Attachment_15_RDTE_LAN_SOP_vNov16.docx
DOCX document 123 KB Posted
- Attached to
- Deployed Mission Support (DMS) Federal contract opportunity
- Solicitation number
- N00421-16-R-0073
About this file
This document provides a draft solicitation for deployed mission support services. The Naval Air Warfare Center Aircraft Division Special Communications Mission Solutions Division requires technical, engineering, operations, and maintenance support for forward deployed mission communication-electronic equipment and systems supporting overseas military units. Services include inspection, troubleshooting, maintenance, modification, logistics support, configuration management, and training for legacy and current systems located in Central Command and Africa Command areas of responsibility. The contractor must provide personnel able to rapidly support deployed forces and rotate every six months between overseas locations. The final solicitation is expected within 30 days under solicitation number N00421-16-R-0073. The requirement is a follow-on to contract N00421-16-C-0035 and the incumbent is BAE Systems Technology Solutions & Services.
Attachment 15 - RDTE LAN SOP
View the file
Other files for this federal contract opportunity
Show all 35
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SCMS Non-Navy RDT&E Network SOP
Special Communications Mission Solutions Division Code 4.11.4
Non-Navy Research, Development, Test and Evaluation Network Standard Operating Procedures (Contract Document Version)
23 August 2016 Version 9
TABLE OF CONTENTS
| STANDARD ARCHITECTURE (HARDWARE/SOFTWARE) | 3 |
| Workstation/Desktop | 3 |
| Portables | 4 |
| Smart-phones | 4 |
| LICENSING | 4 |
| Workstation\Portable | 4 |
| Shareware\Freeware | 5 |
| NEW WORKSTATIONS | 5 |
| NEW HARDWARE PERIPHERALS AND SOFTWARE | 6 |
| PROPERTY TAGGING AND APPROVAL | 6 |
| NETWORK ACCOUNTS | 6 |
| New User Accounts | 6 |
| Inactive Accounts | 6 |
| Removal of Accounts | 6 |
| NAMING CONVENTIONS | 7 |
| User Accounts | 7 |
| Workstations | 7 |
| E-Mail Addresses | 7 |
| Network and Phone Jacks | 8 |
| Printers | 8 |
| COMMON ACCESS CARD (CAC) LOGON | 8 |
| INTERNET ACCESS, USAGE AND MONITORING | 8 |
| BACKUPS | 8 |
| Network | 8 |
| Workstations | 9 |
| Previous Versions | 9 |
| NETWORK DRIVES | 9 |
| Inappropriate Files | 9 |
| Restricting Directories | 10 |
| 10 | |
| Personal Folders (PST) | 10 |
| Outlook Web Access | 10 |
| REMOTE ACCESS | 11 |
| FTP | 11 |
| VTC | 11 |
| EXCESS EQUIPMENT | 12 |
| NETWORK DIAGRAM | 12 |
| SECURITY | 12 |
| Accreditation | 12 |
| Reporting Suspected Violations | 12 |
| Network Ports / Connection Approval | 12 |
| Screen Savers | 12 |
| DOD Banner | 12 |
INTRODUCTION
All personnel using and having user accounts on the Special Communications Mission Solutions (SCMS) Division Non-Navy Research Development Test and Evaluation (RDT&E) Network must conform to this Standard Operating Procedures (SOP). This ensures that network\user hardware\software is compatible allowing for efficient troubleshooting and proper use of assets. This SOP pertains to all Government Funded Equipment (GFE) and Contractor Funded Equipment (CFE) connecting to the SCMS RDT&E Network only.
Computers in the 4.11.4 buildings that are not connected to the SCMS RDT&E Network will not be supported by the SCMS LAN Team and are not governed by this SOP. This SOP in conjunction with a Concept of Operations (CONOPS) and System Security Plan (SSP) shall serve as the governing documents for the SCMS RDT&E Network. This is a dynamic document in which input from the end user is solicited to ensure that efficient, secure network operation is provided to SCMS users. For brevity, the SCMS Non-Navy RDT&E Network will be referred to as ‘the network’ from this point forward in this document.
STANDARD ARCHITECTURE (HARDWARE/SOFTWARE)
In order to maintain compatibility using SCMS’s available resources, a standard architecture has been established. The standard architecture is a minimum, and must be used when ordering new computers. Additional hardware/software can be ordered as needed, but must be Windows 10 Enterprise Edition 64 bit compatible and must conform to the specifications outlined in this document. Internet support from the manufacturer of the hardware and software must be available.
Workstation/Desktop
| Hardware |
| Software |
· Processor: 64-bit processor (Intel Core i7 or better recommended)
· Hardware-assisted virtualization capable (i.e. Intel VT or AMD-V)
· Hardware-enforced Data Execution Prevention (DEP) must be available and enabled
· RAM: 4 GB (8 GB+ or better recommended)
· Hard drive: 500 GB 7200 RPM SATA
· Video Card: Integrated HD graphics (DVI)
· Optical Drive: DVD-ROM/CD Writer
· Monitor: Capable of 1920 x 1080 or higher resolution
· 100/1000 Integrated Network Card
· USB Keyboard
· USB mouse
· CAC Reader – can be integrated into the keyboard or an external USB reader
· Windows 10 Enterprise Edition 64 bit
· Microsoft Office 2013 (32bit only)
· Anti-virus (Government Site license)
· ActivCard CAC Reader software (6.2)
Portables
Portables are to be used for remote/web access only. The use of laptops and docking stations on the network is prohibited.
| Hardware |
| Software |
· Processor: 64-bit processor (Intel Core i7 or better recommended)
· Hardware-assisted virtualization capable (i.e. Intel VT or AMD-V)
· Hardware-enforced Data Execution Prevention (DEP) must be available and enabled
· RAM: 4 GB (8 GB+ or better recommended)
· Hard drive: 500 GB 7200 RPM SATA
· Video Card: Integrated Intel graphics
· Optical Drive: 8X CD/DVD Writer
· Display: Capable of 1366 X 768 or higher resolution
· 100/1000 Integrated Network Card
· Wireless: Wireless b/g/n compatible
· Windows 10 Enterprise Edition 64 bit
· Microsoft Office 2013 (3bit only)
· Anti-virus (Government Site license)
· ActivCard CAC Reader software (Government Only)
Smart-phones
Only government approved BlackBerry smart-phones are allowed to connect to the SCMS Blackberry server.
The SCMS LAN does not support any other smart-phone or tablet.
LICENSING
Workstation\Portable
SCMS provides the licensing to cover certain software applications running on the network servers. SCMS will provide the following software for the client workstations:
· Antivirus software
· Adobe Acrobat Reader
· Flash Player
· ActivCard CAC Reader software (Government Only)
· Windows Media Player
· Citrix
· Sun Java
The SCMS LAN Team is not responsible for maintaining the software or licenses for contractor or project assets.
It is the responsibility of the end user to provide legally licensed copies of any other software that is to be installed on their workstations. This includes the media any required license key/serial number. In the case of a site license, the user must have a copy of the site license, as well as, the number assigned from the site license allotment.
Responsibility for Providing License
| Government LAN |
| Project |
| Contractor |
| Operating System |
| X |
| X |
| X |
| MS Office Suite |
| X |
| Adobe Reader |
| X |
| Adobe Flash |
| X |
Adobe Acrobat
| X |
| X |
Microsoft Visio
| X |
| X |
Microsoft Project
| X |
| X |
Before the software can be allowed on the network, the government LAN Team lead and the Information Assurance Security Manager (IASM) must approve it for installation. Some common examples of software that is the responsibility of the end user to license are:
· Operating System (Windows 10 Enterprise Edition 64 bit )
· Microsoft Office 2013
· Microsoft Project 2013
· Microsoft Visio 2013
· Adobe Acrobat 11 or newer
· Adobe PhotoShop CS5 or newer
· AutoCAD
· Winzip
Shareware\Freeware
Only approved shareware/freeware is authorized on the network. The government LAN Team lead and the Information Assurance Officer (IAO) maintain a list of approved shareware/freeware.
NEW WORKSTATIONS
Orders for new workstations and laptops (GFE/CFE) connecting to the network must conform to the above standards for hardware and software. Also, approval for procurement must be obtained from the government LAN Team lead prior to ordering.
Please ensure that all new workstation requests have been checked against the Windows 10 Enterprise Edition 64 bit Hardware Compatibility List prior to requesting approval. When the new workstation arrives please submit a trouble report to temporarily transfer equipment to the network team for initial system set-up and installation on the network.
NEW HARDWARE PERIPHERALS AND SOFTWARE
New hardware peripherals and software to be installed on a workstation connecting to the SCMS network must be listed on the Windows 10 Enterprise Edition 64 bit Compatibility List and receive approval from the LAN Team lead prior to ordering. Please submit a trouble report when new peripherals arrive for installation by the LAN Team. A network administrator will install hardware and software, ensuring proper licensing has been obtained and compatibility with the network. All additional hardware and software considered essential to project operations will need to be submitted to the LAN Team for testing and evaluation. Once tested and approved it will be installed. No personal software or hardware will be installed on any workstation connected to the network.
PROPERTY TAGGING AND APPROVAL
All property must be tagged as NAWCAD, NAWCAD project, SCMS and/or CFE assets by the designated office. All CFE equipment must have Contract Officer Representative (COR) approval prior to connecting to the network. No personally owned computers are allowed to attach to the network.
NETWORK ACCOUNTS
A user account is required in order to gain access to resources on the network, including file shares, printers and the Intranet (Atlas). All requests to add a new user account or to remove an existing user account must be made via a SCMS LAN Trouble Report. This request can only be made by SCMS government personnel (contact the COR for specific processes).
New User Accounts
A user must have a SAAR-N form signed by the SCMS government LAN Lead and on file at NAVAIR before an SCMS account can be requested. In addition, the user must have a certificate showing they have completed the DoD Cyber Awareness Training. Requests for new user accounts should include the new user’s first name, last name, middle initial, government code or company, their start date, building and room number. The request should also detail any other privileges required by the new employee, such as access to project shares or email distribution group membership.
Inactive Accounts User accounts that have not been logged on to for 30 days will be disabled. You must contact the LAN Team in order to have your account re-enabled.
Removal of Accounts
Government Competency Leads and Contractor Leads will submit a trouble report to notify the LAN Team when their personnel are leaving. The LAN Team will disable the departing user’s account on their last day of employment. The Leads may also designate that the departing user’s files and email be transferred to a designated person. The account will remain disabled for 30 days before it is permanently deleted.
The LAN Team is required to closely monitor account activity and ensure that inactive accounts are removed in a timely manner.
User accounts that have been inactive for 180 days are permanently deleted by the LAN Team.
NAMING CONVENTIONS
User Accounts
SCMS will utilize the following naming convention for user accounts:
Firstname.Lastname
Workstations
The network workstations are named based on their location using the following standard naming convention:
(Building number)_(room number)_(alphanumeric designator)_(government/contractor designator).
The LAN Team has implemented network port security which associates your computer with a specific network jack.
You must submit a LAN trouble report if you need to move your computer for any reason.
This will allow the LAN Team to properly configure the connection to the network and change the computer name to reflect the new location.
The end user is responsible for physically relocating their computer equipment while the LAN Team is responsible for ensuring it can connect to the network.
When moving a NMCI asset, please submit a SCMS Team Trouble Report, stating the NMCI jack you are moving from and the NMCI jack you are moving to, along with Asset Number and Workstation Name.
E-Mail Addresses
Users who will work onsite in a Division 4.11.4 will be provided a SCMS e-mail address.
Users who work offsite will not be provided a SCMS e-mail address unless there is a documented need for it.
SCMS will utilize the firstname.lastname naming convention for the government users followed by @scms.navy.mil. For example: firstname.lastname@scms.navy.mil
SCMS will utilize the firstname.lastname.ctr naming convention for contractors followed by @scms.navy.mil. For example: firstname.lastname.ctr@scms.navy.mil.
Autoforwarding e-mail is prohibited on DoD networks. The SCMS LAN Team will not forward your SCMS e-mail to any another e-mail address.
Network and Phone Jacks
SCMS will ensure that all phone and network jack connections adhere to the following naming convention: Distant end number, rack number, patch panel number, and port number.
Printers
The network printers are named based on location using the following standard naming convention:
(Building number)_(room number)_(printer model)
COMMON ACCESS CARD (CAC) LOGON
A DoD CAC is required to logon to SCMS workstations. The CAC is a DoD Smart Card issued as the standard identification card for active-duty military personnel, reserve personnel, civilian employees, other non-DoD Government employees, state employees of the National Guard, and eligible contractor personnel. It allows holders to gain physical access to DoD facilities, and logical access to DoD computer systems and networks. Only part of DoD Industry personnel are eligible for a CAC. DoD contractors who are under a DoD contract, and are sponsored by a DoD Service or Agency, may be eligible for a CAC if their Government sponsor deems it necessary (per DoD Manual 1000.13). You should not allow another user to logon using your CAC under any circumstances. You should not leave your CAC unattended in a workstation at any time.
INTERNET ACCESS, USAGE AND MONITORING
Computers on the network are prohibited from using phone lines to dial-up to another Internet service provider. SCMS utilizes Internet monitoring software to verify appropriate Internet usage (appropriate use of the Internet is defined in the CONOPS or SSP). SCMS network users will not attempt to load mobile code such as Java applets and ActiveX not expressly authorized for use. Gambling and the access and/or storage of pornographic material are prohibited.
BACKUPS
Network
All network servers, applications and files are backed up on a daily basis. This will ensure that applications and files on all SCMS servers can be fully restored in case of hardware failure. Your work related data should be stored on a shared drive, such as your personal G: drive or the X: drive. The files saved to these drives are automatically backed up.
Workstations
The user is responsible for regularly backing-up files on their workstation to CDs or DVDs. The LAN Team will not attempt to recover non-work related data stored on your workstation.
Previous Versions
The LAN Team has implemented a feature that creates snapshots of the network drives at different times during the day. You can use this feature to recover files that may have been previously deleted. To do so, right click a network folder then select Properties. Click the Previous Versions tab to display a list of available folders with their timestamp. Click the View button to view the contents of the selected folder.
NETWORK DRIVES
End users can store their work related documents on the network drives. These network drives are backed-up nightly by the LAN Team. Each user has a G: drive as their personal home directory. No other user has access to your G: drive. The X: (Projects) and the K: (Common) drives allow project teams to create folders for sharing their project-related documents.
Current Network Drive Mappings and Location
| User Home Directory |
| G: |
| \\scrdata\userhomedirs\ |
| Projects Drive |
| X: |
| \\scrdata\projects\ |
Inappropriate Files
The network drives are not to be used to store personal files or any other non-work related documents. The LAN Team performs regular scans of the network drives for inappropriate files and will remove them as discovered. The LAN Team will be implementing restrictions on the type of files that can be stored on the network. If you wish to keep these types of files you should store them on the C: drive of your workstation. Examples of inappropriate files and documents include:
· Music files (MP3, WMA, WAV)
· Video Files (WMV, AVI, MOV)
· Personal pictures
· Contractor - proposals, personnel reports, assessments, resumes
· Non-work related emails stored in PST files
· Personal files – taxes, bank statements
Restricting Directories
Sub-directories on the X: (Projects) drive may be restricted so that they are only accessible by project team members. A trouble report must be submitted by the project’s government representative to request access to or creation of a restricted directory. The trouble report must include a list of personnel with the degree of accessibility (i.e., read, modify, view etc.). Users will not be provided with “Full Control” permissions on any network drive. Permissions will not be set on any network drives, directories, or files by anyone but the LAN Team.
Microsoft Exchange is the e-mail system for SCMS. MS Outlook is the client software utilized to access e-mail. All changes to the Global Address List must be requested by a government representative via a trouble report.
E-mail is for government business only. Global messages to all building personnel should be used on a limited basis. The allocation of mail storage for each user is limited to 400 MB. Once 350 MB are used, the user will receive a warning email. After the 400 MB limit has been reached the user will no longer be able to send or receive emails.
Personal Folders (PST)
Email containing work related data can be archived to Personal Folder (PST) files on the user’s PST directory (P: drive) which is located on the \\scrfile3\pst\ network drive. These PST files are to be limited to a size of 500MB or less. PST files stored on network drives should not be password protected. If a user chooses to password protect a PST file stored on a network drive, the LAN Team will not be responsible for recovering its password or data.
Emails containing non-work related data are not to be archived to PST files on the network drives. If you wish to archive non-worked related data, it must be stored in a separate PST file on the user’s local C: drive in a folder labeled "Mail". These PST files will not be included in the network backup schedule, and it is the user’s responsibility to back up this data onto removable media, such as CDs. Loss of personal data is not the responsibility of SCMS, and the LAN Team will not attempt to recover such data from non-network resources.
Outlook Web Access
Network users may access their email via the SCMS webmail site at https://mail.scms.navy.mil
This website is restricted and requires that you connect using your CAC card. You must first associate your CAC with your SCMS network account prior to accessing the site. Use the link below to associate your CAC with your SCMS network.
https://scrintranet.scms.navy.mil/cac/ad_link.cfm
External Certificaiton Authority Program The DoD has established the External Certification Authority (ECA) program to support the issuance of DoD-approved certificates to industry partners and other external entities and organizations. When there is a need for remote access ONLY follow the United States Department of Defense External Certification Authority X.509 Certificate Policy Version 4.4 (or higher if approved) 1 October 2015
REMOTE ACCESS
VPN access is available to users with high-speed Internet connections using the SCMS Network Access Page at https://scrnap.scms.navy.mil.
This website is restricted and it requires that you connect using your CAC card or Smart Card. You must have a signed Remote Access User agreement on file with the SCMS LAN Team.
In addition, you must have antivirus software installed on the computer that is connecting to the VPN. The virus definition must be updated and a full computer scan must have been completed within the last seven days. If your computer does not meet these criteria then it will not be allowed to connect to the VPN.
FTP
SCMS users have access to a FTP site for the purpose of transferring large files to clients that can’t be sent via e-mail. The FTP site is available at ftp://ftp.scms.navy.mil. Users must submit a trouble report to request a username and password in order to access the FTP site. Requiring separate usernames to access the site allows the LAN Team to maintain a separation of data per user and to track usage. All data files should be removed from the FTP site in a timely manner after they have been uploaded and then received by the recipient.
VTC
There is no VTC capability on the SCMS LAN at this time.
All requests to use the VTC must be accompanied by a trouble report and a conference room request. The user must reserve the date and time needed for the VTC using the Conference Room Scheduler on the Caddie Intranet. From the Caddie Intranet homepage, click Home and then click Conference Room Schedule. The VTC is located in Room 221 (Training). If the user will be connecting to an outside VTC, the trouble report must include the connection speed, remote end POC, and remote VTC phone number are required at the time of scheduling.
Please do not exceed your allotted time slot; others may be signed up for the subsequent time slot. The VTC Users Manual on the Caddie Intranet will explain how to use the system; any further questions or difficulties should be directed to the LAN Team via a trouble report.
EXCESS EQUIPMENT
Equipment no longer required by a user should be donated to the network. The LAN Team lead will determine if the equipment can be beneficial for use on the network.
NETWORK DIAGRAM
Various diagrams of the network are located in Room 314/321.
SECURITY
Network security is covered in SCMS’s CONOPS and SSP. Below are some key security items, but the SCMS CONOPS and SSP are the security-governing documents.
Accreditation
A designated approving authority at NAVAIR Competency 7.2 accredits the SCMS RDT&E Network.
Reporting Suspected Violations
Report suspected network security or misuse to SCMS’s IASO, Alternate Information Assurance Security Officer (AIASO) or IASM. The IASM, AISM, or NSO will report the incident to proper authorities within the chain of command.
Network Ports / Connection Approval
All workstations connecting to the SCMS LAN must go through a connection approval process with NAVAIR 5.4. Under no circumstance should a user disconnect a workstation from the network or attempt to reconnect a workstation to the network.
Screen Savers
Screen savers have been enabled on all computers connecting to the network. They will auto-lock after five minutes of inactivity.
DOD Banner
The DOD banner must appear at login on every computer attaching to the network. Submit a trouble report if your computer does not display the DOD Banner at logon.
Any security violations or attempt will be reported.
image1.png
File details come from the government source that posted it. Updated .