PN81165_RTA_SPECS_Vol III of III.pdf

PDF 6 MB Posted

Attached to
PN 81165 SOF Human Platform FORGE Federal contract opportunity
Solicitation number
W912PM20R0001
Issued by
Department of the Army Corps of Engineers Engineering District Wilmington

About this file

This solicitation is for the construction of a cardio/strength/nutrition training, physical/hydro therapy, special operations cognitive enhancement for performance training, human engagement and adaptive thinking training, and shower/locker space facility at Fort Bragg, North Carolina. Construction includes a concrete foundation and floor slab with metal frame structure, built-in building systems for fire alarm/mass notification, fire suppression, energy management control, telephone and advanced unclassified and classified communications networks, cable TV, intrusion detection, closed circuit surveillance, and electronic access control systems. Supporting facilities include site preparation, utilities, lighting, vehicle parking, access drives, curb and gutter, sidewalks, storm drainage, landscaping, roads, demolition of existing facilities, and other site improvements. Special construction includes sustainable construction features complying with LEED "Silver" certification requirements. The North American Industry Classification System code is 236220 and the size standard is $39.5 million. The estimated value is between $25-100 million. The solicitation is unrestricted and offers are due by the date specified on beta.SAM.gov where the full solicitation is posted.

View the file

Other files for this federal contract opportunity

Other files attached to PN 81165 SOF Human Platform FORGE, newest first.
File Type Posted
Bidder Site Visit Sign In PN81165 6August2020.pdf PDF
W912PM20R0001 Amendment 0006 Conformed Copy.docx.pdf PDF
W912PM20R0001 Amendment 0006.docx.pdf PDF
W912PM20R0001 Amendment 0005.pdf PDF
W912PM20R0001 Amendment 0005 Conformed Copy.docx.pdf PDF
PN81165_RTA_SPECS_Vol IV of IV no pricing_Redacted.pdf PDF
W912PM20R0001 Amendment 0004.pdf PDF
PN81165_RTA_SPECS_Vol II of IV_0004.pdf PDF
W912PM20R0001 Amendment 0001.pdf PDF
PN81165_RTA_SPECS_Vol III of IV_0004.pdf PDF
PN81165_RTA_SPECS_Vol I of IV_0004.pdf PDF
PN81165_RTA_SPECS_Vol IV of IV.pdf PDF
Summary of Changes__PN81165_Amdt0004.pdf PDF
20R0001 Amendment 0004 Conformed Copy.docx.pdf PDF
W912PM20R00010003_Amendment.docx.pdf PDF
W912PM20R00010003_Conformed.docx.pdf PDF
W912PM20R00010002 Conformed.pdf PDF
W912PM20R00010002 Amendment.pdf PDF
Amendment 0001 Wage Determination .pdf PDF
Summary of Changes__PN81165_Amdt0001.pdf PDF
FY20PN81165-C-001 C-001.pdf PDF
Conformed Solicitation PN 81165.pdf PDF
PN81165_READY FOR ADVERTISEMENT_VOL 1(locked).pdf PDF
W912PM20R0001 PN81165 Human Performance FORGE.pdf PDF
PN81165_RTA_SPECS_Vol II of III.pdf PDF
Attachment 5 NAVFAC_USACE PPQ.pdf PDF
PN81165_RTA_SPECS_Vol I of III.pdf PDF
PN81165_READY FOR ADVERTISEMENT_VOL2.pdf PDF
Show all 28

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Solicitation No. W912PM20R0001

PN81165 Construct SOF Human Performance Training Center (HPTC)

Ft. Bragg, North Carolina

RTA Specifications Vol 3 of 3

July 2020

Specifications – Volume III of III

Division 25 – Division 33

Fort Bragg, North Carolina

SOF Human Platform-Force Generation

(FORGE) Facility

PN81165

Solicitation No.: W912PM-20-R-0001

Ready for Advertisement

July 23, 2020

SOF Human Platform-Force Generation (FORGE) Facility PN81165

SEALS Page 1

THIS PAGE INTENTIONALLY LEFT BLANK

SEALS Page 2

PROJECT TABLE OF CONTENTS

DI VI SI ON 00 - PROCUREMENT AND CONTRACTI NG REQUI REMENTS

00 01 15 LIST OF DRAWINGS

DI VI SI ON 01 - GENERAL REQUI REMENTS

01 10 00.10 38 SUPPLEMENTARY SPECIAL CONTRACT REQUIREMENTS DREDGING /

CONSTRUCTION

01 14 00 WORK RESTRICTIONS

01 20 00.00 20 PRICE AND PAYMENT PROCEDURES

01 32 01.00 37 PROJECT SCHEDULE

01 33 00.00 37 SUBMITTAL PROCEDURES

01 33 29 SUSTAINABILITY REPORTING

01 35 26 GOVERNMENTAL SAFETY REQUIREMENTS

01 42 00 SOURCES FOR REFERENCE PUBLICATIONS

01 45 00.00 10 QUALITY CONTROL

01 45 00.15 10 RESIDENT MANAGEMENT SYSTEM CONTRACTOR MODE(RMS CM)

01 45 35 SPECIAL INSPECTIONS

01 50 00 TEMPORARY CONSTRUCTION FACILITIES AND CONTROLS

01 57 19 TEMPORARY ENVIRONMENTAL CONTROLS

01 62 35.37 RECYCLED/RECOVERED/BIOBASED MATERIALS

01 74 19 CONSTRUCTION WASTE MANAGEMENT AND DISPOSAL

01 78 00.00 37 CLOSEOUT SUBMITTALS

01 78 23 OPERATION AND MAINTENANCE DATA

01 91 00.00 37 COMMISSIONING

DI VI SI ON 02 - EXI STI NG CONDI TI ONS

02 41 00 DEMOLITION

02 82 00 ASBESTOS REMEDIATION

02 83 00 LEAD REMEDIATION

02 84 16 HANDLING OF LIGHTING BALLASTS AND LAMPS CONTAINING PCBs

AND MERCURY

DI VI SI ON 03 - CONCRETE

03 30 00 CAST-IN-PLACE CONCRETE

03 35 43 POLISHED CONCRETE FINISHING

DI VI SI ON 04 - MASONRY

04 20 00 UNIT MASONRY

DI VI SI ON 05 - METALS

05 05 23.16 STRUCTURAL WELDING

05 12 00 STRUCTURAL STEEL

05 21 00 STEEL JOIST FRAMING

05 30 00 STEEL DECKS

05 40 00 COLD-FORMED METAL FRAMING

05 50 13 MISCELLANEOUS METAL FABRICATIONS

05 51 00 METAL STAIRS

05 51 33 METAL LADDERS

05 52 00 METAL RAILINGS

DI VI SI ON 06 - WOOD, PLASTI CS, AND COMPOSI TES

PROJECT TABLE OF CONTENTS Page 1

06 10 00 ROUGH CARPENTRY

06 20 00 FINISH CARPENTRY

06 61 16 SOLID SURFACING FABRICATIONS

DI VI SI ON 07 - THERMAL AND MOI STURE PROTECTI ON

07 05 23 PRESSURE TESTING AN AIR BARRIER SYSTEM FOR AIR TIGHTNESS

07 11 13 BITUMINOUS DAMPPROOFING

07 13 53 ELASTOMERIC SHEET WATERPROOFING

07 21 13 BOARD AND BLOCK INSULATION

07 21 16 MINERAL FIBER BLANKET INSULATION

07 22 00 ROOF AND DECK INSULATION

07 24 00 EXTERIOR INSULATION AND FINISH SYSTEMS

07 27 10.00 10 BUILDING AIR BARRIER SYSTEM

07 27 19.01 SELF-ADHERING AIR BARRIERS

07 27 26 FLUID-APPLIED MEMBRANE AIR BARRIERS

07 41 13 METAL ROOF PANELS

07 54 19 POLYVINYL-CHLORIDE ROOFING

07 60 00 FLASHING AND SHEET METAL

07 84 00 FIRESTOPPING

07 92 00 JOINT SEALANTS

DI VI SI ON 08 - OPENI NGS

08 11 13 STEEL DOORS AND FRAMES

08 11 16 ALUMINUM DOORS AND FRAMES

08 14 00 WOOD DOORS

08 31 00 ACCESS DOORS AND PANELS

08 32 13 ALUMINUM SLIDING GLASS DOORS

08 33 23 OVERHEAD COILING DOORS

08 33 43 FIRE AND SMOKE RATED CURTAINS

08 34 73 SOUND CONTROL DOOR ASSEMBLIES

08 41 13 ALUMINUM-FRAMED ENTRANCES AND STOREFRONTS

08 41 23 FIRE RATED ALUMINUM FRAMED STOREFRONTS

08 42 29 SLIDING AUTOMATIC ENTRANCES

08 44 00 CURTAIN WALL AND GLAZED ASSEMBLIES

08 71 00 DOOR HARDWARE

08 81 00 GLAZING

08 91 00 METAL WALL LOUVERS

DI VI SI ON 09 - FI NI SHES

09 22 00 SUPPORTS FOR PLASTER AND GYPSUM BOARD

09 29 00 GYPSUM BOARD

09 30 10 CERAMIC

09 51 00 ACOUSTICAL CEILING TILE

09 65 00 RESILIENT FLOORING

09 65 66 RESILIENT ATHLETIC FLOORING

09 67 23.03 RESINOUS FLOORING

09 68 00 CARPETING

09 90 00 PAINTS AND COATINGS

09 93 23 INTERIOR STAINS AND TRANSPARENT FINISHES

DI VI SI ON 10 - SPECI ALTI ES

10 11 00 VISUAL DISPLAY UNITS

10 14 00.10 EXTERIOR SIGNAGE

10 14 00.20 INTERIOR SIGNAGE

10 14 53 TRAFFIC SIGNAGE

PROJECT TABLE OF CONTENTS Page 2

10 21 13 TOILET COMPARTMENTS

10 26 00 WALL AND DOOR PROTECTION

10 28 13 TOILET ACCESSORIES

10 43 13 DEFIBRILLATOR CABINETS

10 44 16 FIRE EXTINGUISHERS

10 51 13 METAL LOCKERS

10 51 14 METAL MINI LOCKERS

DI VI SI ON 12 - FURNI SHI NGS

12 24 13 ROLLER WINDOW SHADES

12 48 13 ENTRANCE FLOOR MATS AND FRAMES

12 93 00 SITE FURNISHINGS

DI VI SI ON 13 - SPECI AL CONSTRUCTI ON

13 27 00 VAULTS

13 34 19 METAL BUILDING SYSTEMS

DI VI SI ON 14 - CONVEYI NG EQUI PMENT

14 24 23 HYDRAULIC PASSENGER ELEVATORS

DI VI SI ON 21 - FI RE SUPPRESSI ON

21 13 13.00 10 WET PIPE SPRINKLER SYSTEM, FIRE PROTECTION

21 30 00 FIRE PUMPS

DI VI SI ON 22 - PLUMBI NG

22 00 00 PLUMBING, GENERAL PURPOSE

DI VI SI ON 23 - HEATI NG, VENTI LATI NG, AND AI R CONDI TI ONI NG ( HVAC)

23 00 00 AIR SUPPLY, DISTRIBUTION, VENTILATION, AND EXHAUST SYSTEMS

23 05 48.19 FORCE PROTECTION BRACING FOR HVAC

23 05 93 TESTING, ADJUSTING, AND BALANCING FOR HVAC

23 07 00 THERMAL INSULATION FOR MECHANICAL SYSTEMS

23 09 00 INSTRUMENTATION AND CONTROL FOR HVAC

23 09 13 INSTRUMENTATION AND CONTROL DEVICES FOR HVAC

23 09 23.01 LONWORKS DIRECT DIGITAL CONTROL FOR HVAC AND OTHER

BUILDING CONTROL SYSTEMS

23 11 25 FACILITY GAS PIPING

23 21 23 HYDRONIC PUMPS

23 52 00 HEATING BOILERS

23 64 10 WATER CHILLERS, VAPOR COMPRESSION TYPE

23 64 26 CHILLED WATER AND HOT WATER PIPING SYSTEMS

23 81 00 DECENTRALIZED UNITARY HVAC EQUIPMENT

DI VI SI ON 25 - I NTEGRATED AUTOMATI ON

25 05 11.01 CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS - FIRE

ALARM

25 05 11.02 CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS -

BUILDING AUTOMATION SYSTEM (BAS) / BUILDING MANAGEMENT

SYSTEM (BMS)

25 05 11.03 CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS -

LIGHTING CONTROL SYSTEM

25 05 11.04 CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS - CARD

PROJECT TABLE OF CONTENTS Page 3

SWIPE CONTROL SYSTEM

25 05 11.05 CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS -

CLOSED CIRCUIT TELEVISION (CCTV)

25 05 11.06 CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS -

AUDIO VISUAL (A/V)

25 08 10 UTILITY MONITORING AND CONTROL SYSTEM TESTING

25 10 10 UTILITY MONITORING AND CONTROL SYSTEM (UMCS) INTEGRATION

DI VI SI ON 26 - ELECTRI CAL

26 00 00.00 20 BASIC ELECTRICAL MATERIALS AND METHODS

26 05 00.00 40 COMMON WORK RESULTS FOR ELECTRICAL

26 05 48.00 10 SEISMIC PROTECTION FOR ELECTRICAL EQUIPMENT

26 08 00 APPARATUS INSPECTION AND TESTING

26 20 00 INTERIOR DISTRIBUTION SYSTEM

26 24 13 SWITCHBOARDS

26 28 01.00 10 COORDINATED POWER SYSTEM PROTECTION

26 29 23 VARIABLE FREQUENCY DRIVE SYSTEMS UNDER 600 VOLTS

26 41 00 LIGHTNING PROTECTION SYSTEM

26 51 00 INTERIOR LIGHTING

26 56 00 EXTERIOR LIGHTING

DI VI SI ON 27 - COMMUNI CATI ONS

27 05 14.00 10 CABLE TELEVISION PREMISES DISTRIBUTION SYSTEM

27 10 00 BUILDING TELECOMMUNICATIONS CABLING SYSTEM

DI VI SI ON 28 - ELECTRONI C SAFETY AND SECURI TY

28 10 05 ELECTRONIC SECURITY SYSTEMS (ESS)

28 31 76 INTERIOR FIRE ALARM AND MASS NOTIFICATION SYSTEM

DI VI SI ON 31 - EARTHWORK

31 00 00 EARTHWORK

31 11 00 CLEARING AND GRUBBING

31 31 16.13 CHEMICAL TERMITE CONTROL

DI VI SI ON 32 - EXTERI OR I MPROVEMENTS

32 05 33 LANDSCAPE ESTABLISHMENT

32 11 20 BASE COURSE FOR RIGID AND SUBBASES FOR FLEXIBLE PAVING

32 11 23 AGGREGATE BASE COURSES

32 12 13 BITUMINOUS TACK AND PRIME COATS

32 12 16 HOT-MIX ASPHALT (HMA) FOR ROADS

32 13 13.06 PORTLAND CEMENT CONCRETE PAVEMENT FOR ROADS AND SITE

FACILITIES

32 16 19 CONCRETE CURBS, GUTTERS AND SIDEWALKS

32 17 23 PAVEMENT MARKINGS

32 18 13 SYNTHETIC GRASS SURFACING

32 92 23 SODDING

32 93 00 EXTERIOR PLANTS

DI VI SI ON 33 - UTI LI TI ES

33 01 30.16 TV INSPECTION OF SEWER PIPELINES

33 05 23 TRENCHLESS UTILITY INSTALLATION

33 40 00 STORM DRAINAGE UTILITIES

33 51 15 NATURAL-GAS DISTRIBUTION PIPELINES

PROJECT TABLE OF CONTENTS Page 4

33 71 02 UNDERGROUND ELECTRICAL DISTRIBUTION

33 82 00 TELECOMMUNICATIONS OUTSIDE PLANT (OSP)

-- End of Project Table of Contents --

PROJECT TABLE OF CONTENTS Page 5

PROJECT TABLE OF CONTENTS Page 6

SECTION TABLE OF CONTENTS

DIVISION 25 - INTEGRATED AUTOMATION

SECTION 25 05 11.01

CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS - FIRE ALARM

11/17

PART 1 GENERAL

1.1 CONTROL SYSTEM APPLICABILITY

1.2 RELATED REQUIREMENTS

1.3 REFERENCES

1.4 DEFINITIONS

1.4.1 Computer

1.4.2 Network Connected

1.4.3 User Account Support Levels

1.4.3.1 FULLY Supported

1.4.3.2 MINIMALLY Supported

1.4.3.3 NOT Supported

1.4.4 User Interface

1.4.4.1 Limited Local User Interface

1.4.4.2 Full Local User Interface

1.4.4.3 Remote User Interface

1.5 ADMINISTRATIVE REQUIREMENTS

1.5.1 Coordination

1.6 SUBMITTALS

1.7 QUALITY CONTROL

1.7.1 Regulatory Requirements

1.7.2 Certifications and Qualifications:

1.7.3 Pre-Construction Testing

1.8 DELIVERY, STORAGE, AND HANDLING

1.9 CYBERSECURITY DOCUMENTATION

1.9.1 Cybersecurity Interconnection Schedule

1.9.2 Network Communication Report

1.9.3 Control System Inventory Report

1.9.4 Software Recovery and Reconstitution Images

1.9.5 Cybersecurity Riser Diagram

1.9.6 Control System Cybersecurity Documentation

1.9.6.1 Software Applications

1.9.6.2 For HVAC Control System Devices

1.9.6.2.1 HVAC Control System Devices FULLY Supporting User

Accounts

1.9.6.2.2 All Other HVAC Control System Devices

1.9.6.3 Fire Alarm Control System Devices

1.9.6.4 Default Requirements for Control System Devices

1.10 SOFTWARE UPDATE LICENSING

1.11 CYBERSECURITY DURING CONSTRUCTION

1.11.1 Contractor Computer Equipment

1.11.1.1 Operating System

1.11.1.2 Anti-Malware Software

1.11.1.3 Passwords and Passphrases

1.11.1.4 Contractor Computer Cybersecurity Compliance Statements

1.11.2 Temporary IP Networks

SECTION 25 05 11.01 Page 1

1.11.2.1 Network Boundaries and Connections

1.11.3 Government Access to Network

1.11.4 Temporary Wireless IP Networks

1.11.5 Passwords and Passphrases

1.11.6 Contractor Temporary Network Cybersecurity Compliance

Statements

1.12 CYBERSECURITY DURING WARRANTY PERIOD

PART 2 PRODUCTS

PART 3 EXECUTION

3.1 ACCESS CONTROL REQUIREMENTS

3.1.1 User Accounts

3.1.1.1 Computers

3.1.1.2 For HVAC Control System Devices

3.1.1.3 Fire Alarm Control System Devices

3.1.1.4 Default Requirements for Control System Devices

3.1.2 Unsuccessful Logon Attempts

3.1.2.1 Devices MINIMALLY Supporting Accounts

3.1.2.2 Devices FULLY Supporting Accounts

3.1.2.3 High Availability Interfaces Exempt from Unsuccessful

Logon Attempts Requirements

3.1.3 System Use Notification

3.1.3.1 User Interface Banner Schedule

3.1.4 Permitted Actions Without Identification or Authentication

3.1.5 Wireless Access

3.1.5.1 Wireless IP Communications

3.1.5.2 Non-IP Wireless Communication

3.1.5.3 Wireless Communication Request

3.1.5.4 Wireless Communication Testing

3.2 CYBERSECURITY AUDITING

3.2.1 Audit Events, Content of Audit Records, and Audit Generation

3.2.1.1 Computers

3.2.1.1.1 Audited Events

3.2.1.1.2 Audit Event Information To Record

3.2.1.2 For HVAC Control System Devices

3.2.1.2.1 HVAC Control System Devices FULLY Supporting User

Accounts

3.2.1.2.2 Other HVAC Control System Devices

3.2.1.3 Fire Alarm Control System Devices

3.2.1.4 Default Requirements for Control System Devices

3.2.1.4.1 Devices Which FULLY Support Accounts

3.2.1.4.1.1 Audited Events

3.2.1.4.1.2 Audit Event Information To Record

3.2.1.4.2 Devices Which Do Not FULLY Support Accounts

3.2.2 Audit Storage Capacity and Audit Upload

3.2.2.1 Device Audit Record Upload Software

3.2.3 Response to Audit Processing Failures

3.2.4 Time Stamps

3.2.4.1 Computers

3.2.4.2 For HVAC Control System Devices

3.2.4.3 Fire Alarm Control System Devices

3.2.4.4 Default Requirements for Control System Devices

3.3 REQUIREMENTS FOR LEAST FUNCTIONALITY

3.3.1 Non-IP Control Networks

3.3.2 IP Control Networks

3.4 SAFE MODE AND FAIL SAFE OPERATION

SECTION 25 05 11.01 Page 2

3.5 IDENTIFICATION AND AUTHENTICATION

3.5.1 User Identification and Authentication

3.5.1.1 HVAC Control Systems Devices

3.5.1.2 Electronic Security System Devices

3.5.1.3 Fire Alarm Control System Devices

3.5.1.4 Default Requirements for Control System Devices

3.5.2 Authenticator Management

3.5.2.1 Authentication Type

3.5.2.1.1 For HVAC Control System Devices

3.5.2.1.2 Fire Alarm Control System Devices

3.5.2.1.3 Default Requirements for Control System Devices

3.5.2.2 Password-Based Authentication Requirements

3.5.2.2.1 Passwords for Computers

3.5.2.2.2 Passwords for Non-Computer Devices FULLY Supporting

Accounts

3.5.2.2.3 Passwords for Web Interfaces

3.5.2.2.4 Passwords for Devices Minimally Supporting Accounts

3.5.2.2.5 Password Configuration and Reporting

3.5.2.3 Hardware Token-Based Authentication Requirements

3.5.3 Authenticator Feedback

3.5.4 Device Identification and Authentication

3.5.4.1 For HVAC Control System Devices

3.5.4.2 Fire Alarm Control System Devices

3.5.4.3 Default Requirements for Control System Devices

3.5.5 Cryptographic Module Authentication

3.6 EMERGENCY POWER

3.7 DURABILITY TO VULNERABILITY SCANNING

3.7.1 HVAC Control System Devices Other Than Computers

3.7.2 Fire Alarm Control System Devices Other Than Computers

3.7.3 Default Requirements for Control System Devices

3.8 FIPS 201-2 REQUIREMENT

3.9 DEVICES WITH CONNECTION TO MULTIPLE IP NETWORKS

3.10 SYSTEM AND COMMUNICATION PROTECTION

3.10.1 Denial of Service Protection, Process Isolation and Boundary

Protection

3.10.2 Cryptographic Protection

3.11 SYSTEM AND INTEGRATION INTEGRITY

3.11.1 Malicious Code Protection

3.11.2 Information System Monitoring

3.12 FIELD QUALITY CONTROL

3.12.1 Tests

-- End of Section Table of Contents --

SECTION 25 05 11.01 Page 3

SECTION 25 05 11.01 Page 4

SECTION 25 05 11.01

CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS - FIRE ALARM

11/17

PART 1 GENERAL

Many subparts in this Section contain text in curly braces ("{" and "}") indicating which cybersecurity control and control correlation identifier (CCI) the requirements of the subpart relate to. The text inside these curly braces is for Government reference only, and enables coordination of the requirements of this Section with the RMF process throughout the design and construction process. Text in curly braces are not contractor requirements.

This Section refers to Security Requirements Guide (SRGs) and Security Technical Implementation Guide (STIGs). STIGs and SRGs are are available online at the Information Assurance Support Environment (IASE) website at http://iase.disa.mil/stigs/Pages/index.aspx . Not all control system components have applicable STIGs or SRGs.

1.1 CONTROL SYSTEM APPLICABILITY

There are multiple versions of this Section associated with this project.

Different versions have requirements applicable to different control systems. This specific Section applies only to the following control systems: Fire Alarm Control System.

1.2 RELATED REQUIREMENTS

All Sections containing facility-related control systems or control system components are related to the requirements of this Section. Review all specification sections to determine related requirements.

1.3 REFERENCES

The publications listed below form a part of this specification to the extent referenced. The publications are referred to within the text by the basic designation only.

INSTITUTE OF ELECTRICAL AND ELECTRONICS ENGINEERS (IEEE)

IEEE 802.1x (2010) Local and Metropolitan Area Networks - Port Based Network Access Control

NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST)

NIST FIPS 201-2 (2013) Personal Identity Verification (PIV) of Federal Employees and Contractors

U.S. DEPARTMENT OF DEFENSE (DOD)

DODI 8551.01 (2014) Ports, Protocols, and Services Management (PPSM)

DTM 08-060 (2008) Policy on Use of Department of Defense (DoD) Information Systems - Standard Consent Banner and User Agreement

SECTION 25 05 11.01 Page 5

1.4 DEFINITIONS

1.4.1 Computer

As used in this Section, a computer is one of the following:

a. a device running a non-embedded desktop or server version of Microsoft Windows

b. a device running a non-embedded version of MacOS

c. a device running a non-embedded version of Linux

d. a device running a version or derivative of the Android OS, where Android is considered separate from Linux

e. a device running a version of Apple iOS

1.4.2 Network Connected

A component is network connected (or "connected to a network") only when the device has a network transceiver which is directly connected to the network and implements the network protocol. A device lacking a network transceiver (and accompanying protocol implementation) can never be considered network connected. Note that a device connected to a non-IP network is still considered network connected (an IP connection or IP address is not required for a device to be network connected).

Any device that supports wireless communication is network connected, regardless of whether the device is communicating using wireless .

1.4.3 User Account Support Levels

The support for user accounts is categorized in this Section as one of three levels:

1.4.3.1 FULLY Supported

Device supports configurable individual accounts. Accounts can be created, deleted, modified, etc. Privileges can be assigned to accounts.

1.4.3.2 MINIMALLY Supported

Device supports a small, fixed number of accounts (perhaps only one).

Accounts cannot be modified. A device with only a "User" and an "Administrator" account would fit this category. Similarly, a device with two PINs for logon - one for restricted and one for unrestricted rights would fit here (in other words, the accounts do not have to be the traditional "user name and password" structure).

1.4.3.3 NOT Supported

Device does not support any Access Enforcement therefore the whole concept of "account" is meaningless.

1.4.4 User Interface

Generally, a user interface is hardware on a device allowing user

SECTION 25 05 11.01 Page 6 interaction with that device via input (buttons, switches, sliders, keyboard, touch screen, etc.) and a screen. There are three types of user interfaces defined in this Section: Limited Local User Interface, Full Local User Interface and Remote User Interface. In this Section, when the term "User Interface" is used without specifying which type, it refers only to Full Local User Interface and Remote User Interface (NOT to Limited Local User Interface).

1.4.4.1 Limited Local User Interface

A Limited Local User Interface is a user interface where the interaction is limited, fixed at the factory, and cannot be modified in the field.

The user must be physically at the device to interact with it.

Examples of Limited Local User Interface include thermostats (Space Sensor Modules as defined in Section 23 09 13 INSTRUMENTATION AND CONTROL DEVICES

FOR HVAC).

1.4.4.2 Full Local User Interface

A Full Local User Interface is a user interface where the interaction and displays are field-configurable.

Examples of a Full Local User Interface include local applications on a computer and user interfaces to Variable Speed Drives .

1.4.4.3 Remote User Interface

A Remote User Interface is a user interface on a Client device allowing user interaction with a different Server device. The user need not be physically at the Server device to interact with it.

Examples of Remote User Interfaces include web browsers and Local Display Panels as defined in Section 23 09 00 INSTRUMENTATION AND CONTROL FOR HVAC .

1.5 ADMINISTRATIVE REQUIREMENTS

1.5.1 Coordination

Coordinate the execution of this Section with the execution of all other Sections related to control systems as indicated in the paragraph RELATED REQUIREMENTS. Items that must be considered when coordinating project efforts include but are not limited to:

a. If requesting permission for wireless communication, the Wireless Communication Request submittal must be approved prior to control system device selection and integration.

b. If requesting permission for alternate account lock permissions, the Device Account Lock Exception Request must be approved prior to control system device selection and integration.

c. If requesting permission for the use of a device with multiple IP connections, the Multiple IP Connection Device Request must be approved prior to control system device selection and integration.

d. Wireless testing may be required as part of the control system testing. See requirements for the Wireless Communication Test Report submittal.

SECTION 25 05 11.01 Page 7

e. If the Device Audit Record Upload Software is to be installed on a computer not being provided as part of the control system, coordination is required to identify the computer on which to install the software.

f. Cybersecurity Interconnection Schedule must be coordinated with other work that will be interconnected to, and interconnections must be approved by the Government before relying on them for system functionality.

g. Cybersecurity testing support must be coordinated across control systems and with the Government cybersecurity testing schedule.

h. Passwords must be coordinated with the indicated contact for the project site.

i. If applicable, HTTP web server certificates must be obtained from the indicated contact for the project site.

j. Contractor Computer Cybersecurity Compliance Statements for each contractor using contractor owned computers.

1.6 SUBMITTALS

Government approval is required for submittals with a "G" designation;

submittals not having a "G" designation are for information only. When used, a designation following the "G" designation identifies the office that will review the submittal for the Government. Submittals with an "S" are for inclusion in the Sustainability eNotebook, in conformance to Section 01 33 29 SUSTAINABILITY REPORTING. Submit the following in accordance with Section 01 33 00.00 37 SUBMITTAL PROCEDURES:

SD-01 Preconstruction Submittals

Wireless Communication Request; G

Device Account Lock Exception Request; G

Multiple IP Connection Device Request; G

Contractor Computer Cybersecurity Compliance Statements; G

Contractor Temporary Network Cybersecurity Compliance Statements; G

SD-02 Shop Drawings

User Interface Banner Schedule; S

Network Communication Report; G

Cybersecurity Riser Diagram; G

Control System Inventory Report; G

Cybersecurity Interconnection Schedule; G

SD-03 Product Data

SECTION 25 05 11.01 Page 8

Control System Cybersecurity Documentation; G

SD-06 Test Reports

Wireless Communication Test Report; G

SD-07 Certificates

Software Licenses; G

SD-11 Closeout Submittals

Password Summary Report; G

Software Recovery And Reconstitution Images; G

Device Audit Record Upload Software; G

1.7 QUALITY CONTROL

1.7.1 Regulatory Requirements

For the Fire Alarm control system: There are no requirements to include.

1.7.2 Certifications and Qualifications:

For the Fire Alarm control system: There are no requirements to include.

1.7.3 Pre-Construction Testing

For the Fire Alarm control system: Pre-construction testing is not required.

1.8 DELIVERY, STORAGE, AND HANDLING

Delivery, storage or handling requirements are not needed.

1.9 CYBERSECURITY DOCUMENTATION

1.9.1 Cybersecurity Interconnection Schedule

{For Reference Only: This subpart (and its subparts) relates to CA-3(b), CCI-00258}

Provide a completed Cybersecurity Interconnection Schedule documenting connections between the installed system and other systems. Provide the following information for each device communicating between systems:

Device Identifier, Device Description, Transport layer Protocol, Network Address, Port (if applicable), MAC (Layer 2) address (if applicable), Media, Application Protocol, Service (if applicable), Descriptive Purpose of communication. For communication with other authorized systems also provide the Foreign Destination and POC for Destination. If other control system Sections used on this project include submittals documenting this information, provide copies of those submittals to meet this requirement.

In addition to the requirements of Section 01 33 00.00 37 SUBMITTAL PROCEDURES, provide the Cybersecurity Interconnection Schedule as an editable Microsoft Excel file (a template Cybersecurity Interconnection Schedule in Excel format is available at

SECTION 25 05 11.01 Page 9 http://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/forms-graphics-tables

1.9.2 Network Communication Report

{ For Reference Only: This subpart (and its subparts) relates to CA-9;

CCI-002102, CCI-002103, CCI-002104, CCI-002105 and also the submittal requirements associated with CM-6, CM-7 and SC-41 }

Provide a network communication report. For each networked controller, document the communication characteristics of the controller including communication protocols, services used, and a general description of what information is communicated over the network. For each controller using IP, document all TCP and UDP ports used. If other control system Sections used on this project include submittals documenting this information, provide copies of those submittals to meet this requirement. Document any devices using BACnet or LONWORKs communication protocols.

In addition to the requirements of Section 01 33 00.00 37 SUBMITTAL PROCEDURES, provide the Network Communication Report as an editable Microsoft Excel file.

1.9.3 Control System Inventory Report

{ For Reference Only: This subpart (and its subparts) relates to CM-8(a), CP-12, SI-17, IA-3; CCI-000389, CCI-000392, CCI-000398, CCI-002855, CCI-002856, CCI-002857, CCI-002773, CCI-002774, CCI-002775, CCI-000777, CCI-000778, CCI-001958.}

Provide a Control System Inventory report using the Inventory Spreadsheet listed under this Section at http://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/forms-graphics-tables documenting all networked devices, including network infrastructure devices. For each device provide all applicable information for which there is a field on the spreadsheet in accordance with the instructions on the spreadsheet.

In addition to the requirements of Section 01 33 00.00 37 SUBMITTAL PROCEDURES, provide the Control System Inventory Report as an editable Microsoft Excel file.

1.9.4 Software Recovery and Reconstitution Images

{For Reference Only: This subpart (and its subparts) relates to CP-10;

CCI-000550, CCI-000551, CCI-000552.}

For each computer on which software is installed under this project, provide a recovery image of the final as-built computer. This image must allow for bare-metal restore such that restoration of the image is sufficient to restore system operation to the imaged state without the need for re-installation of software.

If additional user permissions are required to meet this requirement, coordinate the creation of the image with the ISSM or system owner (SO).

1.9.5 Cybersecurity Riser Diagram

{ For Reference Only: This subpart (and its subparts) relates to PL-2(a);

CCI-003051, CCI-003053.}

SECTION 25 05 11.01 Page 10

Provide a cybersecurity riser diagram of the complete control system including all network and controller hardware. If the control system specifications require a riser diagram submittal, provide a copy of that submittal as the cybersecurity riser diagram. Otherwise, provide a riser diagram in tabular format.

1.9.6 Control System Cybersecurity Documentation

This subpart (and its subparts) relates to SA-5 (a),(b),(c); CCIs:

CCI-003124, CCI-003125, CCI-003126, CCI-003127, CCI-003128, CCI-003129,

CCI-003130, CCI-003131}

Provide a Control System Cybersecurity Documentation submittal containing the indicated information for each device and software application.

1.9.6.1 Software Applications

For all software applications running on computers provide:

a. administrator documentation that describes secure configuration of the software (relates to CCI-003124)

b. administrator documentation that describes secure installation of the software (relates to CCI-003125)

c. administrator documentation that describes secure operation of the software (relates to CCI-003124)

d. administrator documentation that describes effective use and maintenance of security functions or mechanisms for the software ( relates to CCI-003127

e. administrator documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the software (relates to CCI-003128)

f. user documentation that describes user-accessible security functions or mechanisms in the software and how to effectively use those security functions or mechanisms (relates to CCI-003129)

g. user documentation that describes methods for user interaction which enables individuals to use the software in a more secure manner ( relates to CCI-003130)

h. user documentation that describes user responsibilities in maintaining the security of the software (relates to CCI-003131)

1.9.6.2 For HVAC Control System Devices

1.9.6.2.1 HVAC Control System Devices FULLY Supporting User Accounts

For all HVAC Control System Devices which FULLY support user accounts, provide:

a. Documentation that describes secure configuration of the device {for reference only: relates to CCI-003124}

b. Documentation that describes secure operation of the device {for reference only: relates to CCI-003124}

SECTION 25 05 11.01 Page 11

c. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {for reference only: relates to

CCI-003127}

d. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {for reference only: relates to CCI-003128}

e. Documentation that describes user-accessible security functions or mechanisms in the device and how to effectively use those security functions or mechanisms; or a specific indication that there are no user-accessible security functions or mechanisms in the device {for reference only: relates to CCI-003129}

f. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {for reference only: relates to CCI-003130}

1.9.6.2.2 All Other HVAC Control System Devices

For all HVAC Control System Devices which do not FULLY support user accounts, provide:

a. Documentation that describes secure configuration of the device; or a specific indication that there are no secure configuration steps that apply {for reference only: relates to CCI-003124}

b. Documentation that describes effective use and maintenance of security functions or mechanisms for the device; or a specific indication that there are no security functions or mechanisms in the device {for reference only: relates to CCI-003127}

c. For devices which include a user interface, documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {for reference only: relates to

CCI-003130}

1.9.6.3 Fire Alarm Control System Devices

Not applicable.

1.9.6.4 Default Requirements for Control System Devices

For control system devices where Control System Cybersecurity Documentation requirements are not otherwise indicated in this Section, provide:

a. Documentation that describes secure configuration of the device {for reference only: relates to CCI-003124}

b. Documentation that describes secure installation of the device {for reference only: relates to CCI-003125}

c. Documentation that describes secure operation of the device {for reference only: relates to CCI-003124}

d. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {for reference only: relates to

CCI-003127}

SECTION 25 05 11.01 Page 12

e. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {for reference only: relates to CCI-003128}

f. Documentation that describes user-accessible security functions or mechanisms in the device and how to effectively use those security functions or mechanisms {for reference only: relates to CCI-003129}

g. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {for reference only: relates to CCI-003130}

h. Documentation that describes user responsibilities in maintaining the security of the device {for reference only: relates to CCI-003131}

1.10 SOFTWARE UPDATE LICENSING

{For Reference Only: This subpart (and its subparts) relates to SI-2 (a),(c); CCI-001227, CCI-002605}

In addition to all other licensing requirements, all software licensing must include licensing of the following software updates for a period of no less than 5 years:

a. Security and bug-fix patches issued by the software manufacturer.

b. Security patches to address any vulnerability identified in the National Vulnerability Database at http://nvd.nist.gov with a Common Vulnerability Scoring System (CVSS) severity rating of MEDIUM or higher.

Provide a single Software Licenses submittal with documentation of the software licenses for all software provided

1.11 CYBERSECURITY DURING CONSTRUCTION

{For Reference Only: This subpart (and its subparts) relates to AC-18, SA-3, CCI-00258}

In addition to the control system cybersecurity requirements indicated in this section, meet following requirement throughout the construction process.

1.11.1 Contractor Computer Equipment

Contractor owned computers may be used for construction. When used, contractor computers must meet the following requirements:

1.11.1.1 Operating System

The operating system must be an operating system currently supported by the manufacturer of the operating system. The operating system must be current on security patches and operating system manufacturer required updates.

1.11.1.2 Anti-Malware Software

The computer must run anti-malware software from a reputable software

SECTION 25 05 11.01 Page 13 manufacturer. Anti-malware software must be a version currently supported by the software manufacturer, must be current on all patches and updates, and must use the latest definitions file. All computers used on this project must be scanned using the installed software at least once per day.

1.11.1.3 Passwords and Passphrases

The passwords and passphrases for all computers must be changed from their default values. Passwords must be a minimum of eight characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.

1.11.1.4 Contractor Computer Cybersecurity Compliance Statements

Provide a single submittal containing completed Contractor Computer Cybersecurity Compliance Statements for each company using contractor owned computers. Contractor Computer Cybersecurity Compliance Statements must use the template published at http://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/forms-graphics-tables Each Statement must be signed by a cybersecurity representative for the relevant company.

1.11.2 Temporary IP Networks

Temporary contractor-installed IP networks may be used during construction. When used, temporary contractor-installed IP networks must meet the following requirements:

1.11.2.1 Network Boundaries and Connections

The network must not extend outside the project site and must not connect to any IP network other than IP networks provided under this project or Government furnished IP networks provided for this purpose. Any and all network access from outside the project site is prohibited.

1.11.3 Government Access to Network

Government personnel must be allowed to have complete and immediate access to the network at any time in order to verify compliance with this specification

1.11.4 Temporary Wireless IP Networks

In addition to the other requirements on temporary IP networks, temporary wireless IP (WiFi) networks must not interfere with existing wireless network and must use WPA2 security. Network names (SSID) for wireless networks must be changed from their default values.

1.11.5 Passwords and Passphrases

The passwords and passphrases for all network devices and network access must be changed from their default values. Passwords must be a minimum 8 characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.

1.11.6 Contractor Temporary Network Cybersecurity Compliance Statements

Provide a single submittal containing completed Contractor Temporary Network Cybersecurity Compliance Statements for each company implementing

SECTION 25 05 11.01 Page 14 a temporary IP network. Contractor Temporary Network Cybersecurity Compliance Statements must use the template published at http://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/forms-graphics-tables Each Statement must be signed by a cybersecurity representative for the relevant company. If no temporary IP networks will be used, provide a single copy of the Statement indicating this.

1.12 CYBERSECURITY DURING WARRANTY PERIOD

All work performed on the control system after acceptance must be performed using Government Furnished Equipment or equipment specifically and individually approved by the Government.

PART 2 PRODUCTS

(NOT USED)

PART 3 EXECUTION

3.1 ACCESS CONTROL REQUIREMENTS

3.1.1 User Accounts

{For Reference Only: This subpart (and its subparts) relate to AC-2(a)and

AC-3; CCI-002110, CCI-000213.}

Any device supporting user accounts (either FULLY or MINIMALLY) must limit access to the device according to specified limitations for each account.

Install and configure any device having a STIG or SRG in accordance with that STIG or SRG.

3.1.1.1 Computers

All computers must FULLY support user accounts.

3.1.1.2 For HVAC Control System Devices

Devices with web interfaces must either FULLY support user accounts or have their web interface disabled. Field devices with full local user interfaces allowing modification of data must at least MINIMALLY support user accounts.

3.1.1.3 Fire Alarm Control System Devices

Not applicable.

3.1.1.4 Default Requirements for Control System Devices

For control system devices where User Account requirements are not otherwise indicated in this Section:

a. Devices with web interfaces must either at least MINIMALLY support user accounts or have their web interface disabled.

b. Field devices with full local user interfaces allowing modification of data must at least MINIMALLY support user accounts.

c. Field devices with read-only full local user interfaces must at least MINIMALLY support user accounts.

SECTION 25 05 11.01 Page 15

3.1.2 Unsuccessful Logon Attempts

{For Reference Only: This subpart (and its subparts) relate AC-7 (a), AC-7 (b); CCI-000043, CCI-000044, CCI-001423, CCI-002236, CCI-002237, CCI-002238}

Except for high availability user interfaces indicated as exempt, devices must meet the indicated requirements for handling unsuccessful logon attempts.

3.1.2.1 Devices MINIMALLY Supporting Accounts

Devices which MINIMALLY support accounts are not required to lock based on unsuccessful logon attempts.

3.1.2.2 Devices FULLY Supporting Accounts

Devices which FULLY support accounts must meet the following requirements. If a device cannot meet these requirements, document device capabilities to protect from subsequent unsuccessful logon attempts and propose alternate protections in a Device Account Lock Exception Request submittal. Do not implement alternate protection measures without explicit permission from the Government.

a. It must lock the user account when three unsuccessful logon attempts occur within a 15 minute interval.

b. Once an account is locked, the account must stay locked until unlocked by an administrator.

c. Once the indicated number of unsuccessful logon attempts occurs, delay further logon prompts by 5 seconds.

3.1.2.3 High Availability Interfaces Exempt from Unsuccessful Logon Attempts Requirements

There are no high availability interfaces which are exempt from unsuccessful logon attempts requirements.

The following table is not required because there are no high availabilty interface requirements.

Hi gh Avai l abi l i t y I nt er f aces Exempt f r om Unsuccessf ul Logon At t empt s Requi r ement s

User I nt er f ace Location Act i on t o t ake i n l i eu of l ocki ng scr een

3.1.3 System Use Notification

(For Reference Only: This subpart (and its subparts) relates to AC-8;

CCI-000048, CCI-002247, CCI-002243, CCI-002244, CCI-002245, CCI-002246,

SECTION 25 05 11.01 Page 16

CCI-000050, CCI-002248)

Web interfaces must display a warning banner meeting the requirements of

DTM 08-060 .

Devices which are connected to a network and have a user interface must display a warning banner meeting the requirements of DTM 08-060 if capable of doing so. Devices which are connected to a network and have a user interface but are not capable of displaying a banner must have a permanently affixed label displaying an approved banner from DTM 08-060 .Labels must be machine printed or engraved, plastic or metal, designed for permanent installation, must use a font no smaller than 14 point, and must provide a high contract between font and background colors.

3.1.3.1 User Interface Banner Schedule

Provide a User Interface Schedule using the format indicated showing each user interface provided and how the information banner requirement has been implemented for each user interface.

User I nt er f ace Schedul e For mat ( wi t h sampl e ent r i es)

User I nt er f ace Description

User I nt er f ace Location

Type of User Interface

Banner I mpl ement at i on

Sample 1 Room 1 Remote DTM 08-060 Banner "A" Displayed at Logon

Sample 2 Room 2 Limited Local DTM 08-060 Banner "B" on Affixed Label

Sample 3 Room 3 Full Local DTM 08-060 Banner "B" Displayed on Screen

3.1.4 Permitted Actions Without Identification or Authentication

{For Reference Only: This subpart (and its subparts) relates to AC-14;

CCI-000061, CCI-000232}

The control system must require identification and authentication before allowing any actions by a user acting from a user interface which MINIMALLY or FULLY supports accounts.

3.1.5 Wireless Access

{For Reference Only: This subpart (and its subparts) relates to AC-18;

CCI-001438, CCI-001439, CCI-002323, CCI-001441}

Unless explicitly authorized by the Government, do not use any wireless communication. Any device with wireless communication capability is considered to be using wireless communication, regardless of whether or not the device is actively communicating wirelessly, except when wireless communication has been physically permanently disabled (such as through the removal of the wireless transceiver).

SECTION 25 05 11.01 Page 17

3.1.5.1 Wireless IP Communications

Unless specifically approved and installed in accordance with the project site requirements, D o not install wireless IP networks, including: do not install a wireless access point; do not install or configure an ad-hoc wireless network; do not install or configure a WiFi Direct communication.

When explicitly authorized by the Government, wireless IP communication may be used to communicate with an existing wireless network.

3.1.5.2 Non-IP Wireless Communication

When non-IP wireless communication is explicitly authorized by the Government, use the maximum level of encryption supported by the specific protocol employed and select signal strength and radiated power to the minimum necessary for reliable communication.

3.1.5.3 Wireless Communication Request

Provide a report documenting the proposed use of wireless communication prior to beginning construction using the Wireless Communication Request Schedule at http://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/forms-graphics-tables

For each device proposed to use wireless communication show: the device identifier, a description of the device, the location of the device, the device identifiers of other devices communicating with the device, the protocol used for communication, encryption type and strength, RF Frequency, Radiated Power in dBm (decibel with a milliwatt reference), free-space range, and the expected as-installed range.

3.1.5.4 Wireless Communication Testing

As part of Performance Verification Testing (PVT), conduct testing of wireless communication for all devices indicated on the approved Wireless Communication Request as requiring testing.

To test wireless communication, test for wireless network reception at multiple points along the wireless test boundary in the vicinity of the wireless device, and record whether a network connection can be established at each point. The wireless test boundary is the facility fence line. If wireless testing is required, provide a Wireless Communication Test Report documenting the testing points and results at each point for each wireless device.

3.2 CYBERSECURITY AUDITING

3.2.1 Audit Events, Content of Audit Records, and Audit Generation

{For Reference Only: This subpart (and its subparts) relates to AU-2(a),(c),(d), AU-3, AU-12; CCI-000123, CCI-001571, CCI-000125, CCI-001485, CCI-000130, CCI-000131, CCI-000132, CCI-00133, CCI-000134, CCI-001487, CCI-000169, CCI-001459, CCI-000171, CCI-000172, CCI-001910}

For devices that have STIG/SRGs related to audit events, content of audit records or audit generation, comply with the requirements of those STIG/SRGs.

SECTION 25 05 11.01 Page 18

3.2.1.1 Computers

For each computer, provide the capability to select audited events and the content of audit logs. Configure computers to audit the indicated events, and to record the indicated information for each auditable event

3.2.1.1.1 Audited Events

Configure each computer to audit the following events:

a. Successful and unsuccessful attempts to access, modify, or delete privileges, security objects, security levels, or categories of information (e.g. classification levels)

b. Successful and unsuccessful logon attempts

c. Privileged activities or other system level access

d. Starting and ending time for user access to the system

e. Concurrent logons from different workstations

f. Successful and unsuccessful accesses to objects

g. All program initiations

h. All direct access to the information system

i. All account creations, modifications, disabling, and terminations

j. All kernel module load, unload, and restart

3.2.1.1.2 Audit Event Information To Record

Configure each computer to record, for each auditable event, the following information (where applicable to the event):

a. What type of event occurred

b. When the event occurred

c. Where the event occurred

d. The source of the event

e. The outcome of the event

f. The identity of any individuals or subjects associated with the event

3.2.1.2 For HVAC Control System Devices

3.2.1.2.1 HVAC Control System Devices FULLY Supporting User Accounts

For devices FULLY supporting accounts, provide the capability to select audited events, and the contents of audit logs. Configure devices to audit the following events:

a. Successful and unsuccessful logon attempts to the device

SECTION 25 05 11.01 Page 19

b. Starting and ending time for user access to the device

c. All account creations, modifications, disabling, and terminations

d. All device shutdown and startup

Configure the device to record for each event the following information (as applicable): the type of event, when the event occurred and the identity of any individuals or subjects associated with the event

3.2.1.2.2 Other HVAC Control System Devices

There are no requirements to perform auditing at HVAC field devices that do not FULLY support accounts.

3.2.1.3 Fire Alarm Control System Devices

3.2.1.4 Default Requirements for Control System Devices

For control system devices where Audit Events, Content of Audit Records, and Audit Generation are not otherwise indicated in this Section:

3.2.1.4.1 Devices Which FULLY Support Accounts

For each device which FULLY supports accounts, provide the capability to select audited events and the content of audit logs. Configure devices to audit the indicated events, and to record the indicated information for each auditable event

3.2.1.4.1.1 Audited Events

Configure each device to audit the following events:

a. Successful and unsuccessful attempts to access, modify, or delete privileges, security objects, security levels, or categories of information (e.g. classification levels)

b. Successful and unsuccessful logon attempts

c. Privileged activities or other system level access

d. Starting and ending time for user access to the system

e. Concurrent logons from different workstations

f. All account creations, modifications, disabling, and terminations

g. All kernel module load, unload, and restart

3.2.1.4.1.2 Audit Event Information To Record

Configure each computer to record, for each auditable event, the following information (where applicable to the event):

a. what type of event occurred

b. when the event occurred

c. where the event occurred

SECTION 25 05 11.01 Page 20

d. the source of the event

e. the outcome of the event

f. the identity of any individuals or subjects associated with the event

3.2.1.4.2 Devices Which Do Not FULLY Support Accounts

For each Device which does not FULLY support accounts configure the device to audit all device shutdown and startup events and to record for each event the type of event and when the event occurred.

3.2.2 Audit Storage Capacity and Audit Upload

{For Reference Only: This subpart (and its subparts) relates to AU-4;

CCI-001848, CCI-001849}

a. For devices that have STIG/SRGs related to audit storage capacity (CCI-001848 or CCI-001849) comply with the requirements of those STIG/SRGs.

b. For non-computer control system devices capable of generating audit records, provide 60 days worth of secure local storage, assuming 10 auditable events per day.

c. For computers, provide storage for at least 10 audit records.

3.2.2.1 Device Audit Record Upload Software

For each non-computer device required to audit events, provide, and license to the Government, software implementing a secure mechanism of uploading audit records from the device to a computer and of exporting the uploaded audit records as a Microsoft Excel file. Where different devices use different software, provide software of each type required to upload audit logs from all devices.

Submit copies of device audit record upload software. If there are no non-computer devices requiring auditing, provide a document stating this in lieu of this submittal.

3.2.3 Response to Audit Processing Failures

{For Reference Only: This subpart (and its subparts) relates to AU-5;

CCI-000139, CCI-000140, CCI-001490}.

Front end computers associated with auditing must, in the case of a failure in the auditing system, notify the ISSM or system owner (SO) via e-mail. In case of an audit failure, if possible, continue to collect audit records by overwriting the oldest existing audit records.

3.2.4 Time Stamps

{For Reference Only: This subpart (and its subparts) relates to AU-8;

CCI-000159, CCI-001889, CCI-001890}

3.2.4.1 Computers

Computers generating audit records must have internal clocks capable of

SECTION 25 05 11.01 Page 21 providing time with a resolution of 1 second. Clocks must not drift more than 10 seconds per day.

Configure the system…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .