PN79439-2_Specifications_Ready to Advertise_Vol3.pdf

PDF 3 MB Posted

Attached to
SOF Advanced Skills Training Facility Annex and HAZMAT Facilities Federal contract opportunity
Solicitation number
W912PM22R0012
Issued by
Department of the Army Corps of Engineers Engineering District Wilmington

About this file

This solicitation is for construction services for an Advanced Skills Training Facility Annex and Hazardous Material Storage buildings at Fort Bragg, North Carolina. The contractor will provide all labor, materials, equipment, and services necessary to construct a single story administrative office building approximately 24,500 square feet, including classrooms, conference rooms, lounge areas, instructional labs, ADA restrooms, locker rooms and showers, storage space, and offices. Supporting facilities include site work, utilities infrastructure, lighting, parking, and landscaping. Additionally, the contractor will construct a separate 1,200 square foot enclosed and 350 square foot open storage Hazardous Material Storage building. Both facilities will be designed for a 40 year minimum life and will incorporate sustainable design and energy efficiency features in accordance with UFC criteria to achieve LEED Silver certification.

View the file

Other files for this federal contract opportunity

Other files attached to SOF Advanced Skills Training Facility Annex and HAZMAT Facilities, newest first.
File Type Posted
PN79439-2 SOF TST ANNEX_DRAWINGS VOL2of3_AM-002_2022-09-09.pdf PDF
Conformed-AMDT002-79439.2-SOF-Annex-Tech-Summary-Changes.pdf PDF
W912PM22R00120002 PN 79439.2.pdf PDF
W912PM22R00120002 PN 79439.2 Conformed Copy.pdf PDF
PN79439-2 SOF TST ANNEX_DRAWINGS VOL3of3_AM-002_2022-09-09.pdf PDF
PN79439-2 SOF TST ANNEX_DRAWINGS VOL1of3_AM-002_2022-09-09.pdf PDF
PN79439-2 SOF TST ANNEX_DRAWINGS VOL2of3_AM-002_2022-09-09.pdf PDF
PN79439-2 SOF TST ANNEX_DRAWINGS_AM-01_2022-08-31.pdf PDF
W912PM22R00120001 PN 79439.2.pdf PDF
PN79439-2 SOF TST ANNEX_SPECS_AM-01_2022-08-31 (.pdf PDF
PN79439-2_SOF TST ANNEX_BIDDER INQUIRY RESPONSES_2022-08-31.pdf PDF
PN79439.2-AMD01-SOF Annex-Tech-Summary-Changes.pdf PDF
PN79439-2_Drawing_T-100_AM-01_2022-08-31.pdf PDF
Site Visit 79439.2 24 August 2022.pdf PDF
PN79439-2_Drawings_RTA_Vol2of3_Aug-2022 (LOCKED).pdf PDF
W912PM22R0012 - 79439.2 RFP_SOF Technical Support Training Annex and Hazmat Storage.pdf PDF
PN79439-2_Drawings_RTA_Vol1of3_Aug-2022 (LOCKED).pdf PDF
PN79439-2_Drawings_RTA_Vol3of3_Aug-2022 (LOCKED).pdf PDF
PN79439-2_Specifications_Ready to Advertise_Vol1.pdf PDF
NAVFAC-USACE PPQ (fillable).pdf PDF
PN79439-2_Drawings_RTA_Vol2of3_Aug-2022 (LOCKED).pdf PDF
PN79439-2_Specifications_Ready to Advertise_Vol2.pdf PDF
VOL IV CE PN79439 2_FFE SID Package_RTA_Aug 2022.pdf PDF
Show all 23

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PN79439.2

SOF Advanced Skills Training Facility Annex and Hazmat Facilities

Fort Bragg, North Carolina

AUGUST 2022

Solicitation No. W912PM22R0012 Contract No. W912PM22XXXXX

This project was designed by the Wilmington District of the U.S. Army Corps of Engineers. The initials or signatures and registration designations of individuals appear on these project documents within the scope of their employment as required by ER 1110-1-8152.

RTA Specifications Volume III of IV

CUI

US Army Corps of Engineers ®

Wilmington District

PN 79439.2, SOF Technical Support

Training Annex and HAZMAT Storage

Fort Bragg, NC

A-E Contract: W912PM22C0007 Task Order: W81LJ821571676

Solicitation No. W912PM22R0012

205 North Michigan Avenue, Suite 3800 Chicago, Illinois 60601-5941, USA

312.616.7500 | www.expfederal.com A-E Project No.: CHI-00243079-A0

Volume 3 of 3

READY TO ADVERTISE

AUGUST 2022

08.02.2022

SPECIFICATIONS

Building, Yarborough Complex, PN79439.2 SOF Technical Support Training Annex & HAZMAT Storage Building, Fort Bragg, NC

W912PM22R0012

Design Analysis July 2022

THIS PAGE IS INTENTIONALLY LEFT BLANK

PROJECT TABLE OF CONTENTS

DIVISION 00 - PROCUREMENT AND CONTRACTING REQUIREMENTS

01 10 00 SOLICITATION CLIN SCHEDULE

DIVISION 01 - GENERAL REQUIREMENTS

01 11 00 08/15 SUMMARY OF WORK

01 14 00 11/11 WORK RESTRICTIONS

01 20 00.00 20 11/11 PRICE AND PAYMENT PROCEDURES

01 30 00 08/15 ADMINISTRATIVE REQUIREMENTS

01 32 01.00 10 02/15 PROJECT SCHEDULE

01 33 00 05/11 SUBMITTAL PROCEDURES

01 33 00 ATTACHMENT A SUBMITTAL REGISTER

01 33 00 ATTACHMENT B ENG FORM 4025-R SAMPLE

01 33 29 02/21 SUSTAINABILITY REQUIREMENTS AND

REPORTING

01 33 29 ATTACHMENT A SUSTAINABLE DESIGN REQUIREMENTS FOR

LEED v4 BD+C

01 35 26 11/15 GOVERNMENTAL SAFETY REQUIREMENTS

01 35 26 ATTACHMENT 1 CESO CHECKLIST A-02 ACCIDENT

PREVENTION PLAN

01 35 26 ATTACHMENT 2 SAFETY PERFORMANCE SIGN

01 42 00 11/14 SOURCES FOR REFERENCE PUBLICATIONS

01 45 00.00 10 11/16 QUALITY CONTROL

01 45 00.15 10 11/16 RESIDENT MANAGEMENT SYSTEM CONTRACTOR

MODE (RMS CM)

01 45 35 02/15 SPECIAL INSPECTIONS

01 45 35 ATTACHMENT A SPECIAL INSPECTIONS SCHEDULE

01 45 35 ATTACHMENT B STATEMENT OF SPECIAL INSPECTIONS

01 50 00 08/09 TEMPORARY CONSTRUCTION FACILITIES AND

CONTROLS

01 57 19 11/15 TEMPORARY ENVIRONMENTAL CONTROLS

01 57 19.00 37 05/15 INDOOR AIR QUALITY (IAQ) MANAGEMENT

01 58 00 08/09 PROJECT IDENTIFICATION

01 74 19 02/19, CHG 3: 11/21 CONSTRUCTION WASTE MANAGEMENT AND

DISPOSAL

01 74 19 ATTACHMENT A CONSTRUCTION WASTE MANAGEMENT FOR LEED

v4

01 78 00 08/11 CLOSEOUT SUBMITTALS

01 78 23 08/15 OPERATION AND MAINTENANCE DATA

01 78 24.00 10 05/17 FACILITY DATA REQUIREMENTS

01 83 16.00 37 12/10 EXTERIOR ENCLOSURE PERFORMANCE

REQUIREMENTS

01 91 00.15 10 05/19, CHG 3: 05/22 TOTAL BUILDING COMMISSIONING

01 91 00.15 10 APPENDIX A OPR DOCUMENT

01 91 00.15 10 APPENDIX B BOD DOCUMENT

01 91 00.15 10 APPENDIX C DESIGN PHASE CX PLAN

01 91 00.15 10 APPENDIX C1 MASTER CX TEST REQUEST FORM

01 91 00.15 10 APPENDIX C2a MASTER CX KICKOFF MEETING

01 91 00.15 10 APPENDIX C2b MASTER CX KICKOFF MEETING SIGN-IN SHEET

DIVISION 02 - EXISTING CONDITIONS

02 41 00 05/10 DEMOLITION

DIVISION 03 - CONCRETE

03 30 00 02/19, CHG 3: 11/21 CAST-IN-PLACE CONCRETE

03 45 00 11/11 PRECAST ARCHITECTURAL CONCRETE

DIVISION 04 - MASONRY

04 20 00 02/11 MASONRY

DIVISION 05 - METALS

05 05 23 11/08 WELDING, STRUCTURAL

05 12 00 11/11 STRUCTURAL STEEL

05 30 00 11/11 STEEL DECKS

05 40 00 05/10 COLD-FORMED METAL FRAMING

05 45 00 09/97 PRE-ENGINEERED LIGHT GAGE STEEL

TRUSSED FRAMES

05 50 13 05/17 MISCELLANEOUS METAL FABRICATIONS

05 51 33 02/16 METAL LADDERS

05 52 00 08/15 METAL RAILINGS

DIVISION 06 - WOOD, PLASTICS, AND COMPOSITES

06 10 00 02/12 ROUGH CARPENTRY

06 20 00 02/12 FINISH CARPENTRY

06 41 16.00 10 08/10 LAMINATE CLAD ARCHITECTURAL CASEWORK

06 61 16 08/10 SOLID SURFACING FABRICATIONS

DIVISION 07 - THERMAL AND MOISTURE PROTECTION

07 05 23 08/19 PRESSURE TESTING AN AIR BARRIER SYSTEM

FOR AIR TIGHTNESS

07 08 27.00 10 02/13 BUILDING AIR BARRIER SYSTEM TESTING

FOR COMMISSIONING

07 14 00 02/12 FLUID-APPLIED WATERPROOFING

07 21 13 05/11 BOARD AND BLOCK INSULATION

07 21 16 11/11 MINERAL FIBER BLANKET INSULATION

07 22 00 08/11 ROOF AND DECK INSULATION

07 24 00 05/11 EXTERIOR INSULATION AND FINISH SYSTEMS

07 27 10.00 10 08/19, CHG 1: 02/20 BUILDING AIR BARRIER SYSTEM

07 27 26 05/17 FLUID-APPLIED MEMBRANE AIR BARRIERS

07 60 00 08/08 FLASHING AND SHEET METAL

07 61 14.00 20 05/11 STEEL STANDING SEAM ROOFING

07 84 00 05/10 FIRESTOPPING

07 92 00 01/07 JOINT SEALANTS

DIVISION 08 - OPENINGS

08 11 13 02/10 STEEL DOORS AND FRAMES

08 14 00 08/11 WOOD DOORS

08 31 00 05/17 ACCESS DOORS AND PANELS

08 33 23 07/07 OVERHEAD COILING DOORS

08 34 73 05/12 SOUND CONTROL DOOR ASSEMBLIES

08 41 13 02/11 ALUMINUM-FRAMED ENTRANCES AND

STOREFRONTS

08 42 29.23 AUTOMATIC SLIDING DOORS

08 51 13 05/11 ALUMINUM WINDOWS

08 71 00 08/08 DOOR HARDWARE

08 71 00 ATTACHMENT 01 DOOR HARDWARE SETS

08 81 00 08/11 GLAZING

08 91 00 05/11 METAL WALL AND DOOR LOUVERS

DIVISION 09 - FINISHES

09 06 90 05/09 COLOR SCHEDULE

09 22 00 02/10 SUPPORTS FOR PLASTER AND GYPSUM BOARD

09 29 00 05/11 GYPSUM BOARD

09 30 00 08/10 CERAMIC TILE, QUARRY TILE, AND PAVER

TILE

09 51 00 08/10 ACOUSTICAL CEILINGS

09 65 00 08/10 RESILIENT FLOORING

09 68 00 05/10 CARPET

09 69 13 11/15 RIGID GRID ACCESS FLOORING

09 90 00 05/11 PAINTS AND COATINGS

DIVISION 10 - SPECIALTIES

10 14 00.10 04/06 EXTERIOR SIGNAGE

10 14 00.20 11/12 INTERIOR SIGNAGE

10 21 13 01/07 TOILET COMPARTMENTS

10 22 13 08/10 WIRE MESH PARTITIONS

10 22 39 05/11 FOLDING PANEL PARTITIONS

10 26 13 08/10 WALL AND CORNER GUARDS

10 28 13 07/06 TOILET ACCESSORIES

10 44 16 05/12 FIRE EXTINGUISHERS

10 51 13 05/11 METAL LOCKERS

10 55 23.00 37 07/10 RECESSED CELL PHONE STORAGE UNIT

10 56 13 04/06 STEEL SHELVING

DIVISION 11 - EQUIPMENT

11 31 13 08/08 ELECTRIC KITCHEN EQUIPMENT

11 53 00 05/11 LABORATORY EQUIPMENT AND FUMEHOODS

DIVISION 12 - FURNISHINGS

12 24 13 08/17 ROLLER WINDOW SHADES

12 48 13 08/17 ENTRANCE FLOOR MATS AND FRAMES

DIVISION 13 - SPECIAL CONSTRUCTION

13 12 80 11/14 RELOCATABLE HAZARDOUS MATERIAL AND

HAZARDOUS WASTE STORAGE BUILDINGS

13 48 00 08/08 SEISMIC PROTECTION FOR MISCELLANEOUS

EQUIPMENT

13 48 00.00 10 10/07 SEISMIC PROTECTION FOR MECHANICAL

EQUIPMENT

DIVISION 21 - FIRE SUPPRESSION

21 13 13.00 10 05/09 WET PIPE SPRINKLER SYSTEM, FIRE

PROTECTION

DIVISION 22 - PLUMBING

22 00 00 11/11 PLUMBING, GENERAL PURPOSE FIXTURE

DIVISION 23 - HEATING, VENTILATING, AND AIR CONDITIONING (HVAC)

23 00 00 08/10 AIR SUPPLY, DISTRIBUTION, VENTILATION,

AND EXHAUST SYSTEMS

23 03 00.00 20 08/10 BASIC MECHANICAL MATERIALS AND METHODS

23 05 15 02/09 COMMON PIPING FOR HVAC

23 05 48.00 40 02/11 VIBRATION AND SEISMIC CONTROLS FOR

HVAC PIPING AND EQUIPMENT

23 05 93 08/09 TESTING, ADJUSTING, AND BALANCING FOR

HVAC

23 07 00 02/13 THERMAL INSULATION FOR MECHANICAL

SYSTEMS

23 09 00 02/19, CHG 3: 05/21 INSTRUMENTATION AND CONTROL FOR HVAC

23 09 13 11/15, CHG 2: 05/21 INSTRUMENTATION AND CONTROL DEVICES

FOR HVAC

23 09 23.01 02/19, CHG 1: 02/20 LONWORKS DIRECT DIGITAL CONTROL FOR

HVAC AND OTHER BUILDING CONTROL SYSTEMS

23 11 25 11/08 FACILITY GAS PIPING

23 23 00 10/07 REFRIGERANT PIPING

23 35 00.00 10 02/09 OVERHEAD VEHICLE TAILPIPE EXHAUST

REMOVAL SYSTEM(S)

23 52 00 04/08 HEATING BOILERS

23 64 10 08/08 WATER CHILLERS, VAPOR COMPRESSION TYPE

23 64 26 08/09 CHILLED WATER PIPING SYSTEMS

23 82 02.00 10 04/08 UNITARY HEATING AND COOLING EQUIPMENT

23 82 46.00 40 08/11 ELECTRIC UNIT HEATERS

DIVISION 25 - INTEGRATED AUTOMATION

25 05 11.00 11/17 CYBERSECURITY FOR HVAC AND BUILDING

AUTOMATION SYSTEM CONTROL SYSTEMS

25 05 11.01 11/17 CYBERSECURITY FOR ELECTRICAL CONTROL

SYSTEMS

25 05 11.02 11/17 CYBERSECURITY FOR FIRE LIFE SAFETY

(FLS)

25 05 11.03 11/17 CYBERSECURITY FOR AUDIO VISUAL CONTROL

SYSTEMS

25 05 11.04 11/17 CYBERSECURITY FOR ELECTRONIC SECUREITY

SYSTEM (ESS) CONTROL SYSTEMS

25 10 10 02/19, CHG 1: 05/21 UTILITY MONITORING AND CONTROL SYSTEM

(UMCS) FRONT END AND INTEGRATION

DIVISION 26 - ELECTRICAL

26 00 00.00 20 07/06 BASIC ELECTRICAL MATERIALS AND METHODS

26 05 00.00 40 08/19 COMMON WORK RESULTS FOR ELECTRICAL

26 05 48.00 10 10/07 SEISMIC PROTECTION FOR ELECTRICAL

EQUIPMENT

26 20 00 02/14 INTERIOR DISTRIBUTION SYSTEM

26 28 01.00 10 10/07 COORDINATED POWER SYSTEM PROTECTION

26 29 23 04/06 VARIABLE FREQUENCY DRIVE SYSTEMS UNDER

600 VOLTS

26 41 00 11/13 LIGHTNING PROTECTION SYSTEM

26 51 00 07/07 INTERIOR LIGHTING

DIVISION 27 - COMMUNICATIONS

27 10 00 08/11 BUILDING TELECOMMUNICATIONS CABLING

SYSTEM

27 40 00 AUDIO VIDEO SYSTEMS

DIVISION 28 - ELECTRONIC SAFETY AND SECURITY

28 16 01.00 10 11/08 SMALL INTRUSION DETECTION SYSTEM

28 20 01.00 10 10/07 ELECTRONIC SECURITY SYSTEM

28 23 23.00 10 02/11 CLOSED CIRCUIT TELEVISION SYSTEMS

28 31 76 08/11 INTERIOR FIRE ALARM AND MASS

NOTIFICATION SYSTEM

DIVISION 31 - EARTHWORK

31 00 00 08/08 EARTHWORK

31 11 00 08/08 CLEARING AND GRUBBING

31 31 16.13 11/14 CHEMICAL TERMITE CONTROL

31 32 11 08/08 SOIL SURFACE EROSION CONTROL

ATTACH. 02921FB EROSION CONTROL AND TURF SEEDING

ATTACH. 02936 TURF - BERMUDA GRASS SEEDING

DIVISION 32 - EXTERIOR IMPROVEMENTS

32 01 19 08/08 FIELD MOLDED SEALANTS FOR SEALING

JOINTS IN RIGID PAVEMENTS

32 05 33 02/10 LANDSCAPE ESTABLISHMENT

32 11 16.16 11/11 BASE COURSE FOR RIGID AND SUBBASE

COURSE FOR FLEXIBLE PAVING

32 11 23 08/08 AGGREGATE AND/OR GRADED-CRUSHED

AGGREGATE BASE COURSE

32 12 10 08/08 BITUMINOUS TACK AND PRIME COATS

32 12 17 04/08 HOT MIX BITUMINOUS PAVEMENT

32 13 13.06 11/11 PORTLAND CEMENT CONCRETE PAVEMENT FOR

ROADS AND SITE FACILITIES

32 16 13 04/08 CONCRETE SIDEWALKS AND CURBS AND

GUTTERS

32 17 23.00 20 04/06 PAVEMENT MARKINGS

32 31 13.53 04/08 HIGH-SECURITY CHAIN LINK FENCES AND

GATES

32 92 19 10/06 SEEDING

32 93 00 02/10 EXTERIOR PLANTS

DIVISION 33 - UTILITIES

33 11 00 02/11 WATER DISTRIBUTION

33 30 00 04/08 SANITARY SEWERS

33 40 00 02/10 STORM DRAINAGE UTILITIES

33 61 00 04/08 PREFABRICATED UNDERGROUND COOLING

DISTRIBUTION SYSTEM

33 71 02 02/15 UNDERGROUND ELECTRICAL DISTRIBUTION

33 82 00 04/06 TELECOMMUNICATIONS OUTSIDE PLANT (OSP)

-- End of Project Table of Contents --

SOF Tech Support Training Annex CUI PN79439.2 Fort Bragg, North Carolina

SECTION TABLE OF CONTENTS

DIVISION 25 - INTEGRATED AUTOMATION

SECTION 25 05 11.00

CYBERSECURITY FOR HVAC AND BUILDING AUTOMATION SYSTEM CONTROL SYSTEMS

11/17 cybersecurity for facility-related control systems

PART 1 GENERAL

1.1 CONTROL SYSTEM APPLICABILITY

1.2 RELATED REQUIREMENTS

1.3 REFERENCES

1.4 DEFINITIONS

1.4.1 Computer

1.4.2 Network Connected

1.4.3 User Account Support Levels

1.4.3.1 FULLY Supported

1.4.3.2 MINIMALLY Supported

1.4.3.3 NOT Supported

1.4.4 User Interface

1.4.4.1 Limited Local User Interface

1.4.4.2 Full Local User Interface

1.4.4.3 Remote User Interface

1.5 ADMINISTRATIVE REQUIREMENTS

1.5.1 Coordination

1.6 SUBMITTALS

1.7 QUALITY CONTROL

1.7.1 Qualifications

1.8 CYBERSECURITY DOCUMENTATION

1.8.1 Control System Inventory Report

1.8.2 Software Recovery and Reconstitution Images

1.8.3 Cybersecurity Riser Diagram

1.8.4 Control System Cybersecurity Documentation

1.8.4.1 For HVAC Control System Devices

1.8.4.1.1 HVAC Control System Devices FULLY Supporting User

Accounts

1.8.4.1.2 All Other HVAC Control System Devices

1.8.4.2 Default Requirements for Control System Devices

1.9 SOFTWARE UPDATE LICENSING

1.10 CYBERSECURITY DURING CONSTRUCTION

1.10.1 Contractor Computer Equipment

1.10.1.1 Operating System

1.10.1.2 Anti-Malware Software

1.10.1.3 Passwords and Passphrases

1.10.1.4 Contractor Computer Cybersecurity Compliance Statements

1.10.2 Temporary IP Networks

1.10.2.1 Network Boundaries and Connections

1.10.3 Government Access to Network

1.10.4 Temporary Wireless IP Networks

1.10.5 Passwords and Passphrases

SECTION 25 05 11.00 Page 1

READY TO ADVERTISE CUI

1.10.6 Contractor Temporary Network Cybersecurity Compliance

Statements

1.11 CYBERSECURITY DURING WARRANTY PERIOD

PART 2 PRODUCTS

PART 3 EXECUTION

3.1 ACCESS CONTROL REQUIREMENTS

3.1.1 User Accounts

3.1.1.1 For HVAC Control System Devices

3.1.1.2 Default Requirements for Control System Devices

3.1.2 Unsuccessful Logon Attempts

3.1.2.1 Devices MINIMALLY Supporting Accounts

3.1.2.2 Devices FULLY Supporting Accounts

3.1.2.3 High Availability Interfaces Exempt from Unsuccessful

Logon Attempts Requirements

3.1.3 Permitted Actions Without Identification or Authentication

3.1.4 Wireless Access

3.1.4.1 Wireless Communications

3.2 CYBERSECURITY AUDITING

3.2.1 Audit Events, Content of Audit Records, and Audit Generation

3.2.1.1 For HVAC Control System Devices

3.2.1.1.1 HVAC Control System Devices FULLY Supporting User

Accounts

3.2.1.1.2 Other HVAC Control System Devices

3.2.1.2 Default Requirements for Control System Devices

3.2.1.2.1 Devices Which FULLY Support Accounts

3.2.1.2.1.1 Audited Events

3.2.1.2.1.2 Audit Event Information To Record

3.2.1.2.2 Devices Which Do Not FULLY Support Accounts

3.2.2 Audit Storage Capacity and Audit Upload

3.2.3 Time Stamps

3.2.3.1 For HVAC Control System Devices

3.3 REQUIREMENTS FOR LEAST FUNCTIONALITY

3.3.1 Non-IP Control Networks

3.3.2 IP Control Networks

3.4 SAFE MODE AND FAIL SAFE OPERATION

3.5 IDENTIFICATION AND AUTHENTICATION

3.5.1 User Identification and Authentication

3.5.1.1 HVAC Control Systems Devices

3.5.1.2 Default Requirements for Control System Devices

3.5.2 Authenticator Management

3.5.2.1 Authentication Type

3.5.2.1.1 For HVAC Control System Devices

3.5.2.1.2 Default Requirements for Control System Devices

3.5.2.2 Password-Based Authentication Requirements

3.5.2.2.1 Passwords for Non-Computer Devices FULLY Supporting

Accounts

3.5.2.2.2 Passwords for Devices Minimally Supporting Accounts

3.5.2.2.3 Password Configuration and Reporting

3.5.2.3 Hardware Token-Based Authentication Requirements

3.5.3 Authenticator Feedback

3.5.4 Device Identification and Authentication

3.5.4.1 For HVAC Control System Devices

3.5.5 Cryptographic Module Authentication

3.6 EMERGENCY POWER

3.7 DURABILITY TO VULNERABILITY SCANNING

SECTION 25 05 11.00 Page 2

3.7.1 HVAC Control System Devices Other Than Computers

3.7.2 Default Requirements for Control System Devices

3.8 SYSTEM AND COMMUNICATION PROTECTION

3.8.1 Denial of Service Protection, Process Isolation and Boundary

Protection

3.9 SYSTEM AND INTEGRATION INTEGRITY

3.10 FIELD QUALITY CONTROL

3.10.1 Tests

-- End of Section Table of Contents --

SECTION 25 05 11.00 Page 3

SECTION 25 05 11.00

CYBERSECURITY FOR HVAC AND BUILDING AUTOMATION SYSTEM CONTROL SYSTEMS

11/17

PART 1 GENERAL

Many subparts in this Section contain text in curly braces ("{" and "}") indicating which cybersecurity control and control correlation identifier (CCI) the requirements of the subpart relate to. The text inside these curly braces is for Government reference only, and enables coordination of the requirements of this Section with the RMF process throughout the design and construction process. Text in curly braces are not contractor requirements.

This Section refers to Security Requirements Guide (SRGs) and Security Technical Implementation Guide (STIGs). STIGs and SRGs are are available online at the Information Assurance Support Environment (IASE) website at http://iase.disa.mil/stigs/Pages/index.aspx . Not all control system components have applicable STIGs or SRGs.

1.1 CONTROL SYSTEM APPLICABILITY

There are multiple versions of this Section associated with this project.

Different versions have requirements applicable to different control systems. This specific Section applies only to the following control systems: HVAC AND BUILDING AUTOMATION SYSTEM (BAS).

1.2 RELATED REQUIREMENTS

All Sections containing facility-related control systems or control system components are related to the requirements of this Section. Review all specification sections to determine related requirements.

1.3 REFERENCES

The publications listed below form a part of this specification to the extent referenced. The publications are referred to within the text by the basic designation only.

AMERICAN SOCIETY OF HEATING, REFRIGERATING AND AIR-CONDITIONING

ENGINEERS (ASHRAE)

ASHRAE 135 (2020; Errata 1-2 2021) BACnet—A Data Communication Protocol for Building Automation and Control Networks

INSTITUTE OF ELECTRICAL AND ELECTRONICS ENGINEERS (IEEE)

IEEE 802.1x (2010) Local and Metropolitan Area Networks - Port Based Network Access Control

U.S. DEPARTMENT OF DEFENSE (DOD)

DODI 8551.01 (2014) Ports, Protocols, and Services Management (PPSM)

SECTION 25 05 11.00 Page 4

1.4 DEFINITIONS

1.4.1 Computer

As used in this Section, a computer is one of the following:

a. a device running a non-embedded desktop or server version of Microsoft Windows

b. a device running a non-embedded version of MacOS

c. a device running a non-embedded version of Linux

d. a device running a version or derivative of the Android OS, where Android is considered separate from Linux

e. a device running a version of Apple iOS

1.4.2 Network Connected

A component is network connected (or "connected to a network") only when the device has a network transceiver which is directly connected to the network and implements the network protocol. A device lacking a network transceiver (and accompanying protocol implementation) can never be considered network connected. Note that a device connected to a non-IP network is still considered network connected (an IP connection or IP address is not required for a device to be network connected).

Any device that supports wireless communication is network connected, regardless of whether the device is communicating using wireless .

1.4.3 User Account Support Levels

The support for user accounts is categorized in this Section as one of three levels:

1.4.3.1 FULLY Supported

Device supports configurable individual accounts. Accounts can be created, deleted, modified, etc. Privileges can be assigned to accounts.

1.4.3.2 MINIMALLY Supported

Device supports a small, fixed number of accounts (perhaps only one).

Accounts cannot be modified. A device with only a "User" and an "Administrator" account would fit this category. Similarly, a device with two PINs for logon - one for restricted and one for unrestricted rights would fit here (in other words, the accounts do not have to be the traditional "user name and password" structure).

1.4.3.3 NOT Supported

Device does not support any Access Enforcement therefore the whole concept of "account" is meaningless.

1.4.4 User Interface

Generally, a user interface is hardware on a device allowing user

SECTION 25 05 11.00 Page 5 interaction with that device via input (buttons, switches, sliders, keyboard, touch screen, etc.) and a screen. There are three types of user interfaces defined in this Section: Limited Local User Interface, Full Local User Interface and Remote User Interface. In this Section, when the term "User Interface" is used without specifying which type, it refers only to Full Local User Interface and Remote User Interface (NOT to Limited Local User Interface).

1.4.4.1 Limited Local User Interface

A Limited Local User Interface is a user interface where the interaction is limited, fixed at the factory, and cannot be modified in the field.

The user must be physically at the device to interact with it.

Examples of Limited Local User Interface include thermostats (Space Sensor Modules as defined in Section 23 09 23.01 LONWORKS DIRECT DIGITAL CONTROL

FOR HVAC AND OTHER BUILDING CONTROL SYSTEMS.

1.4.4.2 Full Local User Interface

A Full Local User Interface is a user interface where the interaction and displays are field-configurable.

Examples of a Full Local User Interface include local applications on a computer and user interfaces to Variable Speed Drives .

1.4.4.3 Remote User Interface

A Remote User Interface is a user interface on a Client device allowing user interaction with a different Server device. The user need not be physically at the Server device to interact with it.

Examples of Remote User Interfaces include web browsers and Local Display Panels as defined in Section 23 09 23.01 LONWORKS DIRECT DIGITAL CONTROL

FOR HVAC AND OTHER BUILDING CONTROL SYSTEMS.

1.5 ADMINISTRATIVE REQUIREMENTS

1.5.1 Coordination

Coordinate the execution of this Section with the execution of all other Sections related to control systems as indicated in the paragraph RELATED REQUIREMENTS. Items that must be considered when coordinating project efforts include but are not limited to:

a. If requesting permission for alternate account lock permissions, the Device Account Lock Exception Request must be approved prior to control system device selection and integration.

b. Cybersecurity Interconnection Schedule must be coordinated with other work that will be interconnected to, and interconnections must be approved by the Government before relying on them for system functionality.

c. Cybersecurity testing support must be coordinated across control systems and with the Government cybersecurity testing schedule.

d. Passwords must be coordinated with the indicated contact for the project site.

SECTION 25 05 11.00 Page 6

e. Contractor Computer Cybersecurity Compliance Statements for each contractor using contractor owned computers.

1.6 SUBMITTALS

Government approval is required for submittals with a "G" designation;

submittals not having a "G" designation are for information only. When used, a designation following the "G" designation identifies the office that will review the submittal for the Government. Submittals with an "S" are for inclusion in the Sustainability eNotebook, in conformance with Section 01 33 29 SUSTAINABILITY. Submit the following in accordance with Section 01 33 00 SUBMITTAL PROCEDURES:

SD-01 Preconstruction Submittals

Contractor Computer Cybersecurity Compliance Statements; G

Contractor Temporary Network Cybersecurity Compliance Statements; G

SD-02 Shop Drawings

Cybersecurity Riser Diagram; G

Control System Inventory Report; G

SD-03 Product Data

Control System Cybersecurity Documentation; G

SD-07 Certificates

Software Licenses; G

SD-11 Closeout Submittals

Password Summary Report; G

Software Recovery And Reconstitution Images; G

1.7 QUALITY CONTROL

1.7.1 Qualifications

For the HVAC AND BUILDING AUTOMATION SYSTEM:

Personnel Certifications and Qualifications Control System Cybersecurity Subject Matter Expert.

The individual will oversee all work within this specification. This position requires that the individual currently meets Information Assurance Manager Level II Certification in accordance with DoDI 8570 Information Workforce Improvement Program.

Individuals for this position should have experience securing DoD systems and with Risk Management Framework. Control System Experience is highly desirable.

Resumes should be submitted to the Government within 14 days after notice to proceed.

Additional Statement:

SECTION 25 05 11.00 Page 7

Control System Cybersecurity Subject Matter Expert can serve across the contract.

1.8 CYBERSECURITY DOCUMENTATION

1.8.1 Control System Inventory Report

{For Reference Only: This subpart (and its subparts) relates to CM-8(a), CP-12, SI-17, IA-3; CCI-000389, CCI-000392, CCI-000398, CCI-002855, CCI-002856, CCI-002857, CCI-002773, CCI-002774, CCI-002775, CCI-000777, CCI-000778, CCI-001958}

Provide a Control System Inventory report using the Inventory Spreadsheet listed under this Section at http://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/forms-graphics-tables documenting all devices, including networked devices, network infrastructure devices, non-networked devices, input devices (e.g.

sensors) and output devices (e.g. actuators). For each device provide all applicable information for which there is a field on the spreadsheet in accordance with the instructions on the spreadsheet.

In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Control System Inventory Report as an editable Microsoft Excel file.

1.8.2 Software Recovery and Reconstitution Images

{For Reference Only: This subpart (and its subparts) relates to CP-10;

CCI-000550, CCI-000551, CCI-000552}

For each control device on which software is installed under this project, provide a recovery image of the final as-built device. This image must allow for bare-metal restore such that restoration of the image is sufficient to restore system operation to the imaged state without the need for re-installation of software.

1.8.3 Cybersecurity Riser Diagram

{For Reference Only: This subpart (and its subparts) relates to PL-2(a);

CCI-003051, CCI-003053}

Provide a cybersecurity riser diagram of the complete control system including all network and controller hardware. If the control system specifications require a riser diagram submittal, provide a copy of that submittal as the cybersecurity riser diagram. Otherwise, provide a riser diagram in one-line format.

1.8.4 Control System Cybersecurity Documentation

This subpart (and its subparts) relates to SA-5 (a),(b),(c); CCIs:

CCI-003124, CCI-003125, CCI-003126, CCI-003127, CCI-003128, CCI-003129,

CCI-003130, CCI-003131}

Provide a Control System Cybersecurity Documentation submittal containing the indicated information for each device and software application.

SECTION 25 05 11.00 Page 8

1.8.4.1 For HVAC Control System Devices

1.8.4.1.1 HVAC Control System Devices FULLY Supporting User Accounts

For all HVAC Control System Devices which FULLY support user accounts, provide:

a. Documentation that describes secure configuration of the device {for reference only: relates to CCI-003124}

b. Documentation that describes secure operation of the device {for reference only: relates to CCI-003124}

c. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {for reference only: relates to

CCI-003127}

d. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {for reference only: relates to CCI-003128}

e. Documentation that describes user-accessible security functions or mechanisms in the device and how to effectively use those security functions or mechanisms; or a specific indication that there are no user-accessible security functions or mechanisms in the device {for reference only: relates to CCI-003129}

f. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {for reference only: relates to CCI-003130}

1.8.4.1.2 All Other HVAC Control System Devices

For all HVAC Control System Devices which do not FULLY support user accounts, provide:

a. Documentation that describes secure configuration of the device; or a specific indication that there are no secure configuration steps that apply {for reference only: relates to CCI-003124}

b. Documentation that describes effective use and maintenance of security functions or mechanisms for the device; or a specific indication that there are no security functions or mechanisms in the device {for reference only: relates to CCI-003127}

c. For devices which include a user interface, documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {for reference only: relates to

CCI-003130}

1.8.4.2 Default Requirements for Control System Devices

For control system devices where Control System Cybersecurity Documentation requirements are not otherwise indicated in this Section, provide:

a. Documentation that describes secure configuration of the device {for reference only: relates to CCI-003124}

SECTION 25 05 11.00 Page 9

b. Documentation that describes secure installation of the device {for reference only: relates to CCI-003125}

c. Documentation that describes secure operation of the device {for reference only: relates to CCI-003124}

d. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {for reference only: relates to

CCI-003127}

e. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {for reference only: relates to CCI-003128}

f. Documentation that describes user-accessible security functions or mechanisms in the device and how to effectively use those security functions or mechanisms {for reference only: relates to CCI-003129}

g. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {for reference only: relates to CCI-003130}

h. Documentation that describes user responsibilities in maintaining the security of the device {for reference only: relates to CCI-003131}

1.9 SOFTWARE UPDATE LICENSING

{For Reference Only: This subpart (and its subparts) relates to SI-2 (a),(c); CCI-001227, CCI-002605}

In addition to all other licensing requirements, all software licensing must include licensing of the following software updates for a period of no less than 5 years:

a. Security and bug-fix patches issued by the software manufacturer.

b. Security patches to address any vulnerability identified in the National Vulnerability Database at http://nvd.nist.gov with a Common Vulnerability Scoring System (CVSS) severity rating of MEDIUM or higher.

Provide a single Software Licenses submittal with documentation of the software licenses for all software provided

1.10 CYBERSECURITY DURING CONSTRUCTION

{For Reference Only: This subpart (and its subparts) relates to AC-18, SA-3, CCI-00258}

In addition to the control system cybersecurity requirements indicated in this section, meet following requirement throughout the construction process.

1.10.1 Contractor Computer Equipment

Contractor owned computers may be used for construction. When used, contractor computers must meet the following requirements:

SECTION 25 05 11.00 Page 10

1.10.1.1 Operating System

The operating system must be an operating system currently supported by the manufacturer of the operating system. The operating system must be current on security patches and operating system manufacturer required updates.

1.10.1.2 Anti-Malware Software

The computer must run anti-malware software from a reputable software manufacturer. Anti-malware software must be a version currently supported by the software manufacturer, must be current on all patches and updates, and must use the latest definitions file. All computers used on this project must be scanned using the installed software at least once per day.

1.10.1.3 Passwords and Passphrases

The passwords and passphrases for all computers must be changed from their default values. Passwords must be a minimum of eight characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.

1.10.1.4 Contractor Computer Cybersecurity Compliance Statements

Provide a single submittal containing completed Contractor Computer Cybersecurity Compliance Statements for each company using contractor owned computers. Contractor Computer Cybersecurity Compliance Statements must use the template published at http://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/forms-graphics-tables Each Statement must be signed by a cybersecurity representative for the relevant company.

1.10.2 Temporary IP Networks

Temporary contractor-installed IP networks may be used during construction. When used, temporary contractor-installed IP networks must meet the following requirements:

1.10.2.1 Network Boundaries and Connections

The network must not extend outside the project site and must not connect to any IP network other than IP networks provided under this project or Government furnished IP networks provided for this purpose. Any and all network access from outside the project site is prohibited.

1.10.3 Government Access to Network

Government personnel must be allowed to have complete and immediate access to the network at any time in order to verify compliance with this specification

1.10.4 Temporary Wireless IP Networks

Temporary wireless IP (WiFi) networks must not be used.

1.10.5 Passwords and Passphrases

The passwords and passphrases for all network devices and network access

SECTION 25 05 11.00 Page 11 must be changed from their default values. Passwords must be a minimum 8 characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.

1.10.6 Contractor Temporary Network Cybersecurity Compliance Statements

Provide a single submittal containing completed Contractor Temporary Network Cybersecurity Compliance Statements for each company implementing a temporary IP network. Contractor Temporary Network Cybersecurity Compliance Statements must use the template published at http://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/forms-graphics-tables Each Statement must be signed by a cybersecurity representative for the relevant company. If no temporary IP networks will be used, provide a single copy of the Statement indicating this.

1.11 CYBERSECURITY DURING WARRANTY PERIOD

All work performed on the control system after acceptance must be performed using Government Furnished Equipment or equipment specifically and individually approved by the Government.

PART 2 PRODUCTS

(NOT USED)

PART 3 EXECUTION

3.1 ACCESS CONTROL REQUIREMENTS

3.1.1 User Accounts

{For Reference Only: This subpart (and its subparts) relate to AC-2(a)and

AC-3; CCI-002110, CCI-000213.}

Any device supporting user accounts (either FULLY or MINIMALLY) must limit access to the device according to specified limitations for each account.

Install and configure any device having a STIG or SRG in accordance with that STIG or SRG.

3.1.1.1 For HVAC Control System Devices

Devices with web interfaces must either FULLY support user accounts or have their web interface disabled. Field devices with full local user interfaces allowing modification of data must at least MINIMALLY support user accounts.

3.1.1.2 Default Requirements for Control System Devices

For control system devices where User Account requirements are not otherwise indicated in this Section:

a. All devices must at least MINIMALLY support user accounts.

3.1.2 Unsuccessful Logon Attempts

{For Reference Only: This subpart (and its subparts) relate AC-7 (a), AC-7 (b); CCI-000043, CCI-000044, CCI-001423, CCI-002236, CCI-002237, CCI-002238}

SECTION 25 05 11.00 Page 12

Except for high availability user interfaces indicated as exempt, devices must meet the indicated requirements for handling unsuccessful logon attempts.

3.1.2.1 Devices MINIMALLY Supporting Accounts

Devices which MINIMALLY support accounts are not required to lock based on unsuccessful logon attempts

3.1.2.2 Devices FULLY Supporting Accounts

Devices which FULLY support accounts must meet the following requirements. If a device cannot meet these requirements, document device capabilities to protect from subsequent unsuccessful logon attempts and propose alternate protections in a Device Account Lock Exception Request submittal. Do not implement alternate protection measures without explicit permission from the Government.

a. It must lock the user account when three unsuccessful logon attempts occur within a 15 minute interval.

b. Once an account is locked, the account must stay locked until unlocked by an administrator.

c. Once the indicated number of unsuccessful logon attempts occurs, delay further logon prompts by 5 seconds.

3.1.2.3 High Availability Interfaces Exempt from Unsuccessful Logon Attempts Requirements

There are no high availability interfaces which are exempt from unsuccessful logon attempts requirements.

3.1.3 Permitted Actions Without Identification or Authentication

{For Reference Only: This subpart (and its subparts) relates to AC-14;

CCI-000061, CCI-000232}

The control system must require identification and authentication before allowing any actions by a user acting from a user interface which MINIMALLY or FULLY supports accounts.

3.1.4 Wireless Access

{For Reference Only: This subpart (and its subparts) relates to AC-18;

CCI-001438, CCI-001439, CCI-002323, CCI-001441}

Unless explicitly authorized by the Government, do not use any wireless communication. Any device with wireless communication capability is considered to be using wireless communication, regardless of whether or not the device is actively communicating wirelessly, except when wireless communication has been physically permanently disabled (such as through the removal of the wireless transceiver).

3.1.4.1 Wireless Communications

Do not install wireless networks, including: do not install a wireless access point; do not install or configure an ad-hoc wireless network; do

SECTION 25 05 11.00 Page 13 not install or configure WiFi Direct communication.

3.2 CYBERSECURITY AUDITING

3.2.1 Audit Events, Content of Audit Records, and Audit Generation

{For Reference Only: This subpart (and its subparts) relates to AU-2(a),(c),(d), AU-3, AU-12; CCI-000123, CCI-001571, CCI-000125, CCI-001485, CCI-000130, CCI-000131, CCI-000132, CCI-00133, CCI-000134, CCI-001487, CCI-000169, CCI-001459, CCI-000171, CCI-000172, CCI-001910}

For devices that have STIG/SRGs related to audit events, content of audit records or audit generation, comply with the requirements of those STIG/SRGs.

3.2.1.1 For HVAC Control System Devices

3.2.1.1.1 HVAC Control System Devices FULLY Supporting User Accounts

For devices FULLY supporting accounts, provide the capability to select audited events, and the contents of audit logs. Configure devices to audit the following events:

a. Successful and unsuccessful logon attempts to the device

b. Starting and ending time for user access to the device

c. All account creations, modifications, disabling, and terminations

d. All device shutdown and startup

Configure the device to record for each event the following information (as applicable): the type of event, when the event occurred and the identity of any individuals or subjects associated with the event

3.2.1.1.2 Other HVAC Control System Devices

There are no requirements to perform auditing at HVAC field devices that do not FULLY support accounts.

3.2.1.2 Default Requirements for Control System Devices

For control system devices where Audit Events, Content of Audit Records, and Audit Generation are not otherwise indicated in this Section:

3.2.1.2.1 Devices Which FULLY Support Accounts

For each device which FULLY supports accounts, provide the capability to select audited events and the content of audit logs. Configure devices to audit the indicated events, and to record the indicated information for each auditable event

3.2.1.2.1.1 Audited Events

Configure each device to audit the following events:

a. Successful and unsuccessful attempts to access, modify, or delete privileges, security objects, security levels, or categories of information (e.g. classification levels)

SECTION 25 05 11.00 Page 14

a. Successful and unsuccessful logon attempts

b. Privileged activities or other system level access

c. Starting and ending time for user access to the system

d. Concurrent logons from different workstations

e. All account creations, modifications, disabling, and terminations

f. All kernel module load, unload, and restart

3.2.1.2.1.2 Audit Event Information To Record

Configure each control device to record, for each auditable event, the following information (where applicable to the event):

a. what type of event occurred

b. when the event occurred

c. where the event occurred

d. the source of the event

e. the outcome of the event

f. the identity of any individuals or subjects associated with the event

3.2.1.2.2 Devices Which Do Not FULLY Support Accounts

For each Device which does not FULLY support accounts configure the device to audit all device shutdown and startup events and to record for each event the type of event and when the event occurred.

3.2.2 Audit Storage Capacity and Audit Upload

{For Reference Only: This subpart (and its subparts) relates to AU-4;

CCI-001848, CCI-001849}

a. For devices that have STIG/SRGs related to audit storage capacity (CCI-001848 or CCI-001849) comply with the requirements of those STIG/SRGs.

b. For non-computer control system devices capable of generating audit records, provide 60 days worth of secure local storage, assuming 10 auditable events per day.

3.2.3 Time Stamps

{For Reference Only: This subpart (and its subparts) relates to AU-8;

CCI-000159, CCI-001889, CCI-001890}

3.2.3.1 For HVAC Control System Devices

Time stamp requirements for HVAC Control Systems are as indicated in the HVAC Control System specifications. Devices generating audit records must have internal clocks capable of providing time with a resolution of 1

SECTION 25 05 11.00 Page 15 second. Clocks cannot drift more than 10 seconds per day. Configure the system so that each device generating audit records maintains accurate time to within 1 second.

3.3 REQUIREMENTS FOR LEAST FUNCTIONALITY

{For Reference Only: This subpart (and its subparts), along with the network communication report submittal specified elsewhere in this section, relates to CM-6 (a), (c), CM-7, CM-7 (1)(b), SC-41; CCI-000363, CCI-000364, CCI-000365, CCI-001588, CCI-001755, CCI-000381, CCI-000380, CCI-00382, CCI-001761, CCI-001762, CCI-002544, CCI-002545, CCI-002546.}

For devices that have a STIG or SRG related to Requirements for Least Functionality (such as configuration settings and port and device I/O access for least functionality), install and configure the device in accordance with that STIG or SRGs.

For HVAC Control Systems: Do not provide devices with user interfaces where one was not required. Do not use a networked sensor or actuator where a non-networked sensor or actuator would suffice.

For Other Control Systems: Do not provide devices with user interfaces where one was not required. Do not use a networked sensor or actuator where a non-networked sensor or actuator would suffice.

3.3.1 Non-IP Control Networks

When control system specifications require particular communication protocols, use only those communication protocols and only as specified.

Do not implement any other communication protocol, or use any protocol on ports other than those specified.

When control system specifications do not indicate requirements for communication protocols, use only those protocols required for operation of the system as specified.

3.3.2 IP Control Networks

Do not use nonsecure functions, ports, protocols and services as defined in DODI 8551.01 unless those ports, protocols and services are specifically required by the control system specifications or otherwise specifically authorized by the Government. Do not use ports, protocols and services that are not specified in the control system specifications or required for operation of the control system.

3.4 SAFE MODE AND FAIL SAFE OPERATION

{For Reference Only: This subpart (and its subparts) relates to CP-12, SI-17; CCI-002855, CCI-002856, CCI-002857, CCI-002773, CCI-002774, CCI-002775}

For all control system components with an applicable STIG or SRG, configure the component in accordance with all applicable STIGs and SRGs.

3.5 IDENTIFICATION AND AUTHENTICATION

3.5.1 User Identification and Authentication

{For Reference Only: This subpart (and its subparts) relates to

SECTION 25 05 11.00 Page 16

IA-2,(1),(12); CCI-000764, CCI-000765, CCI-001953, CCI-001954}

a. Devices that FULLY support accounts must uniquely identify and authenticate organizational users.

b. Devices which allow network access to privileged accounts must implement multifactor authentication for network access to privileged accounts.

3.5.1.1 HVAC Control Systems Devices

Identification and Authentication for network access to privileged accounts must be implemented by either accepting and electronically verify Personal Identity Verification (PIV) credentials or inheriting identification and authentication from the operating system.

3.5.1.2 Default Requirements for Control System Devices

For control system devices where User Identification and Authentication requirements are not otherwise indicated in this Section, User Identification and Authentication for network access to privileged accounts must be implemented by accepting and electronically verify Personal Identity Verification (PIV) credentials or inheriting identification and authentication from the operating system.

3.5.2 Authenticator Management

{For Reference Only: This subpart (and its subparts) relates to IA-5 (b),(c),(e),(g),(1),(11); CCI-000176, CCI-001544, CCI-001989, CCI-000182, CCI-001610, CCI-000192, CCI-000193, CCI-000194, CCI-000205, CCI-001619, CCI-001611, CCI-001612, CCI-001613, CCI-001614, CCI-000195, CCI-001615, CCI-000196, CCI-000197, CCI-000199, CCI-000198, CCI-001616, CCI-001617, CCI-000200, CCI-001618, CCI-002041, CCI-002002, CCI-002003}

3.5.2.1 Authentication Type

3.5.2.1.1 For HVAC Control System Devices

Unless otherwise indicated:

a. Software which FULLY supports accounts and which runs on a device must use password-based authentication or hardware token-based authentication.

b. Other devices which FULLY support accounts must use password-based authentication.

c. Devices MINIMALLY supporting accounts must use password-based authentication.

3.5.2.1.2 Default Requirements for Control System Devices

For control system devices where Authentication Type requirements are not otherwise indicated in this Section:

a. Software which FULLY supports accounts and which runs on a device must use password-based authentication or hardware token-based authentication.

SECTION 25 05 11.00 Page 17

b. Other devices which FULLY support accounts must use either password-based authentication or hardware token-based authentication.

c. Devices MINIMALLY supporting accounts must use either password-based authentication or hardware token-based authentication.

3.5.2.2 Password-Based Authentication Requirements

3.5.2.2.1 Passwords for Non-Computer Devices FULLY Supporting Accounts

All non-computer devices FULLY supporting accounts and supporting password-based authentication must enforce the following requirements:

a. Minimum password length of twelve (12) characters

b. Password must contain at least one uppercase character.

c. Password must contain at least one lowercase character.

d. Password must contain at least one numeric character.

e. Password must contain at least one special character.

f. Password must have a maximum lifetime of sixty (60) days. When passwords expire, prompt users to change passwords. Do no lock accounts due to expired passwords.

g. Password must differ from previous five (5) passwords, where differ is defined as changing at least fifty percent of the characters.

h. Passwords must be cryptographically protected during storage and transmission.

3.5.2.2.2 Passwords for Devices Minimally Supporting Accounts

Devices minimally supporting accounts must support passwords with a minimum length of four characters.

3.5.2.2.3 Password Configuration and Reporting

For all devices with a password, change the password from the default password. Coordinate selection of passwords with COR. Do not use the same password for more than one device unless specifically instructed to do so. Provide a Password Summary Report documenting the password for each device and describing the procedure to change the password for each device.

Do not provide the Password Summary Report in electronic format. Provide two hardcopies of the Password Summary Report, each copy in its own sealed envelope.

3.5.2.3 Hardware Token-Based Authentication Requirements

Devices supporting hardware token-based authentication must use Personal Identity Verification (PIV) credentials for the hardware token.

3.5.3 Authenticator Feedback

{For Reference Only: This subpart relates to IA-6; CCI-000206}

SECTION 25 05 11.00 Page 18

Devices must never show authentication information, including passwords, on a display. Devices that momentarily display a character as it is entered, and then obscure the character, are acceptable. For devices that have STIGs or SRGs related to obscuring of authenticator feedback (CCI-000206), comply with the requirements of those STIGS/SRGs.

3.5.4 Device Identification and Authentication

{For Reference Only: This subpart (and its subparts) relates to IA-3;

CCI-000777, CCI-000778, CCI-001958}

All control devices using Ethernet must use IEEE 802.1x for authentication to the network.

3.5.4.1 For HVAC Control System Devices

Devices using Ethernet must support IEEE 802.1x . Devices using BACnet must support Network Security as specified in Clause 24 of ASHRAE 135.

3.5.5 Cryptographic Module Authentication

{For Reference Only: This subpart (and its subparts) relates to IA-7;

CCI-000803}

For devices that have STIG/SRGs related to cryptographic module authentication (CCI-000803), comply with the requirements of those STIG/SRGs.

3.6 EMERGENCY POWER

{For Reference Only: This subpart (and its subparts) relates to

PE-11,(1); CCI-02955, CCI-000961}

Emergency power is specified in the control system and equipment specifications.

3.7 DURABILITY TO VULNERABILITY SCANNING

{For Reference Only: This subpart (and its subparts) relates to RA-5 (a),(b),(c),(d); CCI-001054, CCI-001055, CCI-0010156, CCI-001641, CCI-001643, CCI-001057, CCI-001058, CCI-001059}

All IP devices must be scannable, such that the device can be scanned by industry standard IP network scanning utilities without harm to the device, application, or functionality.

For control system devices other than computers:

3.7.1 HVAC Control System Devices Other Than Computers

HVAC control system devices other than computers are not required to respond to scans.

3.7.2 Default Requirements for Control System Devices

Non-computer control system devices where Durability to Vulnerability Scanning requirements are not otherwise indicated in this Section are not required to respond to scans.

SECTION 25 05 11.00 Page 19

3.8 SYSTEM AND COMMUNICATION PROTECTION

3.8.1 Denial of Service Protection, Process Isolation and Boundary Protection

{For Reference Only: This subpart (and its subparts) relates to SC-5, SC-39, SC-7(a); CCI-001093, CCI-002385, CCI-002386, CCI-002430, CCI-001097}

To the greatest extent practical, implement control logic in non-computer hardware and without reliance on the network.

3.9 SYSTEM AND INTEGRATION INTEGRITY

3.10 FIELD QUALITY CONTROL

3.10.1 Tests

In addition to testing and testing support required by other Sections, provide a minimum of 8 hours of technical support for cybersecurity testing of control systems.

-- End of Section --

SECTION 25 05 11.00 Page 20

SECTION TABLE OF CONTENTS

DIVISION 25 - INTEGRATED AUTOMATION

SECTION 25 05 11.01

CYBERSECURITY FOR ELECTRICAL CONTROL SYSTEMS

11/17 cybersecurity for facility-related control systems

PART 1 GENERAL

1.1 CONTROL SYSTEM APPLICABILITY

1.2 RELATED REQUIREMENTS

1.3 DEFINITIONS

1.3.1 Computer

1.3.2 Network Connected

1.3.3 User…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .