE
C8 CHAPTER 8. FLOODING/WATER PIPE BREAK
C9 CHAPTER 9. HOSTILE INTRUDER/HOSTAGE SITUATION/
DISGRUNTLED EMPLOYEE
C10 CHAPTER 10. CIVIL DISTURBANCES/THREAT CONDITIONS
C10.1 CIVIL DISTURBANCES 10-1
C10.2 FORCE PROTECTION CONDITIONS (FPCON) 10-1
C10.3 HEALTH PROTECTION CONDITIONS (HPCON) 10-2
C11 CHAPTER 11. BOMB THREAT/ALERT/LETTER OR PACKAGE BOMB
C11.1 BOMB THREAT OR ALERT 11-1
C11.2 LETTER OR PACKAGE BOMB 11-3
C12 CHAPTER 12. SEVERE STORM/WARNINGS
C12.1 IMMEDIATE RESPONSE 12-1
C12.2 RECOVERY 12-1
C13 CHAPTER 13. EARTHQUAKES
C14 CHAPTER 14. HAZARDOUS/TOXIC SPILLS
vi
C15 CHAPTER 15. PLAN MAINTENANCE
C15.1 PLAN MAINTENANCE AND CHANGES 15-1
C15.2 TESTING THE PLAN 15-1
C15.3 SELECTED TEST AREAS 15-1
C15.4 TEST METHODOLOGIES 15-1
C15.5 COOP EVALUATION 15-1
SUPPLEMENT
1 CONTINGENCY NOTIFICATION ROSTERS S1-1
LIST OF FIGURES
1 JITC FH Bomb Threat Checklist Data Card 11-2
LIST OF TABLES
1 Typical Causes of Disruption to IS 4-2 2 Individual Fire Emergency Checklist 5-2 3 Supervisor Fire Emergency Checklist 5-3 4 IS User Extended Power Outage Checklist 6-1 5 Supervisor or ISSO Extended Power Outage Checklist 6-2 6 IS Computer Operator/Technician Air Conditioning Failure Checklist 7-1 7 IS User Flooding/Water Pipe Breakage Checklist 8-1 8 SA or ISSO Flooding/Water Pipe Breakage Checklist 8-1 9 All Personnel Hostile Intruder Checklist 9-1 10 IS Users Hostile Intruder Checklist 9-2 11 SA or ISSO Hostile Intruder Checklist 9-2 12 JITC Manager Hostile Intruder Checklist 9-2 13 All Personnel Bomb Threat/Alert Checklist 11-1 14 All Personnel Hazardous/Toxic Spill Checklist 14-1 vii
ACRONYMS
AC Air Conditioning AOR Area of Responsibility
CAD Cybersecurity Architecture Design CDC Center for Disease Control and Prevention COMSEC Communications Security COOP Continuity of Operations Plan
DHS Department of Homeland Security DISA Defense Information Systems Agency DoD Department of Defense DoDI Department of Defense Instruction
FEMA Federal Emergency Management Agency FGGM Fort George G. Meade FH Fort Huachuca FPCON Force Protection Condition
HazMat Hazardous Material HIPAA Health Insurance Portability and Accountability Act
HPCON Health Protection Condition HVAC Heating, Ventilation and Air Conditioning
IS Information System ISSM Information Systems Security Manager ISSO Information Systems Security Officer IAW In Accordance With ISCP Installation Spill Contingency Plan - Fort Huachuca, Arizona
JITC Joint Interoperability Test Command JITCI JITC Instruction JT2B Cyber Compliance & COMSEC Branch
LAN Local Area Network
MP Military Police
OPM Office of Personnel Management
PAM Personnel Accountability Management PUI Person Under Investigation
SA System Administrator viii
SLDG Senior Leadership Decision Group SOP Standing Operating Procedure
UPS Uninterruptible Power Supply
WHO World Health Organization
1-1
C1. CHAPTER 1. INTRODUCTION
C1.1 Computer operations are performed in widely varying conditions at the Joint Interoperability Test Command (JITC) facilities from the controlled environment of the vault area to equipment shelters on the test nodes, and the Local Area Network users in the office areas. This plan is written as a generic source of guidance and can be tailored to fit each situation.
C1.2. Scope and Use of This Plan.
C1.2.1 This Continuity of Operations Plan (COOP) is concerned with the various Information Systems (IS) located in JITC. It is applicable to all personnel and specifically to those whose duties and responsibilities are designated in this plan.
C1.2.2 Disasters can be caused by an act of nature or as a result of an accident or intentional act.
Losses can include personnel, files, libraries, equipment, and/or the entire IS facility. Through the use of precautionary measures, potential losses from disasters can be avoided or minimized.
These steps include strict enforcement of safety and security regulations.
C1.3 Plan Organization.
C1.3.1 This COOP is organized by the type of emergency condition and subdivided by user responsibility. The responsible individuals include the following personnel: IS Operators, Technicians, Users, Managers, and System Administrators (SA).
C1.3.2 All actions within this document are organized in order of priority. This provides an easy-to-follow outline and negates the possibility of overlooking an important task in an emergency situation.
C1.3.3 This format will allow effective testing of IS personnel in response to simulated emergencies and the reaction of various personnel, as well as different levels of management, to the emergency. Further, the format will accommodate modifications and revisions as an IS changes in size or capability.
C1.3.4 For each emergency plan, the applicable personnel will be expected to initial checklists and indicate the time they complete tasks. IS management also has certain responsibilities to carry out under various emergency conditions, and, for historical purposes, should note the time actions were taken.
C1.4 Emergency Information. The following is general information of which all employees should be aware, regardless of the type of emergency. Supplement 1, page S-1 lists the emergency phone numbers for JITC at Fort Huachuca, Arizona, (FH) and page S-3 lists the emergency numbers for JITC at Fort George G. Meade (FGGM), Maryland.
C1.4.1 Fire: FH call 911 / FGGM call 911.
C1.4.2 Armed Intruder: Make sure you are in a safe position and, if possible, FH call 911 / FGGM call 911, then the JITC Security Office.
1-2
C1.4.3 First-aid Assistance: FH call 911 / FGGM call 911 if an emergency exists.
C1.5 Employee Brief. Supervisors are responsible for briefing their employees with the following information:
• The general alarm is the fire alarm.
• The sounding of the fire alarm will signal complete and immediate evacuation of the JITC buildings.
• When an alarm box is pulled anywhere in the building, the alarm system rings throughout the building.
• Telephone or messenger notification will announce partial evacuation due to fire, bomb threat, or other emergency.
C1.6 Chain of Command Notification. Whenever an emergency calls for the notification of JITC management, the contents of Supplement 1 will assist in determining who should be notified if the primary person is not available. Adherence to the chain of command for notification purposes is directed in all cases.
C1.7 After Action Reports.
C1.7.1 When an emergency occurs, an after action report will be prepared, chronologically detailing the events that took place and presenting an evaluation of the effectiveness of this COOP in handling the emergency. The Information Systems Security Manager (ISSM) will be responsible for coordinating information from the various Information Systems Security Officers (ISSO) for the after action report and for preparing the report. To assist in this reporting requirement, the emergency action checklists are included in this plan to permit recording the time events took place. All individuals’ assigned actions by this plan should keep a detailed record of events as they occur.
C1.7.2 Personnel called to JITC in response to an emergency condition will be debriefed as part of the after action process. This debriefing will focus on the non-disclosure of any sensitive or classified information they may have inadvertently been seen during the course of their emergency efforts. In addition, these personnel may be required to sign a non-disclosure statement.
C1.8 Critical Assumptions. For this COOP, the following assumptions were made:
• All personnel have reviewed the plan and know their responsibilities prior to an emergency occurring.
• Recovery after an emergency is required and needs to be performed in an efficient and timely fashion.
• Periodic testing and evaluation will be performed to ensure this plan is effective and kept up to date.
2-1
C2. CHAPTER 2. EMERGENCY RESPONSE AND EVACUATION PROCEDURES
C2.1 Reference: JITC Instruction (JITCI) 200-50-02, Emergency Notification and Evacuation Procedures.
C2.2 The Cardinal Rule.
NEVER RISK YOUR OWN SAFETY OR THE SAFETY OF OTHERS IN AN
EMERGENCY. PROTECTING LIFE AND LIMB TAKES PRECEDENCE OVER ALL
OTHER EMERGENCY ACTIONS. USE GOOD JUDGEMENT AND COMMON SENSE.
C2.3 Emergency Response. This chapter presents the initial responses to an emergency, to protect life and property and minimize loss. This phase is performed by those individuals involved in an emergency and/or disaster. It consists of those actions that are executed concurrently with the emergency response to limit damage to the IS facility and its data without endangering life.
C2.3.1 Deliberate Shutdown. In conjunction with the emergency response steps for power outages, fire, flooding, and bomb threat/alert, the following loss control measures, when executed, will help prevent damage to system hardware and data files. They should be taken whenever there is sufficient time. These steps include:
• Notify any on-line users of the service interruption by the fastest available means.
• Terminate jobs in progress.
• Power down system hardware and cover with waterproof covers, if appropriate.
• Remove tapes, disks, and other source documents and store them in a safe location, preferably outside the IS facility.
• Normal procedures for storing classified tapes, disks, removable hard drives, and documents will be followed.
• Remove power from any peripheral equipment involved or threatened by the emergency condition by disconnecting power at the source panel.
• Evacuate all personnel from the work area, leave lights on, and close doors as the area is evacuated.
C2.3.2 Emergency Shutdown. Emergency shutdown removes power from systems as quickly as possible without regard for possible damage to equipment or data. This action includes pulling the main power line switches at the panel boxes or pushing the Emergency Power-Off switch by the exit door of the lab and if possible, turning off large uninterruptible power supplies (UPS). DO NOT search for any smaller PC type UPS’ to shut off in an emergency shutdown situation. Disks and tapes (including classified) are not removed, as in a deliberate shutdown (Reference paragraph C2.2.4). Remember life is more important than equipment and media.
Notify firefighters and security of the location of UPS powered equipment that is still on.
2-2
C2.3.3 Extreme Emergencies. In extreme emergencies, the safety of all personnel dictates immediate evacuation.
C2.3.4 Responsible Person. The senior person on-site will assess the situation and determine what immediate actions should be taken to protect equipment and data without endangering life.
Measures include:
• Determining type/scope of emergency.
• Attempting to alleviate emergency (e.g., put out electrical fire).
• Safeguarding of important/classified material.
• Evacuating facility.
C2.4 JITC Emergency Evacuation Procedures. The JITC emergency evacuation routes are posted in all work areas and should be followed unless emergency conditions dictate otherwise.
Refer to JITCI 200-50-02.
C2.4.1 All personnel upon being notified to evacuate shall:
• Immediately terminate all telephone conversations and meetings.
• Secure all classified documents and materials.
• Pick up personal valuables, including individual building passes.
• Close doors as they leave their office.
• Ensure doors to areas processing classified information are secure.
• WALK to designated fire exit. Be alert to evacuation instructions.
• Remain calm. Do not run or push.
• Exit and move away from the building.
C2.4.2 If time permits:
• Turn off computers and electrical appliances in their work area.
• Report to their manager or person in authority and carry out any emergency instructions received.
C2.4.3 If personnel are believed to still be inside the building, notify the police/fire department immediately of the missing person’s probable or last known location.
3-1
C3. CHAPTER 3. PROCEDURES AND PRACTICES
C3.1 Emergency Management.
C3.1.1 There are more than just the 10 hazards addressed in this plan, but most of the others will fit into one or a combination of the categories listed. An example might be an aircraft crashing into a building. There would be building damage as with an earthquake; there could be fire, an explosion, loss of power, loss of air conditioning, water flooding, etc.
C3.1.2 The four steps of Emergency Management are mitigation, preparedness, response, and recovery. Yearly, or after any incident, whether for training or in an actual emergency, the four-step process is to be reviewed and updated. Additional information on the subject may be obtained from the Federal Emergency Management Agency (FEMA), Emergency Management Institute.
All quotes in paragraph C3.1.2.1 through C3.1.2.4 are from the Emergency Manager: An Orientation to the Position, a free web-based independent study course available at http://training.fema.gov/EMIWeb/is/is1.asp.
C3.1.2.1 Mitigation. “Mitigation refers to activities which actually eliminate or reduce the chance of occurrence or the effects of a disaster.” A hazard identification and vulnerability analysis was conducted and is the basis for this plan. However, these activities outlined are not static; they need to be reviewed and updated as conditions change. The information gathered in this step will help guide decisions on preparation.
C3.1.2.2 Preparedness. “Preparedness is planning how to respond in case an emergency or disaster occurs and working to increase resources available to respond effectively.” This includes: training, locations of emergency equipment, who is to respond, evacuation routes, incident command, chain of command, where personnel are to report once clear of the building, and so forth.
C3.1.2.3 Response. “Response activities occur during and immediately following a disaster…” or emergency. There are five stages:
• Notify/warn.
• Ensure personnel safety.
• Protect property, including classified information.
• Assess the damage.
• Restore.
C3.1.2.4 Recovery. “Recovery is the final phase and continues until all systems return to normal, or near normal.” It involves short-term efforts, restoration of vital services, and long-term efforts as services are restored to normal.
C3.2 Security.
C3.2.1 If you work in a classified area, keep in mind that it must be protected from unauthorized access and/or exposure, including access by firefighters and law enforcement officers. When encountering unanticipated situations, common sense should guide your actions. The JITC has provided personnel to assist you in reacting to such situations.
http://training.fema.gov/EMIWeb/is/is1.asp http://training.fema.gov/EMIWeb/is/is1.asp
3-2
C3.2.2 If you discover that the physical security of IS has been violated (i.e., door open, equipment damaged or missing, etc.), DO NOT TOUCH anything in the room. Close the door and guard it against additional unauthorized entry. Contact the JITC Security Manager/office staff for advice and assistance. The security office will contact the Military Police (MP)s, if required.
C3.2.3 When evacuation is necessary, and if time permits, the following procedures are to be followed:
• Ensure all classified material is properly stored in safes, and the safes are locked. In the event a safe cannot be approached, hand carry as much classified information as possible, to a designated meeting place. Find the JITC Security Office Personnel or Facility Security Officer and ask for assistance in safeguarding the material.
• In the event firefighters need access to a classified area, they shall be escorted. If escorting jeopardizes you and/or the firefighters, they should be given unescorted access.
• After responding to the emergency, if it is safe to enter the classified area, a detailed inspection shall be performed to verify that all IS assets used for classified processing to include all classified media (tapes, removable hard drives, disks, hard copy documents, etc.) are present and have not been tampered with.
• If a compromise is suspected or equipment is missing or damaged, a report detailing the nature and extent of the incident shall be completed and forwarded to the appropriate authority and a copy kept for record. The report will specify the steps taken to safeguard classified material, uncleared individuals who had or may have had access to the classified area, current status, inventory of classified equipment, and any debriefing actions taken.
C3.3 Security Awareness and Training. These are required of all JITC personnel:
• Initial and refresher security training.
• Annual counter-intelligence training.
• Defense Information Systems Agency (DISA) required Authorized User training is located at https://cmis.disa.mil/training/onlinetraining/designee/index.cfm.
4-1
C4. CHAPTER 4. DAMAGE ASSESSMENT
C4.1 General.
C4.1.1 The following paragraphs address assessing damage to the IS operating environment in order to estimate the cost and time required to become operational again. As the IS environment changes, the equipment susceptible to damage and the procedures for determining the extent of the damage need to be reviewed and updated regularly to provide information for a later possible damage assessment.
C4.1.2 If the equipment is damaged beyond repair, it will be processed for replacement and/or disposal. If the equipment is repairable, steps outlined in JITCI 630-230-01, Cybersecurity User Instruction, will be followed to ensure safeguarding of any equipment being turned in for repair or disposed of by the government.
C4.1.3 Refer to the System/Lab Cybersecurity Architecture Description (CAD) for information and diagrams regarding IS equipment configurations.
C4.2 Actions Required If The Users Are Denied Information Or Service.
C4.2.1 The degree to which the functional user is affected will be determined by the actual or potential delay or denial of services and the time required to recover. The user, not IS staff, judges the impact upon a functional application or user. The user is responsible for informing the IS staff and determining the priority placed on different IS applications. Table 1 contains a listing of typical causes of disruption to an IS.
C4.2.2 Short-term (outage less than one week) denial of IS services during testing by the functional user will disrupt normal JITC processes and activities, but is determined to be non-critical to Department of Defense.
C4.2.3 Long-term (outage longer than one week) denial or disruption of IS services will adversely affect the operational user community and program managers, requiring priority actions to be undertaken to restore IS services.
C4.3 Programming. If full IS programming environment and/or capability cannot be re-established, a priority determination of programming activities will be established by the members of the IS System/Lab Configuration Management Working Groups. If a long-term outage persists, this group will monitor these priorities. The JITC Contingency Plan identifies actions to be taken to re-establish operations within another JITC area or at another site.
4-2
Table 1. Typical Causes of Disruption to IS
Limited Loss of System Capability
Interruption of System Operations
Major System Disruption, Damage, or Destruction
Failure of key peripheral hardware unit(s)
Failure of electric utilities
Loss of key application programs, proper forms, or documentation
Partial loss of air conditioning or power
Maneuverability of critical personnel
Failure of major hardware or air conditioning unit(s) (partial or total loss)
Failure of major electric utilities
Fire, flood, or sabotage in the IS operating environment
Intrusion of smoke, dirt, or dust
Unavailability of operations personnel
Computer security incident
Planned disruptions (major renovation of spaces/building, movement of location)
Mechanical breakdowns (water pipe bursting, junction box fire, steam failure, air conditioning failure)
Natural acts (earthquake, flood, tornado, lightning)
Civil disorders (bombing, explosions, fire)
C4.4 Off-Premises Storage. Information saved on backup media will be protected so that it is available and recoverable in the event it is required. Locally stored backup media is sufficient in most circumstances; however, off-premises storage of backup media may be required for some systems based on criticality, cost to regenerate lost information, and/or other factors.
JITC ISSOs, in conjunction with the users they support, will determine whether off-premises storage of backup media is required for their systems. In such cases, these ISSOs should make arrangements through the JITC ISSM.
C4.5 Salvage. Salvage of equipment will be performed by the appropriate Accountable Property Officer following government procedures.
C4.6 Notification.
C4.6.1 Analysts/users will be notified through the SA or lab management. An organizational memorandum will be prepared by JITC notifying other interested parties of the IS outage or loss of operational capability. Information included would be cause of outage, estimated time until services are re-established (if available), and any changes of procedures expected when services are brought on-line.
C4.6.2 DISA Headquarters will be advised of all major system disruptions or major IS/facility damage or destruction. Computer security incidents will be reported using the guidelines contained in the JITC Incident Response Plan.
5-1
C5. CHAPTER 5. FIRE
C5.1 Fire Prevention. The following fire prevention requirements apply to JITC buildings:
• There is a "No Smoking" policy throughout all buildings. Smoking is only permitted in designated smoking areas in the compound.
• Oily rags, waste, cleaning fluids, or other flammable material are to be placed in approved metal containers provided for that purpose.
• Aisle space of 36 inches is provided in stock rooms and other storage areas.
• To permit efficient firefighting, material will be stacked no higher than two feet from the ceiling. No equipment will be located within 18 inches of the heads of an automatic sprinkler system or alarm.
C5.2 Fire Detection And Suppression.
C5.2.1 An automatic fire alarm system has been installed and is connected to the Fort Huachuca Fire Department, less than three miles away. Firefighting support is available 24-hours a day via the fire department. Fire alarm location identification panels are located at the front lobby receptionist desk. Portable fire extinguishers are present at strategic points in the hallways.
Main power cutoff switch locations are documented in the individual lab/system SOP, Appendix C. Smoke detectors are strategically placed under raised flooring and on the ceiling.
Sprinklers are strategically placed on some ceilings.
C5.2.2 The facility's fire and security alarm systems have integral battery backup power in the event of a main power failure. An emergency lighting system is in place to allow safe evacuation if power is lost.
C5.3 Smoke In IS Facility. When smoke is detected, its source should be promptly determined and appropriate action taken. Refer to Table 2.
C5.4 Fire Drills. In the event of a fire within the confines of the facility, the movement of all personnel from the occupied space to points of safety shall be performed rapidly and in a safe manner. Fire drills will ensure that personnel are cognizant of their responsibilities, proper procedures, and exit points during an emergency. Periodic fire drills shall be performed as required, but no less than semiannually.
C5.5 Fire Emergency Response. The guidelines in Tables 2 and 3 are recommended as emergency responses to a fire in a computer facility/building. Also, refer to JITCI 200-50-02, Fire and Evacuation Instructions, for evacuation procedures.
5-2
Table 2. Individual Fire Emergency Checklist
ACTION TIME INITIAL
1. Report any odor of smoke or evidence of fire in your work area immediately to your supervisor or, in his/her absence, the next senior person in the chain of command. (Refer to Supplement 1.)
2. Anyone detecting a fire in the JITC areas should:
• If appropriate, and it is safe to do so, at FH call 911 or FGGM call 911 and report the fire.
• Quickly alert people in the surrounding area.
• For a very small fire, if you think it is possible without risk of personal injury, attempt to put it out using a hand-held fire extinguisher with one other person's help.
• If appropriate and it is safe to do so, call the Service Desk to report smoke or fire.
3. If directed to evacuate the JITC facility:
• Exit the building immediately.
• Remain in the area.
• Do not return to the building until it has been declared safe by building security, JITC management, or fire department personnel.
5-3
Table 3. Supervisor Fire Emergency Checklist
1. Upon being notified of a fire in the JITC area, investigate the area immediately.
2. If investigation reveals nothing unusual, call the Service Desk and report the situation.
3. If fire is found, call the fire department- FH call 911 or FGGM call 911. Notify next in chain of command. (Refer to Supplement 1.)
4. If at any time during this process, smoke or flames appear:
• Terminate the investigation and evacuate the IS area immediately.
• Check to ensure that all personnel have departed. Notify next in chain of command.
• For a very small fire, if you think it is possible without risk of personal injury, attempt to put it out using a hand-held fire extinguisher with one other person's help.
5. Once outside the IS area, do the following:
• If applicable, ensure doors to IS are closed.
• Notify personnel in the adjacent areas.
• Report to the front lobby to direct the firefighters when they arrive.
• Notify next in chain of command.
6-1
C6. CHAPTER 6. EXTENDED POWER OUTAGE
C6.1 The guidelines in Tables 4 and 5 are recommended as responses to an extended power outage.
C6.2 An extended power outage, for the purpose of this COOP, is one that occurs when the primary power source and the UPS have all failed. The UPS systems can provide sufficient power to keep most ISs running for about 15 minutes at a full-load condition.
C6.3 If the systems are stopped by a sudden power outage, there is a very good chance of either hardware or software problems which could take a considerable amount of time to resolve. This means JITC personnel must make a rapid decision in this emergency to cancel all jobs and power down the system in a non-graceful manner (users may lose data, but systems do not crash).
C6.4 The steps in this emergency condition require fast action and a quick decision by a number of personnel. There is no lab-wide alarm to notify users with information regarding the power situation. When the primary power goes off, UPS alarms may be heard by users near the UPS room, but not by all personnel throughout the lab. There is no direct indication that the power being supplied to the computers is being furnished by the UPS batteries. At this time, the only probable indication is an interruption of some of the building lights. The IS users will have to monitor the total operating environment to take proper action during the emergency.
Table 4. IS User Extended Power Outage Checklist
1. When detecting an indication that the system has switched to
UPS power, note time of outage.
2. Immediately notify the following:
• The Service Desk.
• The personnel listed on the appropriate Contingency Notification Roster. (Refer to Supplement 1.)
3. Check the UPS indicators to verify proper operation. Reset the audible alarm. Refer to either the System/Lab Procedures or the UPS manual for procedures.
4. Brief all users on the situation and alert them to the possibility of having to cancel all jobs and power down the systems in a non-graceful manner.
5. Contact the first available person in the appropriate Contingency Notification Roster and request permission to cancel all jobs and power down the systems in a non-graceful manner.
6. Upon approval to power down, begin system shutdown procedures. Refer to the System/Lab Procedures.
6-2
Table 5. Supervisor or ISSO Extended Power Outage Checklist
1. When notified of the situation by IS users, remain available to
IS users in the event that a decision is required to cancel all jobs.
2. Be prepared to direct IS users to power down the systems in a non-graceful manner.
3. If the systems must be powered down, notify the division chief immediately and provide him/her an estimated recovery time.
7-1
C7. CHAPTER 7. AIR CONDITIONING FAILURE
The building has air conditioning (AC) units supporting the ISs operations. The AC system must maintain room temperature at or below 95 degrees Fahrenheit (oF) (35 degrees Celsius (oC)). In the event of a failure of the AC system, the ambient temperature must be continually monitored so that appropriate action can be taken. The guidelines in Table 6 are recommended as responses to an air conditioning failure.
Table 6. IS Computer Operator/Technician Air Conditioning Failure Checklist
1. When it is determined that the air conditioning is not working, notify the following:
• The personnel on the appropriate Contingency
2. Monitor the ambient temperature.
3. If/when room temperature reaches 90oF (32oC), notify users and personnel on the appropriate Contingency Notification Roster (Supplement 1) that the systems might be powered down due to temperature problems.
4. When room temperature reaches 95oF (35oC) do the following:
• Notify the users that the system is being powered down.
• Advise the personnel on the appropriate Contingency Notification Roster that the system is being powered down.
• Gracefully power down the system.
7-2
(This page intentionally left blank.)
8-1
C8. CHAPTER 8. FLOODING/WATER PIPE BREAK
This emergency condition can encompass any situation where water has entered the ISs areas of the JITC facility, whether it be from a leaking roof, leaking pipe, or the result of the efforts of firefighters in other parts of the building. All of these present very real health and safety problems to the individuals who work in the JITC IS facilities because of the disastrous consequences of bringing together water and electricity. Any time water enters the JITC;
prompt, effective action must be taken to prevent the water from reaching any piece of hardware that has power applied. The guidelines in Tables 7 and 8 are recommended as responses to water or flooding.
Table 7. IS User Flooding/Water Pipe Breakage Checklist
1. If water is found, try to determine the source of the water.
Notify:
• The personnel on the appropriate Contingency
2. If the water is entering from the ceiling, and it is safe to do so, initiate immediate system shutdown. Use plastic sheeting to cover all equipment in the area where the water is entering.
3. Monitor water buildup. If it is increasing in depth, notify the supervisor or ISSO who will decide if the situation requires that the directly affected equipment be powered down.
NOTE: If your area has raised flooring, check under the floor.
Table 8. SA or ISSO Flooding/Water Pipe Breakage Checklist
1. If notified of water under or on the floor of IS, determine if water level is rising.
2. If water level on the floor of IS is rising, decide if the situation requires that the equipment in the vicinity of the water be powered down.
3. Notify the division chief.
8-2
9-1
C9. CHAPTER 9. HOSTILE INTRUDER/HOSTAGE SITUATION/
DISGRUNTLED EMPLOYEE
A hostile intruder can range from an individual trying to gain access to areas where they are not allowed to a disgruntled employee being on the premises and interfering with normal day-to-day operations. A hostage situation may also be involved. The most important rule for JITC personnel is to NEVER endanger themselves. The basic reaction by JITC personnel should be to keep out of the way, if possible. The guidelines in Tables 9, 10, 11, and 12 are recommended as responses to a hostile intruder.
Table 9. All Personnel Hostile Intruder Checklist
1. If you observe an unauthorized person or suspected hostile intruder in the JITC areas, notify security and your supervisor.
2. Provide security and your supervisor with the following information:
• Exact location of the intruder.
• Intruder's direction of movement or actions.
• Weapon(s) and type (knife, gun, etc.).
• Physical and personal traits of the intruder:
Type and color of clothes, shoes, hair, eyes, etc.
Scars, tattoos, etc.
Accent, vocabulary, etc.
Remember:
• Do not jeopardize yourself.
• Do not attempt to resist the intruder.
• Avoid the intruder(s) if possible.
• If possible, call the police, FH call 911 or FGGM call
911, and inform them of a hostile intruder on the premises and request assistance/guidance.
• Remain vigilant and look for opportunities to escape.
9-2
Table 10. IS User Hostile Intruder Checklist
1. If notified by the security office that a hostile intruder is in the building, or a hostage situation exists, follow all instructions provided by the security office.
2. Notify the SA or ISSO and your supervisor of the situation and the instructions received.
Table 11. SA or ISSO Hostile Intruder Checklist
1. If notified of a hostile intruder/hostage situation, either by the security office or by other competent authority, follow all instructions provided by the authority making the notification.
2. Pass the information and instructions received to the following:
• IS users.
• Division chief and your supervisor.
Table 12. JITC Manager Hostile Intruder Checklist
1. If notified of an unauthorized/hostile intruder by a subordinate, immediately pass the information to the security office.
2. If notified of a hostile intruder/hostage situation by the Security Office or by other competent authority, determine from the authority making the notification, the actions required by your subordinates.
3. Personally ensure that all of your subordinates receive the information about the situation.
4. If the building is to be evacuated, check all spaces under your control to ensure that all personnel have evacuated the building.
10-1
C10. CHAPTER 10. CIVIL DISTURBANCES/THREAT CONDITIONS
C10.1 Civil Disturbances. The Fort Huachuca or FGGM Security/MP and local civil authorities will deal with civil disturbances. In the event a civil disturbance develops in the local area, all JITC personnel should:
• Remove all visible indications of their affiliation with Fort Huachuca, FGGM, or JITC.
• Not wear caps or jackets with JITC or contractor company names or insignia.
• Not wear your identification badge outside the facility/office area.
NOTE: A civil disturbance in a local community may cause an alert condition on Fort Huachuca or FGGM.
C10.2 Force Protection Conditions (FPCON). A Chairman of the Joint Chiefs of Staff-approved program standardizes the military services' identification of and recommended responses to terrorist threats against United States personnel and facilities. This program facilitates Inter- Service coordination and support for antiterrorism activities.
C10.2.1 FPCON NORMAL. This condition applies when a general global threat of possible terrorist activity exists and warrants a routine security posture.
C10.2.2 FPCON ALPHA. This condition applies when there is a general threat of possible terrorist activity against personnel and facilities, the nature and extent of which are unpredictable, and when circumstances do not justify full implementation of FPCON BRAVO measures. However, it may be necessary to implement certain measures from higher FPCONS resulting from intelligence received or as a deterrent. The measures in this FPCON must be capable of being maintained indefinitely. Situational Awareness: Increase your security awareness in your workplace and at your quarters. Report any unusual activity or abandoned parcels to security forces at FH call 911 or FGGM call 911. Secure vehicles and unused buildings; spread the word about the FPCON.
C10.2.3 FPCON BRAVO. This condition applies when an increased and more predictable threat of terrorist activity exists. The measures in this FPCON must be capable of being maintained for weeks without causing undue hardship, affecting operational capability, and/or aggravating relations with local authorities. Situational Awareness: Continue or introduce FPCON ALPHA actions. Assist in tightening workplace security. Remain alert for and report suspicious persons, vehicles, objects, or activity to security forces at FH call 911 or FGGM call
911. Lock and check vehicles before entering. Carefully inspect mail parcels and letters. Do not move suspicious objects.
10-2
C10.2.4 FPCON CHARLIE. This condition applies when an incident occurs or intelligence is received indicating some form of terrorist action or targeting against personnel and facilities is likely. Implementation of measures in this FPCON for more than a short period probably will create hardship and affect the activities of the unit and its personnel. Situational Awareness:
Introduce and continue FPCON ALPHA and BRAVO actions. Remain calm and stay in your workplace or quarters; limit movement to essential travel only. Inspect vehicles before use and obey parking ban restrictions. Keep personnel and vehicle identification readily available. Do not accept unexpected deliveries or objects from strangers. Quickly follow the instructions of supervisors and/or security forces.
C10.2.5 FPCON DELTA. This condition applies in the immediate area where a terrorist attack has occurred or when intelligence has been received that terrorist action against a specific location or person is imminent. Normally, this FPCON is declared as a localized condition.
FPCON DELTA measures are not intended to be sustained for substantial periods. Situational Awareness: Introduce and continue all previous FPCON actions. Stay inside, keep exterior doors and windows locked. Do not move around unless directed to do so. Keep blinds and window shades drawn. If you hear shooting or explosions, get down and stay down. Assist the injured.
C10.3 Health Protection Conditions (HPCON). A Department of Defense program which standardizes the identification of a recommended response to increasing probability that a contagion will start and may succeed in negatively impacting mission essential personnel and thereby negatively impact mission objectives. This program is designed to mitigate personnel and mission related risks.
C10.3.1 HPCON Normal (Mandatory Measures). This condition applies at all times, as a general threat of public health contagions is always present. At this level, leadership ensures personnel are aware of U.S.
Center for Disease Control and Prevention (CDC) in addition and state/local guidance concerning prevention and mitigation of infectious and communicable illness and diseases.
Triggers:
• Applies at all times as a general threat of public health. Contagions always exist throughout the world.
Measures:
• Review and update local HPCON framework per DoDI 6200.03 Public Health Emergency within DoD.
• Provide health and safety situational awareness to the workforce.
• Promote proven immune-boosting habits to the workforce (e.g., routine hand washing, cough in sleeve or in the bend of the elbow, cover your cough or sneeze with a tissue, then throw the tissue in the trash, establish a healthy diet, exercise regularly, and sanitize common-use areas using CDC-recommended cleaners).
C10.3.2 HPCON ALPHA (Increased Community Transmission). This condition applies when a common and generally treatable, threat to public health exists such as cold or flu season. All procedures that apply during HPCON Normal are applicable, additionally all personnel should, if medical conditions permit, receive vaccinations as soon as they are available.
10-3
Triggers:
• Report of unusual health risk or disease.
• At the beginning of any officially announced infectious outbreak with the potential of reaching a
DISA Area of Responsibility (AOR) of concern.
• A trending increase in Persons Under Investigation (PUI) close to a DISA AOR.
(A person with the following characteristics: fever (body temperature of or greater than 38°C, 100.4°F) and pneumonia or acute respiratory distress syndrome (based on clinical or radiological evidence); close contact with a symptomatic traveler who developed fever and acute respiratory illness (not necessarily pneumonia) within 14 days after traveling from a destination of concern.)
• Continue all measures from lower HPCONs.
• Consider convening the Senior Leadership Decision Group (SLDG)
• Continue to emphasize good hygiene measures and practices.
• Ensure personnel are familiar with crisis reporting procedures, (e.g., accountability and symptomatic illnesses reporting that do not violate HIPAA policies).
• Educate workforce on specific health concerns and mitigation/prevention measures.
• Provide updates to senior leaders for situational awareness.
• Routinely assemble Emergency Readiness Group/Emergency Operations Center members and review scenario-based courses of action.
• Maintain strict accountability using Personnel Accountability Management System (PAM).
HPCON Bravo (Increased Community Transmission). This condition applies when an increased or more predictable threat to public health exists. However, the known illness or disease has not been reported within the primary AOR. Additionally at this stage, leadership should begin reviewing, updating and generating response plans specific to the illness or disease. All conditions from previous HPCONs also apply under HPCON Bravo.
Triggers:
• International Health Regulations Emergency Committee of the World Health Organization declares an outbreak as a public health emergency of international concern
• Officially reported outbreak of illness or disease with an increased potential of infection to a DISA AOR of concern.
• Clusters of cases reported in areas of concern.
• Personnel reporting symptoms of the illness or disease of concern within the DISA AOR.
• Follow any travel restrictions imposed by the CDC, Department of Homeland Security (DHS), Department of State or higher-level Headquarters authority.
• Check for additional Office of Personnel Management (OPM) guidance for leave.
• Consider limiting official travel to mission-essential only. Emphasize the risks of leisure travel to the workforce.
• Exercise operating under reduced staffing and use of mass telework.
• Re-scope or modify exercises in affected areas to limit risk to U.S. personnel.
• Consider restrictions of movement for persons critical to national security.
• Employ strict hygiene measures for personnel and equipment.
Haakenson, Stephanie K CIV (USA)
10-4
• Implement self-quarantine for employees who have or members of their household who have traveled to restricted/high-risk areas.
• Consider instituting social distancing practices to reduce the likelihood of spreading infection to mission-essentia1 workforce, (e.g., potentially cancelling in-person meetings and closing gyms, training rooms, cafeterias, etc.)
• Consider canceling mass gatherings such as conferences, all hands meetings and training.
• Consider convening the SLDG.
HPCON Charlie (High Morbidity Epidemic or Contamination). This condition applies when a known threat to public health exists within the AOR. During HPCON Charlie leadership should fully execute their pandemic and mission assurance plans. All measures applied within HPCONs Normal, Alpha and Bravo apply.
Triggers:
• Officially reported outbreak of illness or disease within a DISA AOR of concern.
• Confirmed cases reported involving DISA personnel causing a moderate mission impact.
• DISA personnel failing to report to work due to illness or uncertainty of personal safety.
• Convene the SLDG.
• Maximize telework.
• Close meeting rooms, gyms, training rooms, cafeterias, etc.
• Cancel mass gatherings such as conferences, all hands and training.
• Restrict visitor access to facility.
• Impose strict hygiene practices, (e.g., no handshaking, disinfect/wipe down common-use items/areas using CDC-recommended cleaners.).
• Avoid possibly contaminated water/food or risk area.
• Institute measures to combat any known vector/carrier of the disease, if applicable.
• Maintain strict personnel accountability.
HPCON DELTA: This condition applies when a known threat to public health exists within the AOR and agency personnel within the primary AOR have reported infection with the illness or disease of concern.
During HPCON Delta all measures and procedures to detect and defeat the contagion should be executed immediately.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .