HSBP1017Q0084_Statement_of_Work.pdf
PDF 383 KB Posted
- Attached to
- El Paso, TX Parcel Scanner Federal contract opportunity
- Solicitation number
- HSBP10-17-Q-0084
About this file
HSBP1017Q0084 - Statement of Work
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Copy_of_FY17Pallet_Requirements_Matrix_SmallCargo_Large_Parcel_0084.xlsx | XLSX spreadsheet | |
| Parcel_Vendor_Responses_to_RFQ_HSBP1017Q0084.docx | DOCX document | |
| Cargo_Large_Parcel_X-Ray_SOW__20170609_FINAL_(0084).docx | DOCX document | |
| Requirements_Matrix_(final).pdf | ||
| HSBP1017Q0084_(final).pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
U. S. Customs and Border Protection
Statement of Work
SMALL SCALE NON-INTRUSIVE INSPECTION (NII)
CARGO / LARGE PARCEL X-RAY SYSTEMS
Prepared by
Interdiction Technology Branch
Interdiction Technology Branch 11/09/2016 2
Contents
1.0 PURPOSE
1.1 Background
1.2 Scope
1.3 Government and Program Management Organization
1.4 Contractor Management Organization
2.0 APPLICABLE DOCUMENTS
2.1 Applicable Federal Regulations and Publications
2.2 Applicable National Standards
2.3 Applicable Department of Homeland Security (DHS)/ Customs and Border Protection (CBP) Documents, as may be amended*
3.0 GENERAL REQUIREMENTS
3.1 Requirement Definitions:
3.2 Performance Requirements
3.2.1 Computer Security Requirements
3.2.2 Identification and Authentication
3.2.3 Access Control
3.2.4 Auditing
3.2.5 Printed Documents
3.3 System Integration
3.3.1 System Installation
3.3.2 Work Center
3.3.3 Workstation Integration and Interface
3.3.4 Integrated Image Capture
Interdiction Technology Branch 11/09/2016 3
3.3.5 Integrated Image Storage
3.3.6 Integrated Data Set Download
3.3.7 Safety Interlocks
3.4 Reliability, Availability and Maintainability Design Requirements
3.4.1 Basic System Reliability Requirements – Inherent Availability (Ai)
3.4.2 Predictive Reliability, Availability, and Maintainability Analysis
3.4.3 Classification of Reliability Critical Items
3.4.4 Control of Reliability Critical Items
3.4.5 Corrosion Control
3.5 Quality Assurance/Quality Control Plan
3.6 Testing
3.6.1 Factory Testing
3.6.2 Site Acceptance Testing
3.6.3 Discrimination Testing
3.7 System Safety Program
3.7.1 Radiation Safety
3.7.2 Radiation Safety Design Review
3.7.3 Radiological Survey and Report
3.7.4 Annual Radiation Survey and Report
3.7.5 Safety Plan
3.7.6 Hazardous Materials
3.8 Information Technology Security
3.8.1 Basic Requirements
3.8.2 Security Authorization
3.8.3 DHS Security Policy Requirement
Interdiction Technology Branch 11/09/2016 4
3.8.4 Encryption Compliance Requirement
3.8.5 Security Review
3.8.6 Access to Unclassified Facilities, Information Technology (IT) Resources, and Sensitive Information
3.8.7 Personal Identity Verification of Contractor Personnel
3.8.8 Security Requirements for Unclassified Information Technology Resources
3.8.9 Contractor Personnel Access
3.8.10 Enterprise Architecture (EA) Compliance
3.8.11 Supply Chain Risk Management Terms and Conditions:
3.8.12 IPv6
3.8.13 CBP Contractor Handling PII Level
3.8.14 Personal Identification Verification (PIV) Credential Compliance
3.8.15 DHS Information Technology Portfolio Alignment
3.9 Accessibility Requirements (Section 508 Compliance)
3.9.1 Section 508 Applicable EIT Accessibility Standards
3.9.2 Section 508 Applicable Exceptions
3.9.3 Section 508 Compliance Requirements
4.0 LIFE CYCLE SUSTAINMENT AND SUPPORT REQUIREMENTS
4.1 Warranty
4.2 System Training
4.2.1 Operator Training
4.2.2 Train-the-Trainer Course
4.2.3 Training Material
4.2.4 Ownership
4.3 Technical Manuals
Interdiction Technology Branch 11/09/2016 5
4.3.1 Operator Manual
4.3.2 Operational/Storage Checklist
4.3.3 Service and Maintenance Manual
4.4 Technical Reviews
4.5 Other Reviews
4.6 Sustainment and Maintenance
4.6.1 Service Support Availability Requirements - Operational Availability
4.6.2 Service Calls and Work Orders
4.6.3 Preventative Maintenance
4.6.4 Corrective Maintenance
4.6.5 Conditional but Operational Status
4.6.6 Corrosion Control under Preventative and Corrective Maintenance
5.0 CONFIGURATION MANAGEMENT
5.1 Configuration Baseline
5.2 Technical Documentation
5.3 Management of the Technical Documentation
5.4 Engineering Change Proposals (ECPs)
5.5 Configuration Changes
5.6 Configuration Control Reports
5.7 Interchangeability
5.8 Accessibility
6.0 DOCUMENTATION DELIVERABLES (Data Item Description (DID))
Appendix B Deliverables
Appendix C: Acronyms
Appendix D: Glossary of Terms
Interdiction Technology Branch 11/09/2016 6
1.0 PURPOSE
The U.S. Customs and Border Protection (CBP) requires Cargo/ Large Parcel (CLP) X- Ray Systems. The purpose of this procurement is to provide CBP with the capability to non-intrusively inspect cargo, including pallets, baggage, mail, and packages, for contraband at various locations, including airports, seaports, checkpoints, and land ports of entry.
1.1 Background
Customs and Border Protection, an agency of the Department of Homeland Security (DHS), is responsible for targeting, selecting and examining cargo deemed high risk for terrorist-related activity, smuggling of contraband and trade law violation. CBP is also responsible for facilitating the release of low-risk cargo. CBP has a continuing requirement to interdict incoming contraband such as weapons, explosives, illegal drugs, outgoing currency and weapons, through examination of break-bulk cargo, passenger baggage and international mail parcels.
1.2 Scope
The Contractor shall supply CLP X-Ray Systems for use at airports, seaports, checkpoints and land ports of entry. These systems will be used to perform non-intrusive inspection (NII) of conveyances for detection of illegal contraband coming into the United States. The technical performance specifications and service requirements for the CLP X-Ray Systems are contained in the sections below.
1.3 Government and Program Management Organization
This program is under the technical direction of the Small Scale (SS)-NII Contracting Officer Representative (COR) assigned to the CBP Laboratories and Scientific Services Directorate (LSSD), Interdiction Technology Branch (ITB) in coordination with CBP Enterprise Services, Integrated Logistics Branch (ILB) – CBP NII Maintenance, Repair, and Operations Support Center (MROSC).
CBP will manage this program through CBP LSSD/ITB for system acquisition, delivery, and acceptance. CBP will coordinate with the Contractor to ensure successful system integration. The CBP Enterprise Service, CBP NII MROSC will manage the warranty service support, and maintenance services. The CBP Office of Training Development (OTD) will approve training development. CBP OTD and Enterprise Networks and Technology Support Directorate (ENTSD) - Technology Training Support Branch (TTSB) will coordinate operator training. The CBP Human Resources Management (HRM) will approve radiation safety.
1.4 Contractor Management Organization
The Contractor shall provide a Project Management Plan for CBP Review including all major points of contact and the Contractor overall management structure. This plan shall include the schedule for completing all tasks required to fabricate, ship, install, test, train, and maintain CLP X-Ray Systems and all major points of contact and the Contractors overall management. The Project Management Plan shall be prepared in accordance with Data Item Description (DID) A001.
2.0 APPLICABLE DOCUMENTS
Documents cited shall be referenced and used as called for in this Statement of Work (SOW)/Performance Specification and the DIDs. In the event of a conflict between the texts of this SOW and the references cited below, the SOW takes precedence.
However, nothing in this SOW supersedes applicable federal and state safety laws.
2.1 Applicable Federal Regulations and Publications
a. Code of Federal Regulations, 29 CFR Part 1910, Occupational Safety and
Health Standards (OSHA),
b. United States Code (29 USC 701et seq.) Rehabilitation Act of 1973, as amended, Title V, Section 508
c. Office of Management Budget (OMB), Memorandum M-05-22, August 2, 2005
d. United States Code (36 CFR Part1194) Electronic and Information
Technology Accessibility Standards, including 36 CFR 1194.21, Software Applications and Operating Systems
e. United States Code, (44 USC Chapter 35), Federal Information Security Modernization Act (FISMA) of 2014
f. OMB Circular A-130
g. United States Code (5 USC 552a), The Privacy Act, 2010
h. United States Code (6 USC 133), Critical Infrastructure Information Act of
2002 (Title II, Subtitle B, of the Homeland Security Act)
i. United States Code (6 CFR Part 29 Protected Critical Infrastructure
Information
j. Code of Federal Regulations (49 CFR Part 1520), Protection of Sensitive
Security Information
k. Code of Federal Regulations, 49 CFR Part 1544.2 (e)3, Use of X-ray
Systems., 2016
l. Code of Federal Regulations, 21 CFR Part 1020.40, Performance
Standards For Ionizing Radiation Emitting Products, Cabinet X-ray Systems., 2015, (FDA)
m. Code of Federal Regulations, 49 CFR Part 172, Subpart B, Table of Hazardous Materials and Special Provisions
Note: The regulations can be accessed by going to: http://ecfr.gpoaccess.gov.
2.2 Applicable National Standards
a. American National Standards Institute, ANSl/HPS N43.3, General Radiation
Safety - Installations Using Non-Medical X-Ray and Sealed Gamma-Ray Sources, Energies up to 10 MeV, 2008.
b. American National Standards Institute, ANSl/HPS N43.14, Radiation Safety for Active Interrogation Systems for Security Screening of Cargo, Energies up to 100 MeV, 2011.
c. American National Standards Institute, ANSI/HPS N43.17, Radiation Safety for Personnel Security Screening Systems Using X-Rays, 2009
d. American National Standards Institute, ANSI/IEEE N42.46, Determination of the Imaging Performance of X-Ray and Gamma-Ray Systems for Cargo and Vehicle Security Screening, 2008
e. National Fire Protection Association (NFPA) 79, Electrical Standards for Industrial Machinery, 2015.
f. NFPA 70, Recommended Practice for Electrical Equipment Maintenance,
g. NIST Special Publication 500-267
h. Federal Information Processing Standards Publications (FIPS PUBS), Advanced Encryption Standard (AES), FIPS 197
i. Security Requirements for Cryptographic Modules, FIPS PUBS 140-2
j. International Standards Organization (ISO) 9000 series, Quality
Management
k. SAE International Standard EIA649B, Configuration Management Standard
l. Federal Information Processing Standards Publication (FIPS PUB) Number
201-2, Personal Identity Verification (PIV) of Federal Employees and Contractors, August 2013
2.3 Applicable Department of Homeland Security (DHS)/ Customs and
Border Protection (CBP) Documents, as may be amended*
a. DHS Enterprise Data Management Policy Directive 103-01, 08/25/2014
b. DHS Management Directive (MD) 11042.1 Safeguarding Sensitive But
Unclassified (For Official Use Only) Information
c. DHS Sensitive Systems Policy Directive 4300A, Version 12.01, February
12, 2016
d. DHS 4300A Sensitive Systems Handbook Version 12.0
November 15, 2015
e. DHS Section 508 Program Management Office and Electronic and
Information Technology Accessibility MD 4010.2, 10/26/2005
f. Homeland Security Presidential Directive-12 (HSPD-12), Policy for a
Common Identification Standard for Federal Employees and Contractors, August 2004
*Current DHS documents may be accessed at https://www.dhs.gov/dhs-security-and-training-requirements-Contractors
3.0 GENERAL REQUIREMENTS
The Contractor shall perform all work necessary to fabricate and deliver the specified CLP X-Ray System. The Contractor must meet or exceed all technical specifications.
The CLP X-ray systems shall conform to OSHA Standards, (29 CFR 1910.120), NFPA 79, Chapter 4, and NFPA 70, Article 110 requirements. The Contractor shall perform the work necessary to develop, test and deliver the procured equipment. The Contractor shall also provide warranty, maintenance, and training in support of these SS-NII systems as identified in the Technical Specifications Section 3.2 (see Appendix A). The Contractor shall prepare Monthly Progress Reports in accordance with the attached DID A006 while performing tasks within this SOW.
3.1 Requirement Definitions:
Threshold: The minimum level of operational performance that the Government is willing to accept is considered a threshold value. A system that does not meet one or more threshold requirements will not be accepted.
3.2 Performance Requirements
Appendix A contains the performance requirements matrix.
3.2.1 Computer Security Requirements
All CLP X-ray system computers shall comply with the IT policies captured in DHS 4300A Sensitive Systems Policy and Sensitive Systems Handbook referenced in Section 2.
All SS-NII System computers and software programs that enable a User to analyze/enhance images and store an Image Data Set (IDS), and the Data Base computers and programs that store an IDS, shall have the following features incorporated. Computers and server(s) with enough memory and speed to meet all the requirements of this SOW and its appendices (see Appendix A). Computer operating systems shall be Windows 7 64bit operating system or greater; capable of upgrade to Windows 10. The system shall have a wireless technology that can be encrypted in accordance with DHS 4300A Section 4.6 Wireless Network Communications, or its replacement. The wireless capability shall have the ability to be disabled when not in use. Each system shall have the capability to tag each scan with the username. The username shall be displayed with the image and the Data Set.
See Appendix A for contents of an IDS which shall be created for each system scan.
3.2.2 Identification and Authentication
A. Levels of Access – The Contractor shall provide three levels of CBP User access: Operator, Supervisor, and Administrator. Operator shall be able to perform all system functions except copying and deleting images or Data Sets.
Operator shall not have access to User Accounts. Operator and Supervisor shall not have access to the Graphical User Interface (GUI). Supervisor shall be able to perform all Operator functions plus be able to create Operator accounts and be able to copy and delete images or Data Sets. Supervisor shall have access to Operator Accounts, and reset Operator and Supervisor passwords. The Administrator shall be able to perform all Operator and Supervisor functions plus have access to all Accounts. The Administrator shall be able to create, edit, and/or delete all Level Accounts. The Contractor shall create a simplified procedure for the Administrator and Supervisor to use in order to create, edit, and delete User Accounts. Operator and Supervisor shall not have access to Windows except for those hard drives that have IDS stored on them or the external drives from which an image may be imported or an image or IDS may be exported or copied. The CBP Administrator Account shall have access to Windows Operating System.
B. Passwords – All passwords used to access the CLP X-ray Systems for operation are required to be Strong Passwords. Strong Passwords have the following requirements:
1. Are at least 12 characters in length
2. Comply with the DHS hardening guidelines for operating systems and the configuration guides for applications. In the absence of guidance, the Information Systems Security Officer (ISSO) will determine the appropriate password complexity based on the level of risk.
3. Strong password must contain at least one (1) Uppercase letter, one (1) Lowercase letter, one (1) base 10 number, and one (1) special character.
4. Strong passwords do not contain any dictionary word
5. Strong passwords do not contain any proper noun or the name of any person, pet, child, or fictional character.
6. Passwords do not contain any employee serial number, Social Security
Number, birth date, phone number, or any information that could be readily guessed about the creator of the password.
7. Strong passwords do not contain any simple pattern of letters or numbers, such as “qwerty” or “xyz123”.
8. Strong passwords do not contain any word, noun, or name spelled backwards or with a single digit appended, or with a two-digit “year” string, such as 98xyz123.
9. Strong pass phrases, if used in-addition to or instead-of passwords, follow the same guidelines.
10. Strong passwords are not the same as the User Identification (ID).
11. Are not the same as any of the User’s previous 8 passwords
C. The CLP X-ray system must have the ability to:
1. Deactivate unused accounts automatically if they have not been used in 45 days.
2. Passwords should not be set to the null string.
3. Automatic password change frequency. The system shall require the user to change their password every 90 days.
4. Password Storage – The system shall store all user account passwords in encrypted form.
3.2.3 Access Control
A. Unique User Accounts – The CLP X-ray System shall enable all users to have unique account identifiers, including separate identifiers for operator accounts and administrator accounts.
B. Automatic Account Lockout – CLP X-ray System shall lock a user account for twenty (20) minutes after three consecutive failed logon attempts.
C. Username shall be visible to show username at login.
D. Automatic Session Termination – CLP X-ray System shall lock the user login session after twenty (20) minutes of inactivity. The system shall require the user to authenticate with the user account password to regain system access after the system lock. After (60) minutes of inactivity, the system shall log the user out of the system.
E. Warning Banner – The DHS Chief Information Security Officer (CISO) mandates that a warning banner statement be displayed on all DHS systems during User account logon. The system shall prompt the User to accept the current language before the user can authenticate with the User ID and User password to access the system. The current language required follows:
1. You are accessing a U.S. Government information system, which includes
(1) this computer, (2) this computer network, (3) all computers connected to this network and (4) all devices and storage media attached to this network or to a computer on this network. This information system is provided for U.S. Government-authorized use only.
2. Unauthorized or improper use or access of this system may result in disciplinary action, as well as civil and criminal penalties.
3. By using this information system, you understand and consent to the following:
a. You have no reasonable expectation of privacy when you use this information system; this includes any communications or data transiting, stored on, originated from or directed to this information system. At any time, and for any lawful Government purpose, the Government may monitor, intercept, search and seize any communication or data transiting, stored on, originated from or directed to or from this information system.
b. The Government may disclose or use any communications or data transiting, stored on, originated from or directed to or from this information system for any lawful Government purpose.
You are NOT authorized to process classified information on this information system.
3.2.4 Auditing
A. Audit Records – CLP X-ray System will retain audit records sufficient in detail to facilitate the reconstruction of events if compromise or malfunction occurs. Audit records shall contain at least the following information:
1. Identity of each user and device accessing or attempting to access the system
2. Time and date of the access and the logoff
3. Activities that might modify, bypass, or negate information security safeguards
4. Security – relevant actions associated with processing
5. All activities performed using an administrator account/identity
B. Audit Record Access – Audit records and audit logs should be protected from unauthorized access, modification, or destruction.
C. Audit Record Retention – Audit records should be maintained on the system for a minimum of ninety (90) days. Audit records shall be preserved for a period of 7 years as part of managing records for each system to allow audit information to be placed online for analysis with reasonable ease.
D. Audit Reduction / Report Generation – The CLP X-ray System will provide an audit reduction and report generation capability that:
1. Supports on-demand audit review, analysis, and reporting requirements and after-the-fact investigations of security incidents
2. Without altering the original content or time ordering of audit records
E. The CLP X-Ray System will have the capability to tag each scan with the username who conducted it. The username and time shall be displayed with the image and the IDS.
F. Any report that is created shall include a username field.
3.2.5 Printed Documents
All SS-NII Systems shall have the capability of printing all the items of an IDS. All printed documents shall have "FOR OFFICIAL USE ONLY – LAW ENFORCEMENT SENSITIVE" in the header or footer. The footer shall contain system type and location.
3.3 System Integration
Integration of NII inspection system equipment and its supporting Subsystems shall be the responsibility of the NII systems Contractor.
3.3.1 System Installation
In order to verify that the SS-NII system can be deployed to the designed CBP deployment location, the Contractor, upon written request, shall support a Site Survey at each of the POEs. The Contractor shall support the Site Survey at least 60 days prior to the CBP Site Acceptance Test. Upon completion of the survey, the Contractor shall submit a Site Survey Report in the Contractor’s format within 15 days to the CBP-ITB Facilities Coordinator. The report is to be in a CBP approved Contractor's format. The Site Survey Report shall, at a minimum, address the items listed in DID A005 Equipment Installation Data. Additional system installation information, if required, may be identified in the Performance Requirements Section of this SOW.
3.3.2 Work Center
The Contractor shall deliver a work center that is ergonomically designed in accordance with DHS standards found in Human Engineering Design Criteria Standards Part 1:
Project Introduction and Existing Standards, DHS S&T TSD Standards project, (NISTIR 7889), Section 5.2.9, at http://nvlpubs.nist.gov/nistpubs/ir/2014/NIST.IR.7889.pdf.
3.3.3 Workstation Integration and Interface
The Contractor shall configure and integrate all workstations/servers and computer software/operating systems to include a system Operator Console. The system controls and displays enables a conveyance to be scanned; the conveyance image(s) to be analyzed; a system operator to make a Suspect or Non-suspect decision and storage of all the items associated with the scan into an IDS and the storage/retrieval of the IDS.
Operator Console shall have Dynamic Zoom, backspace, and clear functions, all icons to be placed with other functions icons. The Contractor shall meet additional integration requirements such as computer hardware/software technology refresh requirements, if applicable, are specified within Section 3.2 (see Appendix A).
3.3.4 Integrated Image Capture
All SS-NII Systems shall be capable of capturing and displaying all of the items that are contained in an IDS. The IDS shall include, as a minimum, the radiographic image, a Data Sheet or Manifest, operator notes, the operator’s Suspect or Non-suspect decision and the User's name. The Contractor shall meet additional IDS element requirements, specified in Section 3.2 (see Appendix A). All Metadata shall be the sole property of CBP and shall not be released or distributed without explicit consent of the Contracting Officer.
3.3.5 Integrated Image Storage
All CLP X-ray Systems shall be capable of storing all IDS created for a period of 90 Days with up to two (2) Terabyte of storage. A warning shall be provided when the hard drive used to store the IDS files reaches 85% of its maximum storage capacity. The warning shall alert the Operator for the need to archive IDS files. Auto-deletion of Non- Suspect files to start at 90% capacity and delete to 60% of storage capacity.
The system shall provide an option at the Administrator level for auto delete of Non- Suspect files that are over 90 days old.
3.3.6 Integrated Data Set Download
All CLP X-ray Systems shall be capable of exporting an IDS in its native language to external media via encrypted USB flash drive and encrypted external hard drive. The IDS shall consist of the data specified within section 3.2 (see Appendix A). The consolidated IDS shall encompass all of the data required to perform an offsite scan review and analysis as though the reviewer were stationed at the original data site. The system shall also be capable of creating and exporting a summary scan report for each conveyance scanned – the format of this report shall be PDF. The image data shall be configured in a format that allows the Government to easily transfer the image from one computer containing the image analysis software to another computer containing the image analysis software without the loss of the image analysis functionality.
3.3.7 Safety Interlocks
The Contractor shall provide safety interlocks such as operator proximity/presence sensors or "dead man switches" for all systems for the protection of pedestrian traffic and untrained personnel.
The Contractor shall provide an Operator’s Mat and Emergency Stop Switches for all systems that will enable an operator to manually interrupt the scanning process by disabling the emission of X-rays in an emergency or when there is an unauthorized entry inside the system's Radiation Control Area. The number and locations of the emergency stops shall be as specified in the performance requirements Section 3.2 (see Appendix A). See ANSI N43.3-2008, paragraph 7.5.2, and ANSI N43.14-2011, chapter 6.1, for more details on safety interlocks. The SS-NII systems shall also provide audible and visible (flashing lights) alarms when actively radiating.
3.4 Reliability, Availability and Maintainability Design Requirements The Contractor shall design the CLP X-ray System to meet the Reliability, Availability and Maintainability (RAM) requirements for Inherent Availability (Ai) and Operational Availability (Ao) (see section 4.6). The following are minimum requirements for these systems.
3.4.1 Basic System Reliability Requirements – Inherent Availability (Ai) The CLP X-ray System and all its components shall be designed to operate satisfactorily at a given point in time when used under the stated conditions in the environment described in this statement of work. It excludes logistics time, waiting or administrative downtime, and preventative maintenance downtime. It includes corrective maintenance downtime. Inherent availability is generally derived from analysis of an engineering design and is calculated as the mean time between failures (MTBF) divided by the MTBF plus the mean time to repair (MTTR).
The Inherent System Availability for each serialized system shall be calculated annually based on a 365 day year. For this Ai, a minimum of 0.9900 must be achieved for each year for the entire 10 year life cycle for this system. The Ai is calculated using the following:
Ai = Mean Time Between Failures (MTBF) Mean Time Between Failures (MTBF) + Mean Time to Repair (MTTR)
3.4.1.1 Mean Time Between Failures (MTBF)
The time between failures (TBF) is the time duration from the start of when the system is placed into an ‘operational’ status until suffering a failure. A failure is defined as a malfunction that degrades performance or operational capability, which cannot be tolerated for even a brief period before correction. The total time between failure (TTBF) is the sum of all TBFs for the reporting period. The mean time between failures (MTBF) is calculated as the TTBF divided by the total number of failures for that reporting period. The overall system shall be designed to possess a MTBF of no less than 1000 hours. The Government will calculate the MTBF on an annual basis.
The MTBF for each serialized system shall be calculated annually using a 365-day (8760 hours) reporting period by using the following:
MTBF = Total Time Between Failures (TTBF) Total Number of Failure Incidents
3.4.1.2 Mean Time to Repair (MTTR)
The time to repair (TTR) is the time duration from the start of a repair activity to correct a failure until the system is returned to full performance and capability. The total time to repair (TTTR) is the sum of all TTRs for the reporting period. The mean time to repair (MTTR) is calculated as the TTTR divided by the total number of repair activities for that reporting period. The overall system shall be designed to possess a MTTR to achieve the Ai requirement. The Government will calculate the MTTR on an annual basis.
The MTTR for each serialized system shall be calculated annually using a 365-day (8760 hours) reporting period by using the following:
MTTR = Total Time to Repair (TTTR) Total Number of Repair Activities
3.4.1.3 Life Cycle Expectation
The designed operating life of the system shall be no less than 10 years. The system shall be capable of exceeding a normal operating period of 16 hours a day, 6 days a week, 52 weeks a year during an operating life of 10 years and be capable of surge operations consisting of 24 hours a day, 7 days a week for 2 weeks (336 hours).
3.4.2 Predictive Reliability, Availability, and Maintainability Analysis The Contractor shall provide predictive Obsolescence Analysis of system components and a Component Replacement Analysis in the Contractor’s format at time of quote, see DID A002. The Component Replacement Analysis shall include:
A. Procedures for the procurement of critical items, to include availability and procurement lead times.
B. Criteria and procedures for the design and redesign of critical items C. Procedures for controlling and monitoring of critical items after manufacture to meet the Ai and Ao requirements (e.g., date coding, traceability, assembly techniques, test requirements, acceptance test requirements, control of sub- Contractors’ and manufacturers’ controls, in-process controls, special handling, and storage requirements).
3.4.3 Classification of Reliability Critical Items
A Critical Item is an identified weak link in a system, has an adverse impact on, or contributes to failures of the system performing its mission, creates potential safety problems, or contributes to other areas of high risk to overall system reliability. The Contractor shall classify all SS-NII items as critical if one or more of the following conditions are satisfied:
1. Item represents a significant new development or application.
2. Item has critical failure modes.
3. Item has history indicating need for improvement. A Preplanned Product
Improvement Plan (PPIP) shall be developed and provided by the Contractor for any item with a history of needing improvement.
4. Item has known operating life, limited shelf life, or environmental sensitivity (e.g., vibration, thermal, etc.) that warrants controlled surveillance.
5. Item whose failure can result in the failure of the system and which is not compensated by redundancy or alternate operational procedures
3.4.4 Control of Reliability Critical Items
The Contractor shall be responsible for the control and Quality Control (Contractor shall address in DID number A012 Quality Assurance/Quality Control Plan) of critical items, which shall include as a minimum:
1. Procedures for the procurement of, and availability of, spares of critical items
2. Criteria and procedures for the design and redesign of critical items
3. Procedures for controlling and monitoring of critical items after manufacture
(e.g., date coding, traceability, assembly techniques, test requirements, acceptance test requirements, control of sub-contractors' and manufacturers' controls, in-process controls, special handling and storage requirements).
3.4.5 Corrosion Control
The Contractor shall apply corrosion control techniques and measures to mitigate and correct corrosion of the system. The Contractor shall visually inspect the equipment for signs of corrosion. The Contractor shall apply best industry standards and practices to remove corrosion or replace parent material, properly treat and prepare surfaces for painting, and apply a color-matched finish and prevent future corrosion.
3.5 Quality Assurance/Quality Control Plan
The Contractor shall provide a Quality Assurance/Quality Control (QA/QC) plan based on the most current and applicable certified ISO processes and procedures. The Contractor’s QA/QC plan shall define key performance measures to include traceable metrics, verifiable performance standards, and address risk identification and mitigation processes used to meet the performance requirements in this SOW.
The Contractor shall provide a QA/QC Plan in accordance with DID A012.
3.6 Testing
The Contractor shall prepare and submit an Acceptance Test Plan (ATP) in accordance with the attached DID A013. The Contractor shall perform inspections and tests necessary to ensure that CLP X-ray Systems conforms to CBP approved technical documentation and configuration, to include operational testing of the first article delivery. Using the approved ATP, the Contractor shall conduct verification and validation tests to ensure the system meets all performance requirements and to verify it can be operated as specified in the system’s Operator’s Manual (DID A008). Additional Contractor testing requirements, if applicable, are identified in the performance Section
3.2 (see Appendix A) of this SOW. The Contractor shall provide the test articles as defined in ANSI N42.46, Chapter 4, to affect this level of testing.
3.6.1 Factory Testing
A CBP team shall conduct a CBP Factory Test (FT) of all units at the Contractor’s facility in accordance with the ATP (DID A013) to verify that the unit is suitable for shipment to its intended deployment location, including proper assembly, functionality, and operation. The CBP team will conduct an FT in accordance with a CBP FT Plan for all systems. The Contractor shall provide the appropriate test articles for the CBP team in support of the FT.
3.6.2 Site Acceptance Testing
A CBP team will conduct a CBP Site Acceptance Test (SAT) for each unit at its designated deployment location. The CBP team will conduct the CBP SAT in accordance with a CBP SAT Plan (SATP) for CLP X-ray system. The CBP SAT shall consist of a review of the Contractor’s pre-SAT documentation and Radiation Survey/Leak Test Report (DID A015), plus an inventory and physical inspection of the system, system component operations and tests of the total integrated system against actual targets. The Contractor shall be required to provide test articles for the SAT as determined by the SATP or the Test Director. This allows CBP to verify that the system has not been physically damaged nor performance impacted due to transport of the system. The CBP SAT will not occur until the Contractor has trained the SAT team members, no later than 7 days before the SAT date.
3.6.3 Discrimination Testing
In the absence of an ANSI for Material Discrimination, the CBP team will test the following characteristics, using the following or similar test fixtures. Two characteristics must be demonstrated.
The first characteristic is the system’s ability to differentiate and identify the three categories of material (organic, intermediate, and metallic) from each other as a function of color when they are placed in close proximity to one another. The materials suggested are HDPE, Aluminum (Al), Steel, and Lead (Pb). The materials used shall all have the same attenuation, which can be between 20X and 50X. The test fixture used should be able to hold at least two plates of each material. The CBP team will determine success based on the number of plates where at least 50% of the surface is the correct color. Twelve scans will be required and 90% of the plates must display the proper color.
The second characteristic to be demonstrated is the system’s attenuation range for two of the materials. For a three material category system, the two materials used shall be HDPE and Steel. For a four material category system, the two materials used can be either HDPE & Steel or Al & Pb. There shall be at least 7 different thicknesses (steps) of each material. One step shall be so thin that the system cannot properly identify the material and therefore it appears gray. One other step shall be so thick that the system cannot properly identify the material and therefore it appears black. All the other steps shall vary in color intensity as a function of their thickness (the thicker the step, the more intense the color). Success is based on the number of steps where at least 75% of the surface is the correct color intensity. Twelve scans will be required and 90% of the steps must display the proper color intensity.
3.7 System Safety Program
The Contractor shall maintain a system safety program that continually identifies all hazards and provides a methodology to either eliminate or control these identified hazards.
3.7.1 Radiation Safety
The Contractor shall provide a radiation dose map in the Contractor’s format for the system that shows the personnel safety zone and radiation portal monitor (RPM) interference zone. All products, designs, and specifications provided and all construction and installation activities conducted shall comply with all OSHA, as well as any other appropriate laws, regulations, standards, codes and health and safety guidelines.
3.7.2 Radiation Safety Design Review
The Contractor is required to demonstrate, during factory testing, the construction techniques, practices and design of the protective shielding/cabinet interfaces (corner joints, collimator joints, imaging source housing, etc.) and shall be in compliance with ANSI N43.3- 2008, Chapter 7, and N43.14-2011 Chapter 6.0, standards for their system.
The Contractor shall ensure that any movement or shifting that may be associated with shipping will not produce or lead to emission leaks from cracks, stress or misalignment of the structures and shielding devices that are either associated with the primary beam containment or scatter containment scheme.
3.7.3 Radiological Survey and Report
The Contractor shall be required to conduct a radiological survey prior to system delivery to ensure that radiation emissions are within specified limits. Each system delivered shall be accompanied with a report of the radiological survey performed on the system, signed by the Radiation Safety Officer of the company. This survey will address both the radiation levels that system operators will be exposed to while at their workstations and the level of radiation that is transmitted to the environment as a result of system leakage. The report shall show that by means of an outline drawing the levels of emission/scatter radiation measured, the ‘worst case’ operating conditions (i.e.
highest energy level, slowest scan speed, greatest scatter range) and the measurement equipment used. The Contractor shall provide a radiological survey report and a Radiation Survey Report or Leak Test Report as applicable in accordance with the attached DID A015 for each system delivered.
3.7.4 Annual Radiation Survey and Report
The Contractor shall perform Radiation Surveys at the time of delivery site prior to site acceptance and annually thereafter for the systems that contain radiation emitting devices (X-Ray systems). The X-ray systems shall be in compliance with 21 CFR 1020.31, Radiographic Equipment, (a) Control and indication of technique factors (energy, time, and amperage) and (b) Reproducibility (ability of device to produce consistent radiation doses). The Contractor shall provide a radiation survey report to the NII Operations Center within 48 hours of completion. A representative/sample Radiation Survey Report shall be submitted with the quote and each Site Acceptance Test in accordance with DID A015.
3.7.5 Safety Plan
In accordance with 29 CFR 1910.120, Occupational Safety and Health Standards (OSHA), Appendix D, paragraph 8, the Contractor shall develop and implement a safety plan. The Contractor’s safety plan in the Contractor’s format shall also continually identify all safety hazards and provide a methodology to mitigate or eliminate each of the identified hazards, see DID A023.
All products, designs and specifications provided and all construction and installation activities conducted shall comply with all OSHA and General Services Administration
(GSA) regulations, as well as any other appropriate laws, regulations, standards, codes and health and safety guidelines.
3.7.6 Hazardous Materials
In accordance with 29 CFR 1910.1200 (e)(2), Occupational Safety and Health Standards (OSHA), the Contractor shall provide a list of all hazardous materials and the corresponding Material Safety Data Sheet (MSDS) for each identified Hazardous Material. The list shall include the material description, quantity of the material, storage and disposal instructions, exposure risks, symptoms and treatments. The list shall be prepared in accordance with DID A004 and be maintained in the Technical Documentation Package throughout the life of the NII system. The list shall be derived for the Hazardous materials identified in the 49 CFR Part 172, Subpart B - Table of Hazardous Materials and Special Provisions.
3.8 Information Technology Security
The Contractor shall adhere to all DHS and CBP IT security policies and the basic requirements, security authorization, encryption compliance, and pass security review.
3.8.1 Basic Requirements
The Contractor shall adhere to all DHS and CBP IT security policies, including the guidelines and policies stated in the DHS Sensitive Systems Policy Directive 4300A, chapters 4 and 5, or any subsequent, replacement or revised publication. This policy mandates DHS organizational elements, including Contractors, follow guidelines outlined in the DHS 4300A, Sensitive Systems Handbook, Information Technology Security Program, version 12, 11/15/15 with attachments or any subsequent, replacement or revised publication.
DHS Directive 4300A, Section 3.1 Basic Requirements outlines the management, operational and technical baseline security requirements (BLSR) for DHS Components to ensure confidentiality, integrity, availability, authenticity and non-repudiation of sensitive information systems. The 4300A Handbook provides greater detail of the BLSRs, including the roles and responsibilities associated with each.
CBP will provide personnel with the appropriate clearance levels to support the security certification/accreditation processes under this Agreement in accordance with DHS MD 4300A, DHS Sensitive Systems Policy and Handbook, paragraph 4.1.1.d. During all systems development life cycle (SDLC) phases of CBP systems, CBP personnel will develop documentation and provide any required information for all levels of classification in support of the certification/accreditation process. In addition, all security certification/accreditation will be performed using the DHS certification/accreditation process, methodology and tools.
3.8.2 Security Authorization
a. A Security Authorization of any infrastructure directly in support of the DHS information system shall be performed by the Contractor as a general support system (GSS) prior to DHS occupancy to characterize the network, identify threats, identify vulnerabilities, analyze existing and planned security controls, determine likelihood of threat, analyze impact, determine risk, recommend controls, perform remediation on identified deficiencies, and document the results. The Security Authorization shall be performed in accordance with the DHS Security Policy and the controls provided by the hosting provider shall be equal to or stronger than the Federal Information Processing Standards (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems, Section 3, security categorization of the DHS information system.
b. At the beginning of the contract, and annually thereafter, the Contractor shall provide the results of an independent assessment and verification of security controls in the Contractor’s format. The independent assessment and verification shall apply the same standards that DHS applies in the Security Authorization Process of its information systems. Any deficiencies noted during this assessment shall be provided to the COR for entry into the DHS’ Plan of Action and Milestone (POA&M) Management Process. The Contractor shall use the DHS’ POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies shall be corrected within the timeframes dictated by the DHS POA&M Management Process. Contractor procedures shall be subject to periodic, unannounced assessments by DHS officials. The physical aspects associated with Contractor activities shall also be subject to such assessments.
c. On a periodic basis, the DHS and its Components, including the DHS Office of Inspector General, may choose to evaluate any or all of the security controls implemented by the Contractor under these clauses. Evaluation could include, but is not limited to vulnerability scanning. The DHS and its Components reserve the right to conduct audits at their discretion. With ten working days’ notice, at the request of the Government, the Contractor shall fully cooperate and facilitate in a Government-sponsored security control assessment at each location wherein DHS information is processed or stored, or information systems are developed, operated, maintained, or used on behalf of DHS, including those initiated by the Office of the Inspector General. The Government may conduct a security control assessment on shorter notice (to include unannounced assessments) determined by DHS in the event of a security incident.
3.8.3 DHS Security Policy Requirement
All hardware, software, and services provided under this contract must be compliant with DHS 4300A DHS Sensitive System Policy, Section 4.8, and the DHS 4300A Sensitive Systems Handbook, Section 4.8.
3.8.4 Encryption Compliance Requirement
All systems drives provided under this contract must be DHS encryption compliant.
The following methods are acceptable for encrypting sensitive information:
• Products using FIPS 197 Advanced Encryption Standard (AES), Chapter 5, algorithms with at least 256 bit encryption that has been validated under FIPS 140-2 Security Requirements for Cryptographic Modules, Chapter 4.
• National Security Agency (NSA) Type 2 or Type 1 encryption
3.8.5 Security Review
The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS including the organization of the DHS Office of the Chief Information Officer, Office of Inspector General, the CBP Chief Information Security Officer, authorized Contracting Officer’s Representative (COR), and other Government oversight organizations, access to the Contractor’s and subcontractor’s facilities, installations, operations, documentation, databases, and personnel used in the performance of this contract. The Contractor will contact the DHS Chief Information Security Officer to coordinate and participate in the review and inspection activity of Government oversight organizations external to the DHS.
The Contractor shall provide access to the extent necessary for the Government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of DHS/CBP data or the function of computer systems operated on behalf of DHS/CBP, and to preserve evidence of computer crime.
3.8.6 Access to Unclassified Facilities, Information Technology (IT) Resources, and Sensitive Information
IT resources, and sensitive information during the acquisition process and contract performance are essential to the DHS mission. DHS Management Directive (MD)
11042.1 Safeguarding Sensitive But Unclassified (For Official Use Only) Information paragraph 6, describes how Contractors must handle sensitive but unclassified information. DHS Sensitive Systems Policy Directive 4300A, paragraph 3.14.1, and DHS Sensitive Systems Handbook, MD 4300, an Information Technology Security Program, Chapter 4, prescribe policies and procedures on security for IT resources. Contractors shall comply with these policies and procedures, any replacement publications, or any other current or future DHS policies and procedures covering Contractors specifically for all task/delivery orders that require access to DHS facilities, IT resources or sensitive information. Contractors shall not use or redistribute any DHS information processed, stored, or transmitted by the Contractor except as specified in the contract.
Contractors who require access to the DHS network, such as when conducting remote maintenance, require a background investigation in accordance with DHS MD 4300A Sensitive Systems Policy and Handbook, MD 4300.A, paragraph 4.1.1.d.
3.8.7 Personal Identity Verification of Contractor Personnel
a. The Contractor shall comply with agency personal identity verification procedures identified in the contract that implement Homeland Security Presidential Directive-12 (HSPD-12), Policy for a Common Identification Standard for Federal Employees and Contractors, paragraph 3, Office of Management and Budget (OMB) guidance M-05-24, Appendix A, chapters 3 and 4, and Federal Information Processing Standards Publication (FIPS PUB) Number 201-2, Personnel Identity Verification of Federal Employees and Contractors, Section 2.
b. The Contractor shall insert this clause in all subcontracts when the subcontractor is required to have routine physical access to a federally -controlled facility or routine access to a Federally-controlled information system.
3.8.8 Security Requirements for Unclassified Information Technology Resources
a. The Contractor shall be responsible for Information Technology (IT) security for all systems connected to a DHS network or operated by the Contractor for DHS, regardless of location. This clause applies to all or any part of the contract that includes information technology resources or services for which the Contractor must have physical or electronic access to sensitive information contained in DHS unclassified systems that directly support the agency’s mission.
b. The Contractor shall provide, implement, and maintain an IT Security Plan. This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract.
(b.1)…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .