RAMEY Specs V3 25-32.pdf
PDF 2 MB Posted
- Attached to
- Ramey Unit School Replacement Federal contract opportunity
- Solicitation number
- Not on record
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| DraftVOLUME 2_COMPILED SET_update 5-16-2022 2 of 4.pdf | ||
| DraftVOLUME 2_COMPILED SET_update 5-16-2022 3 of 4.pdf | ||
| DraftVOLUME 2_COMPILED SET_update 5-16-2022 1 of 4.pdf | ||
| DraftVOLUME 2_COMPILED SET_update 5-16-2022 4 of 4.pdf | ||
| DraftVOLUME 1_COMPILED SET 1.pdf | ||
| RAMEY Specs V5 Attachments.pdf | ||
| RAMEY Specs V2 09-23.pdf | ||
| W912HN22R3001 Draft Ramey School Final 19 May.pdf | ||
| DraftVOLUME 3_COMPILED SET_updated 4-12-2022.pdf | ||
| RAMEY Specs V1 01-08.pdf | ||
| RAMEY Specs V4 33-35.pdf |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
AGUADILLA,
PUERTO RICO
Solicitation Number
W912HN-22-R-3001
Ramey Unit School Replacement Volume 3 of 5: Specifications Divisions 25 - 32
PN AM00049
May 2022
U.S. ARMY ENGINEER DISTRICT, SAVANNAH
CORPS OF ENGINEERS
100 WEST OGLETHORPE AVENUE
SAVANNAH, GEORGIA 31401-3640
US Army Corps Of Engineers Savannah District
RAMEY UNIT SCHOOL REPLACEMENT 22R3001
AGUADILLA, PUERTO RICO
PROJECT TABLE OF CONTENTS
DI VI SI ON 01 - GENERAL REQUI REMENTS
01 11 00 08/15, CHG 2: 08/21 SUMMARY OF WORK
01 14 00 11/11, CHG 14: 02/22 WORK RESTRICTIONS
01 23 00 03/14 BID OPTIONS
01 30 00 09/21 ADMINISTRATIVE PROCEDURES
01 32 01 01/22 PROJECT SCHEDULE
01 33 00 02/22 SUBMITTAL PROCEDURES
01 33 29 02/15 SUSTAINABILITY REPORTING
01 33 29.37 07/14 LEED(TM) DOCUMENTATION
01 35 26 12/21 GOVERNMENTAL SAFETY REQUIREMENTS
01 42 00 11/14 SOURCES FOR REFERENCE PUBLICATIONS
01 45 00 03/20 RESIDENT MANAGEMENT SYSTEM CONTRACTOR
MODE (RMS CM)
01 45 00.00 10 11/16 QUALITY CONTROL
01 45 04 02/22 CONTRACTOR QUALITY CONTROL
01 45 35 11/20 SPECIAL INSPECTIONS
01 50 02 02/22 TEMPORARY CONSTRUCTION FACILITIES
01 52 10 02/22 CONTRACTING OFFICER'S FIELD OFFICE
01 55 26 01/22 TRAFFIC CONTROL
01 57 19 11/15, CHG 5: 08/21 TEMPORARY ENVIRONMENTAL CONTROLS
01 57 20 ENVIRONMENTAL PROTECTION
01 74 19 02/19, CHG 3: 11/21 CONSTRUCTION WASTE MANAGEMENT AND
DISPOSAL
01 78 00 05/19, CHG 1: 08/21 CLOSEOUT SUBMITTALS
01 78 23 08/15, CHG 2: 08/21 OPERATION AND MAINTENANCE DATA
01 91 00.15 10 05/19, CHG 2: 08/20 TOTAL BUILDING COMMISSIONING
DI VI SI ON 02 - EXI STI NG CONDI TI ONS
02 41 00 05/10, CHG 2: 02/19 DEMOLITION
02 42 91 11/18 REMOVAL AND SALVAGE OF HISTORIC
CONSTRUCTION MATERIALS
02 81 00 11/18 TRANSPORTATION AND DISPOSAL OF
HAZARDOUS MATERIALS
02 82 00 11/18, CHG 1: 11/19 ASBESTOS REMEDIATION
02 83 00 11/18 LEAD REMEDIATION
02 84 16 05/20 HANDLING OF LIGHTING BALLASTS AND
LAMPS CONTAINING PCBs AND MERCURY
02 84 33 05/20 REMOVAL AND DISPOSAL OF
POLYCHLORINATED BIPHENYLS (PCBs)
DI VI SI ON 03 - CONCRETE
03 30 00 02/19, CHG 2: 05/21 CAST-IN-PLACE CONCRETE
03 33 00 11/09 CAST-IN-PLACE ARCHITECTURAL CONCRETE
03 52 00 08/11 LIGHTWEIGHT CONCRETE ROOF INSULATION
DI VI SI ON 05 - METALS
05 50 13 05/17, CHG 1: 08/18 MISCELLANEOUS METAL FABRICATIONS
05 51 00 02/17, CHG 1: 05/17 METAL STAIRS
05 51 33 02/16, CHG 2: 02/18 METAL LADDERS
05 52 00 02/18, CHG 1: 02/20 METAL RAILINGS
DI VI SI ON 06 - WOOD, PLASTI CS, AND COMPOSI TES
PROJECT TABLE OF CONTENTS Page 1
06 10 00 08/16, CHG 2: 11/18 ROUGH CARPENTRY
06 41 16.00 10 08/10, CHG 1: 11/18 SOLID PHENOLIC ARCHITECTURAL CABINETS
06 61 16 08/20 SOLID SURFACING FABRICATIONS
DI VI SI ON 07 - THERMAL AND MOI STURE PROTECTI ON
07 05 23 08/19 PRESSURE TESTING AN AIR BARRIER SYSTEM
FOR AIR TIGHTNESS
07 17 00 02/16 BENTONITE WATERPROOFING
07 21 16 11/11, CHG 4: 08/18 MINERAL FIBER BLANKET INSULATION
07 27 10.00 10 08/19, CHG 1: 02/20 BUILDING AIR BARRIER SYSTEM
07 52 00 05/12, CHG 5: 11/19 MODIFIED BITUMINOUS MEMBRANE ROOFING
07 60 00 05/17, CHG 2: 11/18 FLASHING AND SHEET METAL
07 84 00 05/10, CHG 1: 08/13 FIRESTOPPING
07 92 00 08/16, CHG 3: 11/18 JOINT SEALANTS
DI VI SI ON 08 - OPENI NGS
08 11 13 08/20 STEEL DOORS AND FRAMES
08 14 00 08/16, CHG 1: 08/18 WOOD DOORS
08 33 13 05/09, CHG 2: 11/12 COILING COUNTER DOORS
08 33 23 08/20, CHG 1: 02/22 OVERHEAD COILING DOORS
08 34 73 11/19, CHG 1: 02/21 SOUND CONTROL DOOR ASSEMBLIES
08 39 54 08/09 BLAST RESISTANT DOORS
08 41 13 08/18, CHG 1: 08/18 ALUMINUM-FRAMED ENTRANCES AND
STOREFRONTS
08 44 00 05/19 CURTAIN WALL AND GLAZED ASSEMBLIES
08 71 00 02/16, CHG 4: 02/22 DOOR HARDWARE
08 81 00 05/19 GLAZING
08 91 00 08/20 METAL WALL LOUVERS
DI VI SI ON 09 - FI NI SHES
09 06 00 05/09, CHG 1: 11/13 SCHEDULES FOR FINISHES
09 22 00 02/10, CHG 2: 08/18 SUPPORTS FOR PLASTER AND GYPSUM BOARD
09 29 00 08/16, CHG 4: 02/20 GYPSUM BOARD
09 30 10 08/20 TILING
09 51 00 08/20 ACOUSTICAL CEILINGS
09 65 00 08/10, CHG 3: 08/18 RESILIENT FLOORING
09 65 66 08/16, CHG 1: 08/18 RESILIENT ATHLETIC FLOORING
09 66 23 08/16, CHG 1: 08/18 RESINOUS MATRIX TERRAZZO FLOORING
09 67 23.13 11/19 STANDARD RESINOUS FLOORING
09 68 00 11/17, CHG 2: 08/20 CARPETING
09 72 00 08/17, CHG 1: 08/18 WALLCOVERINGS
09 84 20 08/16, CHG 1: 08/18 ACOUSTICAL WALL AND CEILING PANELS
09 90 00 02/21 PAINTS AND COATINGS
DI VI SI ON 10 - SPECI ALTI ES
10 11 00 08/20 VISUAL DISPLAY UNITS
10 14 00.10 08/17, CHG 1: 11/18 EXTERIOR SIGNAGE
10 14 00.20 08/20 INTERIOR SIGNAGE AND GRAPHIC BOARDS
10 21 13 08/20 TOILET COMPARTMENTS
10 21 23.16 04/06 CUBICLE TRACK AND HARDWARE
10 22 39 08/20 FOLDING PANEL PARTITIONS
10 26 00 08/20 WALL AND DOOR PROTECTION
10 28 13 08/20 TOILET ACCESSORIES
10 44 16 11/19 FIRE EXTINGUISHERS
10 51 26 PLASTIC LOCKERS
PROJECT TABLE OF CONTENTS Page 2
10 56 28 HIGH DENSITY STORAGE
10 71 36 CANOPIES
10 75 00 FLAGPOLES
DI VI SI ON 11 - EQUI PMENT
11 05 40 3/16/2022 COMMON WORK RESULTS FOR FOODSERVICE
EQUIPMENT
11 13 00 LOADING DOCK EQUIPMENT
11 31 13 08/17, CHG 1: 08/18 ELECTRIC KITCHEN EQUIPMENT
11 61 00 STAGE EQUIPMENT
11 66 00 ATHLETIC EQUIPMENT
11 68 13 08/17, CHG 1: 08/18 PLAYGROUND EQUIPMENT
11 68 43 SCOREBOARDS
11 81 29 FACILITY FALL PROTECTION
11 90 00 MISCELLANEOUS EQUIPMENT
DI VI SI ON 12 - FURNI SHI NGS
12 24 13 08/20 ROLLER WINDOW SHADES
12 61 13 08/20 UPHOLSTERED AUDIENCE SEATING
12 63 33 BLEACHERS
DI VI SI ON 13 - SPECI AL CONSTRUCTI ON
13 34 23 11/11 PRE-FABRICATED GUARD BOOTHS
13 48 73 05/20, CHG 1: 08/20 SEISMIC CONTROL FOR MECHANICAL
EQUIPMENT
DI VI SI ON 14 - CONVEYI NG EQUI PMENT
14 24 23 05/16 HYDRAULIC PASSENGER ELEVATORS
DI VI SI ON 21 - FI RE SUPPRESSI ON
21 13 13 08/20 WET PIPE SPRINKLER SYSTEMS, FIRE
PROTECTION
21 30 00 04/08, CHG 1: 08/13 FIRE PUMPS
21 30 01 PACKAGED FIRE PUMP SYSTEM ENCLOSURE
21 41 00 STEEL WATER STORAGE TANKS FOR
FIRE-SUPPRESSION WATER
DI VI SI ON 22 - PLUMBI NG
22 00 00 11/15, CHG 4: 05/21 PLUMBING, GENERAL PURPOSE
DI VI SI ON 23 - HEATI NG, VENTI LATI NG, AND AI R CONDI TI ONI NG ( HVAC)
23 05 15 02/14 COMMON PIPING FOR HVAC
23 05 48.19 05/18, CHG 2: 08/20 SEISMIC BRACING FOR HVAC
23 05 93 11/15 TESTING, ADJUSTING, AND BALANCING FOR
HVAC
23 07 00 02/13, CHG 7: 05/20 THERMAL INSULATION FOR MECHANICAL
SYSTEMS
23 09 00 02/19, CHG 3: 05/21 INSTRUMENTATION AND CONTROL FOR HVAC
23 09 13 11/15, CHG 2: 05/21 INSTRUMENTATION AND CONTROL DEVICES
FOR HVAC
23 09 23.01 02/19, CHG 1: 02/20 LONWORKS DIRECT DIGITAL CONTROL FOR
HVAC AND OTHER BUILDING CONTROL SYSTEMS
PROJECT TABLE OF CONTENTS Page 3
23 11 20 05/20 FACILITY GAS PIPING
23 23 00 10/07 REFRIGERANT PIPING
23 30 00 05/20 HVAC AIR DISTRIBUTION
23 64 10 11/16, CHG 2: 08/18 WATER CHILLERS, VAPOR COMPRESSION TYPE
23 64 26 08/09, CHG 5: 11/19 CHILLED, CHILLED-HOT, AND CONDENSER
WATER PIPING SYSTEMS
23 81 00 05/18, CHG 1: 02/21 DECENTRALIZED UNITARY HVAC EQUIPMENT
DI VI SI ON 25 - I NTEGRATED AUTOMATI ON
25 05 11.01 05/21 CYBERSECURITY FOR BUILDING MANAGEMENT
SYSTEMS (BMS)
25 05 11.02 05/21 CYBERSECURITY FOR FACILITY-RELATED
CONTROL SYSTEMS - FIRE ALARM AND MASS
NOTIFICATION SYSTEMS
25 05 11.03 05/21 CYBERSECURITY FOR LIGHTING CONTROL
SYSTEM
25 05 11.04 05/21 CYBERSECURITY FOR FACILITY-RELATED
CONTROL SYSTEMS
25 10 10 02/19, CHG 1: 05/21 UTILITY MONITORING AND CONTROL SYSTEM
(UMCS) FRONT END AND INTEGRATION
DI VI SI ON 26 - ELECTRI CAL
26 05 48.00 10 10/07 SEISMIC PROTECTION FOR ELECTRICAL
EQUIPMENT
26 08 00 08/08, CHG 1: 02/15 APPARATUS INSPECTION AND TESTING
26 12 19.10 05/19, CHG 1: 11/19 THREE-PHASE, LIQUID-FILLED PAD-MOUNTED
TRANSFORMERS
26 20 00 08/19, CHG 2: 05/21 INTERIOR DISTRIBUTION SYSTEM
26 24 13 05/15, CHG 1: 08/17 SWITCHBOARDS
26 28 01.00 10 10/07 COORDINATED POWER SYSTEM PROTECTION
26 29 23 02/20, CHG: 1 - 05/21 ADJUSTABLE SPEED DRIVE (ASD) SYSTEMS
UNDER 600 VOLTS
26 31 00 05/15 SOLAR PHOTOVOLTAIC (PV) COMPONENTS
26 32 15.00 05/20 ENGINE-GENERATOR SET STATIONARY
15-2500 KW, WITH AUXILIARIES
26 36 23 05/20 AUTOMATIC TRANSFER SWITCHES AND
BY-PASS/ISOLATION SWITCH
26 41 00 11/13 LIGHTNING PROTECTION SYSTEM
26 51 00 05/20, CHG 1: 05/21 INTERIOR LIGHTING
26 56 00 05/20 EXTERIOR LIGHTING
DI VI SI ON 27 - COMMUNI CATI ONS
27 10 00 08/11 BUILDING TELECOMMUNICATIONS CABLING
SYSTEM
27 51 23.10 05/11 INTERCOMMUNICATION SYSTEM
DI VI SI ON 28 - ELECTRONI C SAFETY AND SECURI TY
28 10 05 05/16 ELECTRONIC SECURITY SYSTEMS (ESS)
28 31 76 08/20 INTERIOR FIRE ALARM AND MASS
NOTIFICATION SYSTEM, ADDRESSABLE
DI VI SI ON 31 - EARTHWORK
31 00 00 08/08, CHG 2: 02/21 EARTHWORK
31 11 00 11/18 CLEARING AND GRUBBING
PROJECT TABLE OF CONTENTS Page 4
31 31 16.13 08/16 CHEMICAL TERMITE CONTROL
31 32 11 08/08 SOIL SURFACE EROSION CONTROL
DI VI SI ON 32 - EXTERI OR I MPROVEMENTS
32 05 33 08/17 LANDSCAPE ESTABLISHMENT
32 11 23 08/17 AGGREGATE BASE COURSES
32 12 13 05/17 BITUMINOUS TACK AND PRIME COATS
32 12 16.16 11/20 ROAD-MIX ASPHALT PAVING
32 15 00 05/17 AGGREGATE SURFACING
32 16 19 05/18 CONCRETE CURBS, GUTTERS AND SIDEWALKS
32 17 23 08/16, CHG 5: 11/18 PAVEMENT MARKINGS
32 18 16.13 08/17 PLAYGROUND PROTECTIVE SURFACING
32 31 13 11/16 CHAIN LINK FENCES AND GATES
32 31 19 11/16 DECORATIVE METAL FENCES AND GATES
32 92 19 08/17 SEEDING
32 92 23 04/06 SODDING
32 93 00 08/17 EXTERIOR PLANTS
32 96 00 08/17 TRANSPLANTING EXTERIOR PLANTS
DI VI SI ON 33 - UTI LI TI ES
33 11 00 02/18, CHG 1: 02/22 WATER UTILITY DISTRIBUTION PIPING
33 12 33.00 30 11/11 WATER METERS
33 16 00 02/18 UNDERGROUND POTABLE WATER STORAGE TANKS
33 30 00 05/18 SANITARY SEWERAGE
33 40 00 02/10 STORM DRAINAGE UTILITIES
33 71 01 05/19, CHG 1: 11/19 OVERHEAD TRANSMISSION AND DISTRIBUTION
33 71 02 02/15, CHG 1: 11/19 UNDERGROUND ELECTRICAL DISTRIBUTION
33 82 00 04/06 TELECOMMUNICATIONS OUTSIDE PLANT (OSP)
DI VI SI ON 35 - WATERWAY AND MARI NE CONSTRUCTI ON
35 45 02.00 10 05/21 SUBMERSIBLE WELL PUMPS AND CONTROLS
-- End of Project Table of Contents --
PROJECT TABLE OF CONTENTS Page 5
PROJECT ATTACHMENTS TABLE OF CONTENTS Page 1
PROJECT ATTACHMENTS TABLE OF CONTENTS
DIVISION 01 – GENERAL REQUIREMENTS
01 45 35 11/20 SPECIAL INSPECTIONS ATTACHEMNT 1-STATEMENT
OF SPECIAL INSPECTIONS
01 45 35 11/20 SPECIAL INSPECTIONS ATTACHMENT 2-SCHEDULE
OF SPECIAL INSPECTIONS
01 91 00 05/19 TOTAL BUILDING COMMISSIONING-COMMISSIONING
PLAN
08 71 00 02/16 DOOR HARDWARE-HARDWARE SETS
SECTION 25 05 11.01
CYBERSECURITY FOR BUILDING MANAGEMENT SYSTEMS (BMS)
05/21
PART 1 GENERAL
Many subparts in this Section contain text in curly braces ("{" and "}") indicating which cybersecurity control and control correlation identifier (CCI) the requirements of the subpart relate to. The text inside these curly braces is for Government reference only and enables coordination of the requirements of this Section with the RMF process throughout the design and construction process. Text in curly braces are not contractor requirements.
This Section refers to Security Requirements Guide (SRGs) and Security Technical Implementation Guide (STIGs). STIGs and SRGs are available online at the Information Assurance Support Environment (IASE) website at https://public.cyber.mil/stigs/downloads/ and an SRG/STIG Applicability Guide and Collection Tool is available at https://public.cyber.mil/stigs/SCAP/ . Not all control system components have applicable STIGs or SRGs. The "Control Systems SRG" does not apply to work performed under this Section; all requirements within this section to apply applicable SRGs DO NOT include the "Control Systems SRG".
1.1 CONTROL SYSTEM APPLICABILITY
There are multiple versions of this Section associated with this project.
Different versions have requirements applicable to different control systems. This specific Section applies only to the following control systems: BMS.
1.2 RELATED REQUIREMENTS
This section does not contain sufficient requirements to procure a control system and must be used in conjunction with other Sections which specify control systems. This Section adds cybersecurity requirements to the control systems specified in other Sections, and as these requirements are conditioned on the control system being provided, there may be requirements in this Section that will not apply to this project. All Sections containing facility-related control systems or control system components are related to the requirements of this Section. Review all specification sections to determine related requirements.
In cases where a requirement is specified in both this Section and in another Section, the more stringent requirement must be met. In cases where a requirement in this Section conflicts with the requirements of another Section such that both requirements cannot be met at the same time, request direction from the Contracting Officer Representative to determine which requirement applies to the project.
SECTION 25 05 11.01 Page 1
1.3 REFERENCES
The publications listed below form a part of this specification to the extent referenced. The publications are referred to within the text by the basic designation only.
INSTITUTE OF ELECTRICAL AND ELECTRONICS ENGINEERS (IEEE)
IEEE 802.1x (2010) Local and Metropolitan Area Networks - Port Based Network Access Control
INTERNET ENGINEERING TASK FORCE (IETF)
IETF RFC 2819 (2000) Remote Network Monitoring (RMON) Management Information Base (MIB)
NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST)
NIST FIPS 140-2 (2001) Security Requirements for Cryptographic Modules
NIST FIPS 201-2 (2013) Personal Identity Verification (PIV) of Federal Employees and Contractors
U.S. DEPARTMENT OF DEFENSE (DOD)
DODI 8551.01 (2014) Ports, Protocols, and Services Management (PPSM)
DTM 08-060 (2008) Policy on Use of Department of Defense (DoD) Information Systems - Standard Consent Banner and User Agreement
1.4 DEFINITIONS
1.4.1 Administrator Account
An administrator account is an account with full permissions to a device, application, or operating system, including the ability to create and modify other user accounts.
Note that the operating system Administrator Account may be different than Administrator Accounts for applications hosted on that operating system.
Also, most controllers will not have any support for accounts and will therefore not have an 'Aministrator Account'.
1.4.2 Computer
A computer is one of the following:
a. a device running a non-embedded desktop or server version of Microsoft Windows
b. a device running a non-embedded version of MacOS
SECTION 25 05 11.01 Page 2
c. a device running a non-embedded version of Linux
d. a device running a version or derivative of the Android Operating System, where Android is considered separate from Linux
e. a device running a version of Apple iOS
Unless otherwise indicated or clear from context use of the word "device" in this Section includes computers.
1.4.3 Controller
A device other than a computer or Ethernet switch.
1.4.4 Mission Space
A device or media is in mission space if physical access to the device or media is controlled by the organization served by the device. For example, a VAV box controller in a suspended ceiling is in mission space if the VAV box serves that room; an electrical switchgear in an electrical room or an AHU in a mechanical room or on a rooftop may still be considered to be in mission space if the organization (mission) served by that switchgear or AHU controls access to the electrical room, mechanical room or rooftop.
1.4.5 Network
A network is a group of two or more devices that can communicate using a network protocol. Network protocols must provide a method for addressing devices on the network; a communication method that does not provide an addressing scheme is not a networked form of communication. Devices that communicate using a method of communication that does not support device addressing are not using a network.
1.4.6 Network Connected
A component is network connected (or "connected to a network") only when the device has a network transceiver which is directly connected to the network and implements the network protocol. A device lacking a network transceiver (and accompanying protocol implementation) can never be considered network connected. Note that (unlike many IT definitions of "Network Connected") a device connected to a non-IP network is still considered network connected (an IP connection or IP address is not required for a device to be network connected).
1.4.6.1 Wireless Network Connected
Any device that supports wireless network communication is network connected to a wireless network, regardless of whether the device is communicating using wireless. Unless physically disabled, devices with wireless transceivers support wireless, it is not sufficient to disable the wireless in software.
1.4.7 Network Media
The thing that provides the communication channel between the devices on a network. Typically wire, but might include wireless, fiber optic, or
SECTION 25 05 11.01 Page 3 even power line (some network protocols allow sending network signals over power wiring).
1.4.8 User Account Support Levels
The support for user accounts is categorized in this Section as one of three levels:
1.4.8.1 FULLY Supported
Device supports configurable individual accounts. Accounts can be created, deleted, modified, etc. Privileges can be assigned to accounts.
These devices support user-based (as opposed to role-based) authentication.
1.4.8.2 MINIMALLY Supported
Device supports a small, fixed number of accounts (perhaps only one).
Accounts cannot be modified. A device with only a "User" and an "Administrator" account would fit this category. Similarly, a device with two PINs for logon - one for restricted and one for unrestricted rights would fit here (in other words, the accounts do not have to be the traditional "username and password" structure). These devices typically only support role-based authentication.
Examples of devices which MINIMALLY support accounts are a) a variable frequency drive with a single account which requires a PIN for access to configuration; and b) a room lighting control touchpad interface that has a single account.
1.4.8.3 NOT Supported
Device does not support any Access Enforcement therefore the whole concept of "account" is meaningless.
1.4.9 Manual Local Input
Manual Local Inputs are system analog or binary inputs that are adjustable by a person but are, by intrinsic hardware design, very limited in potential capabilities. Manual Local Inputs do not have touch screens or full keyboards, but may have a few buttons or dials to allow input.
Manual Local Inputs do not have full graphic screens or dot-matrix displays, but may have simple lights (LEDs) or 7-segment displays. Manual Local Inputs do not have any sort of menu structure, each button has a single well-defined function.
Examples of Manual Local Inputs are H-O-A switches, simple thermostats, and disconnect switches.
1.4.10 Card Reader
A card reader is an input/output device whose primary function is to assist in two-factor authentication. A card reader must have an interface to read data from a card and may be able to write data to a card. A card reader may have a means (such as buttons, keypad, touchscreen, etc.) for a user to input a PIN or password, as well as a limited display.
1.4.11 User Interface
A User Interface (UI) is something other than a Manual Local Input or Card
SECTION 25 05 11.01 Page 4
Reader that allows a person to interact with the system or device. Note that while a Card Reader is not by itself a User Interface, a User Interface may contain a Card Reader in order for it to authenticate its user. Within control systems, there are a wide range of User Interfaces.
Two important distinctions are 1) whether the user interface is Local or Remote, and 2) the effective capabilities of the User Interface to alter data, which is the "privilege" of the user interface (where effective privilege available to a specific user at a specific user interface is the combination of the greatest privilege offered by the user interface and the specific account the user is logged into).
1.4.11.1 Local User Interface
A Local User Interface is a user interface where the physical hardware the user interacts with (keyboard, buttons, display, etc.) is physically part of the device being affected. All of the relevant characteristics of the user interface are embodied within a single device.
Note that a Local UI may be able to access data in a different device, Local versus Remote in this context refers to the user interface itself;
the capability to access data in a different device is covered under "Full User Interface".
1.4.11.2 Remote User Interface
A Remote User Interface implements a Client/Server model where the physical hardware the user interacts with (Client) is physically distinct from the device being affected (Server). Most or all of the security and functionality characteristics of the user interface are defined by the Server, not the Client. The Client and Server communicate via a network connection. A common example of a remote user interface is a web-based interface where the browser (client) is generally on different hardware than the web server (server). A Remote UI remains a Remote UI even if the user happens to be at a Client on the same hardware as the Server. What is important is that a) the Client may be on different hardware than the Server and b) the majority of the security and functional characteristics of the interface are defined at the Server.
Note that this definition of "remote" is consistent with that generally used in the control industry but is not aligned with the NIST 800-53 definition of "Remote", which refers to "outside the system". The term "Remote" here better aligns with the NIST 800-53 definition of "Network" (remote from within the system) Access.
1.4.11.3 Types of User Interface (by capability)
User interfaces are also categorized by their capabilities as being Read Only, Limited, or Full.
1.4.11.3.1 Read-Only User Interface
A Read Only User Interface (also referred to as a View-Only User Interface) is a user interface that only allows for reading data, it does not allow (have the capability to) modify data. A Read Only User Interface may be either Local or Remote. A User Interface that is configured to be Read Only (by some other means than the interface itself, such as using configuration software on a laptop) is a Read-Only
SECTION 25 05 11.01 Page 5
Interface. Note a Read Only User Interface may have buttons (or touch screen, etc.) allowing the user to navigate through the presentation of data.
Examples of a Read Only User Interfaces are a) a publicly viewable "energy dashboard" showing weather data and energy usage within a building and b) digital wayfinding signage.
1.4.11.3.2 Limited User Interface
A Limited User Interface is a user interface that - by design - can only alter information local to the user interface. Note that the determination of "alter" includes only direct interactions, it explicitly excludes interactions that might occur as secondary effects. For example, an interface changing the flow setpoint in a pump controller is a direct interaction, the subsequent change in flow (as well as any subsequent downstream changes in valve position) are not direct interactions.
Two examples of LIMITED UIs are: a) a variable speed drive has a Limited Local User Interface which allows the user to change properties within the drive, but does not allow affecting things outside the drive; and b) a typical home WiFi Router has a Limited Remote User Interface which allows configuration of the Router, but does not allow direct interaction with other devices.
1.4.11.3.3 Full User Interface
A Full User Interface can alter information in devices outside the device with the user interface. For example, a typical Local Display Panel is a Full Local User Interface while a browser-based front end is a Full Remote User Interface.
1.4.11.3.4 View-Only User Interface
See Read-Only User Interface
1.4.11.4 Other User Interface Terminology
In addition to defining whether a user interface is a Hardware Limited, Read-Only, Limited or Full, and whether it is Local or Remote, user interfaces are classified by whether they are writable or privileged.
1.4.11.4.1 Writable User Interface
Any User Interface that is not Read-Only is Writable. (Limited User Interfaces and Full User Interfaces are both writable user interfaces (as they are capable of changing a value)).
1.4.11.4.2 Privileged User Interface
A Privileged UI is a UI that has sufficient capabilities or functionality that it requires specific cybersecurity measures to be put in place to limit its unauthorized use. Ultimately, whether a specific user interface is considered a Privileged User Interface must be determined by usage.
Unless otherwise specified, user interfaces can be determined to be privileged or not using the following:
a. Read-Only User Interfaces are not privileged user interfaces.
SECTION 25 05 11.01 Page 6
b. Full User Interfaces are privileged user interfaces.
c. User interfaces that allow for configuration of auditing or allows for modification or deletion of audit logs are privileged user interface.
d. User interfaces that allow for reprogramming a network connected device is a privileged user interface.
e. Except as specified above, a Limited User Interface must be determined to be privileged or not based on the specific capabilities and use case of the user interface. In general however, user interfaces that do not offer significant capabilities above and beyond those available at that location via other means (e.g. such as a disconnect switch, breaker, or hand-off-auto switch, or physical attack) are not privileged.
1.4.12 Wireless Network
Any network that communicates without using wires or fiber optics as the communication media. Wireless networks include: WiFi, Bluetooth, ZigBee, cellular, satellite, 900 MHz radio, 2.4 GHz, free space optical, point-to-point laser, and IR.
1.4.13 Wired Broadcast Network
Wired Broadcast Networks are any network, such as powerline carrier networks and modem (wired telephony), that use wire-based technologies where there is not a clearly defined boundary for signal propagation.
1.5 ADMINISTRATIVE REQUIREMENTS
1.5.1 Points of Contact
Coordinate with the following Points of Contact as indicated in this Section and as required. Not all projects will require coordination with all Points of Contact. When coordination is required and no Point of Contact is indicated, coordinate with The Contracting Office Representative (COR).
a. Government Computer Access Point of Contact: The Contracting Office Representative (COR)
b. HTTPS Certificate Point of Contact: The Contracting Office Representative (COR)
c. Email Address Point of Contact: The Contracting Office Representative
(COR)
d. Password Point of Contact: The Contracting Office Representative (COR)
e. Mobile Code Point of Contact: The Contracting Office Representative
(COR)
f. PKI Infrastructure Point of Contact: The Contracting Office Representative (COR)
SECTION 25 05 11.01 Page 7
1.5.2 Coordination
Coordinate the execution of this Section with the execution of all other Sections related to control systems as indicated in the paragraph RELATED REQUIREMENTS. Items that must be considered when coordinating project efforts include but are not limited to:
a. If requesting permission for wireless or wired broadcast communication, the Wireless and Wired Broadcast Communication Request submittal must be approved prior to control system device selection and installation.
b. If requesting permission for alternate account lock permissions, the Device Account Lock Exception Request must be approved prior to control system device selection and installation.
c. If requesting permission for the use of a device with multiple physical connections to IP networks, the Multiple IP Connection Device Request must be approved prior to control system device selection and installation.
d. Wireless testing may be required as part of the control system testing. See requirements for the Wireless Communication Test Report submittal.
e. If the Device Audit Record Upload Software is to be installed on a computer not being provided as part of the control system, coordination is required to identify the computer on which to install the software.
f. The Cybersecurity Interconnection Schedule must be coordinated with other work that will be interconnected to, and interconnections must be approved by the Government before relying on them for system functionality.
g. Cybersecurity testing support must be coordinated across control systems and with the Government cybersecurity testing schedule.
h. Passwords must be coordinated with the indicated contact for the project site.
i. If applicable, HTTPS web server certificates must be obtained from the indicated HTTPS Certificate Point of Contact.
j. Contractor Computer Cybersecurity Compliance Statements must be provided for each contractor using contractor owned computers.
1.6 SUBMITTALS
Government approval is required for submittals with a "G" or "S" classification. Submittals not having a "G" or "S" classification are for Contractor Quality Control approval. Submit the following in accordance with Section 01 33 00 SUBMITTAL PROCEDURES:
SD-01 Preconstruction Submittals Wireless and Wired Broadcast Communication Request ; GDevice Account Lock Exception Request ; G
SECTION 25 05 11.01 Page 8
Multiple Ethernet Connection Device Request ; G
Contractor Computer Cybersecurity Compliance Statements ; G
Contractor Temporary Network Cybersecurity Compliance Statements ; G
Cybersecurity Interconnection Schedule ; G
Proposed STIG and SRG Applicability Report ; G
SD-02 Shop Drawings
Network Communication Report ; G
Cybersecurity Riser Diagram ; G
SD-03 Product Data
Control System Cybersecurity Documentation ; G
SD-06 Test Reports
Wireless Communication Test Report ; G
Control System Cybersecurity Testing Procedures ; G
Control System Cybersecurity Testing Report ; G
SD-07 Certificates
Software Licenses ; G
SD-11 Closeout Submittals
Confidential Password Report ; G
Password Change Summary Report ; G
Enclosure Keys ; G
Software and Configuration Backups ; G
Auditing Front End Software ; G
Device Audit Record Upload Software ; G
System Maintenance Tool Software ; G
Control System Scanning Tools ; G
STIG, SRG and Vendor Guide Compliance Result Report ; G
Control System Inventory Report ; G
SECTION 25 05 11.01 Page 9
1.7 CYBERSECURITY DOCUMENTATION
{For Government Reference Only: This subpart (and its subparts) relates to PL-7; CCI-003071}
1.7.1 Proposed STIG and SRG Applicability Report
For each model of network connected or network infrastructure device, use the DISA SRG/STIG Applicability Guide and Collection Tool (available at https://public.cyber.mil/stigs/SCAP/ to identify applicable STIGs or SRGs and provide a report indicating applicable STIGs and SRGs for each model.
1.7.2 Cybersecurity Interconnection Schedule
Provide a completed Cybersecurity Interconnection Schedule documenting network connections between the installed system and other systems.
Provide the following information for each device directly communicating between systems: Device Identifier, Device Description, Transport layer Protocol, Network Address, Port (if applicable), MAC (Layer 2) address (if applicable), Media, Application Protocol, Service (if applicable), Descriptive Purpose of communication. For communication with other authorized systems also provide the Foreign Destination and POC for Destination. If other control system Sections used on this project include submittals documenting this information, provide copies of those submittals to meet this requirement.
In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Cybersecurity Interconnection Schedule as an editable Microsoft Excel file (a template Cybersecurity Interconnection Schedule in Excel format is available at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11
1.7.3 Network Communication Report
{For Government Reference Only: This subpart (and its subparts) relates to CA-9, PL-8; CCI-003075; CCI-002102, CCI-002103, CCI-002104, CCI-002105, CCI-003072, CCI-003073, CCI-003075 and also the submittal requirements associated with CM-6, CM-7, SC-8 and SC-41 including CM-7(3), CCI-000388. }
Provide a network communication report. For each networked device, document the communication characteristics of the device including communication protocols, services used, encryption employed, and a general description of what information is communicated over the network. For each device using IP, document all TCP and UDP ports used. For non-IP communications, document communication protocol and media used. If other control system Sections used on this project include submittals documenting this information, provide copies of those submittals to meet this requirement.
In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Network Communication Report as an editable Microsoft Excel file.
1.7.4 Control System Inventory Report
{For Government Reference Only: This subpart (and its subparts) relates
SECTION 25 05 11.01 Page 10 to CM-8(a), SI-17, IA-3; CCI-000389, CCI-000392, CCI-000398, CCI-002773, CCI-002774, CCI-002775, CCI-000777, CCI-000778, CCI-001958}
Provide a Control System Inventory report using the Inventory Spreadsheet listed under this Section at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11 documenting all networked devices, including network infrastructure devices. For each device provide all applicable information for which there is a field on the spreadsheet in accordance with the instructions on the spreadsheet.
In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Control System Inventory Report as an editable Microsoft Excel file.
1.7.5 Software and Configuration Backups
{For Government Reference Only: This subpart (and its subparts) relates to CP-10; CCI-000550, CCI-000551, CCI-000552}
For each computer on which software is installed under this project, provide a recovery image of the final as-built computer. This image must allow for bare-metal restore such that restoration of the image is sufficient to restore system operation to the imaged state without the need for re-installation of software. If additional user permissions are required to meet this requirement, coordinate the creation of the image with the identified Government Computer Access Point of Contact.
For all ethernet switches provide a backup of the switch configuration.
For all controllers, provide a backup of the controller configuration and the source code for all loaded application programs (all software that is not common to every controller of the same manufacturer and model).
If any or all of these are provided under another Section, provide documentation indicating this and referencing those submittals.
1.7.6 Cybersecurity Riser Diagram
{For Government Reference Only: This subpart (and its subparts) relates to PL-2(a), PL-8; CCI-003051, CCI-003053, CCI-003072, CCI-003073, CCI-003075}
Provide a cybersecurity riser diagram of the complete control system including all network and device hardware. If the control system specifications require a riser diagram submittal, provide a copy of that submittal as the cybersecurity riser diagram. Otherwise, provide a riser diagram in one-line format overlayed on a facility schematic.
1.7.7 STIG, SRG and Vendor Guide Compliance Result Report
For every component (device or software) with an applicable STIG or SRG in the Proposed STIG and SRG Applicability Report, provide a result report documenting compliance with the STIG or SRG requirements. For components which are scannable by the SCAP (security content automation protocol) tool (available online at https://public.cyber.mil/stigs/scap ), provide the SCAP report and raw scan results.
For every component (device or software) with manufacturer provided
SECTION 25 05 11.01 Page 11 cybersecurity documentation, procedure, or method for secure configuration or installation, provide a report documenting how the component was configured and any deviation from the manufacturer instructions.
1.7.8 Control System Cybersecurity Documentation
{For Government Reference Only: This subpart (and its subparts) relates to SA-5 (a),(b),(c); CCIs: CCI-003124, CCI-003125, CCI-003126, CCI-003127, CCI-003128, CCI-003129, CCI-003130, CCI-003131}
Provide a Control System Cybersecurity Documentation submittal containing the indicated information for each device and software application.
1.7.8.1 Software Applications
For all software applications running on computers provide:
a. administrator documentation that describes secure configuration of the software {For Government Reference Only: relates to CCI-003124}
b. administrator documentation that describes secure installation of the software {For Government Reference Only: relates to CCI-003125}
c. administrator documentation that describes secure operation of the software {For Government Reference Only: relates to CCI-003124}
d. administrator documentation that describes effective use and maintenance of security functions or mechanisms for the software {For Government Reference Only: relates to CCI-003127}
e. administrator documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the software {For Government Reference Only: relates to
CCI-003128}
f. user documentation that describes user-accessible security functions or mechanisms in the software and how to effectively use those security functions or mechanisms {For Government Reference Only:
relates to CCI-003129}
g. user documentation that describes methods for user interaction which enables individuals to use the software in a more secure manner {For Government Reference Only: relates to CCI-003130}
h. user documentation that describes user responsibilities in maintaining the security of the software {For Government Reference Only: relates to CCI-003131}
1.7.8.2 For HVAC Control System Devices
1.7.8.2.1 HVAC Control System Devices FULLY Supporting User Accounts
For all HVAC Control System Devices which FULLY support user accounts, provide:
a. Documentation that describes secure configuration of the device {For Government Reference Only: relates to CCI-003124}
SECTION 25 05 11.01 Page 12
b. Documentation that describes secure operation of the device {For Government Reference Only: relates to CCI-003124}
c. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {For Government Reference Only:
relates to CCI-003127}
d. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {For Government Reference Only: relates to CCI-003128}
e. Documentation that describes user-accessible security functions or mechanisms in the device and how to effectively use those security functions or mechanisms; or a specific indication that there are no user-accessible security functions or mechanisms in the device {For Government Reference Only: relates to CCI-003129}
f. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {For Government Reference Only: relates to CCI-003130}
1.7.8.2.2 All Other HVAC Control System Devices
For all HVAC Control System Devices which do not FULLY support user accounts, provide:
a. Documentation that describes secure configuration of the device; or a specific indication that there are no secure configuration steps that apply {For Government Reference Only: relates to CCI-003124}
b. Documentation that describes effective use and maintenance of security functions or mechanisms for the device; or a specific indication that there are no security functions or mechanisms in the device {For Government Reference Only: relates to CCI-003127}
c. For devices which include a user interface, documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {For Government Reference Only:
relates to CCI-003130}
1.7.8.3 Default Requirements for Control System Devices
For control system devices where Control System Cybersecurity Documentation requirements are not otherwise indicated in this Section, provide:
a. Documentation that describes secure configuration of the device {For Government Reference Only: relates to CCI-003124}
b. Documentation that describes secure installation of the device {For Government Reference Only: relates to CCI-003125}
c. Documentation that describes secure operation of the device {For Government Reference Only: relates to CCI-003124}
d. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {For Government Reference Only:
relates to CCI-003127}
SECTION 25 05 11.01 Page 13
e. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {For Government Reference Only: relates to CCI-003128}
f. Documentation that describes user-accessible security functions or mechanisms in the device and how to effectively use those security functions or mechanisms {For Government Reference Only: relates to
CCI-003129}
g. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {For Government Reference Only: relates to CCI-003130}
h. Documentation that describes user responsibilities in maintaining the security of the device {For Government Reference Only: relates to
CCI-003131}
1.8 SOFTWARE LICENSING
{For Government Reference Only: This subpart (and its subparts) relates to SI-2(a), SI-2(c), SI-7(14); CCI-001227, CCI-002605, CCI-002737}
For all software provided that has not already been licensed to the government or project site, provide a license to the Government for a period of no less than 5 years, and the license must also include the following software updates:
a. Security and bug-fix patches issued by the software manufacturer.
b. Security patches to address any vulnerability identified in the National Vulnerability Database at http://nvd.nist.gov with a Common Vulnerability Scoring System (CVSS) severity rating of MEDIUM or higher.
Provide a single Software Licenses submittal with documentation of the software licenses for all software provided
1.9 CYBERSECURITY DURING CONSTRUCTION
{For Government Reference Only: This subpart (and its subparts) relates to
AC-18, SA-3; CCI-000258}
In addition to the control system cybersecurity requirements indicated in this section, meet following requirement throughout the construction process.
1.9.1 Contractor Computer Equipment
Contractor owned computers may be used for construction. Contractor computers connected to the control system, control system network, or a control system component at any point during construction must meet the following requirements:
1.9.1.1 Operating System
The operating system must be an operating system currently supported by the manufacturer of the operating system. The operating system must be
SECTION 25 05 11.01 Page 14 current on security patches and operating system manufacturer required updates.
1.9.1.2 Anti-Malware Software
The computer must run anti-malware software from a reputable software manufacturer. Anti-malware software must be a version currently supported by the software manufacturer, must be current on all patches and updates, and must use the latest definitions file. Computers used on this project must be scanned using the installed software at least once per day.
1.9.1.3 Passwords and Passphrases
The passwords and passphrases for computers, applications, and web-based applications supporting passwords must be changed from their default values. Passwords must be a minimum of eight characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.
1.9.1.4 User-Based Authentication
Each user must have a unique account; sharing of a single account between multiple users is prohibited.
1.9.1.5 Demonstration of Compliance
The Government has the right to require demonstration of computer compliance with these requirements at any time during the project.
1.9.1.6 Contractor Computer Cybersecurity Compliance Statements
Provide a single submittal containing completed Contractor Computer Cybersecurity Compliance Statements for each company using contractor owned computers. Contractor Computer Cybersecurity Compliance Statements must use the template published at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11 Each Statement must be signed by a cybersecurity representative for the relevant company.
1.9.2 Temporary IP Networks
Temporary contractor-installed IP networks may be used during construction. When used, temporary contractor-installed IP networks connected to the control system, control system network, or a control system component at any point during construction must meet the following requirements:
1.9.2.1 Network Boundaries and Connections
The network must not extend outside the project site and must not connect to any IP network other than those specifically provided or furnished for this project. Any and all access to the network from outside the project site is prohibited.
1.9.3 Government Access to Network
Government personnel must be allowed to have complete and immediate access to the network at any time in order to verify compliance with this
SECTION 25 05 11.01 Page 15 specification.
1.9.4 Temporary Wireless IP Networks
In addition to the other requirements on temporary IP networks, temporary wireless IP (WiFi) networks, when permitted, must not interfere with existing wireless networks, must use WPA2 security and must not broadcast the network name (SSID). Network names (SSID) for wireless networks must be changed from their default values.
1.9.5 Passwords and Passphrases
The passwords and passphrases for all network devices and network access must be changed from their default values. Passwords must be a minimum 8 characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.
1.9.6 Contractor Temporary Network Cybersecurity Compliance Statements
Provide a single submittal containing completed Contractor Temporary Network Cybersecurity Compliance Statements for each company implementing a temporary IP network. Contractor Temporary Network Cybersecurity Compliance Statements must use the template published at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11 Each Statement must be signed by a cybersecurity representative for the relevant company. If no temporary IP networks will be used, provide a single copy of the Statement indicating this.
1.10 CYBERSECURITY DURING WARRANTY PERIOD
All work performed on the control system after acceptance must be performed using Government Furnished Equipment or equipment specifically and individually approved by the Government.
PART 2 PRODUCTS
All products used on this project must meet the indicated requirements, but not all products specified here will be required by every project.
2.1 ETHERNET SWITCH
Provide Open Systems Interconnection (OSI) Layer 2 Ethernet switches with the following capabilities, and with an interface to support switch configuration for these capabilities:
2.1.1 Required Functionality
Switches must:
a. Copper Ethernet ports must auto negotiate for 10, 100 and 1000 megabits-per-second links.
b. Be capable of implementing port level access control by MAC address and limit the number of MAC addresses to one MAC address per port.
d. Support Remote Network Monitoring (RMON) Port Analysis in accordance with IETF RFC 2819
SECTION 25 05 11.01 Page 16
e. Configure target port and analysis port such that switch clones all target port traffic to analysis port.
f. Support authentication via RADIUS server (for management and 802.1x)
g. Support IEEE 802.1x network login.
2.1.2 Configuration Requirements
Switches must:
a. Support configuration save and restore.
b. Support both manual IP address assignment and acquisition of a dynamic IP address via Dynamic Host Configuration Protocol (DHCP).
c. Be capable of limiting access for configuration to one or more of: a web interface using HTTPS, a command line interface using SSH, or an SNMP connection using SNMP version 3 or later.
d. Support the ability to lock configuration capability to a dedicated management port.
2.2 DAISY CHAIN IP CONTROLLERS
Controllers used as Daisy Chain IP Controllers must be IP controllers with exactly two Ethernet network connections and basic built-in switch capabilities to allow implementation of an Ethernet network in a daisy chain architecture. Switches incorporated by Daisy Chain IP Controllers are not required to meet the requirements for Ethernet Switches as defined in this Section.
PART 3 EXECUTION
3.1 CYBERSECURITY HARDENING AND CONFIGURATION GUIDES
Install, configure, and harden all hardware and software furnished on this project in accordance with manufacturer provided documentation, procedures, or methods for secure configuration or installation. Do not implement specific hardening actions if that action would conflict with requireed functionality or another requirement of this Section.
3.2 NETWORK REQUIREMENTS
3.2.1 Wireless and Wired Broadcast Communication
{For Government Reference Only: This subpart (and its subparts) relates to AC-18, AC-18(3); CCI-001438, CCI-001439, CCI-002323, CCI-001441, CCI-002252}
Unless explicitly authorized by the Government, do not use any wireless or wired broadcast communication. If requesting authorization for wireless or wired broadcast communication, wired broadcast media such as powerline carrier is preferred to wireless.
SECTION 25 05 11.01 Page 17
3.2.1.1 Wireless and Wired Broadcast IP Communications
Do not install wireless or wired broadcast IP networks, including: do not install a wireless access point; do not install or configure an ad-hoc wireless network; do not install or configure a WiFi Direct communication.
When explicitly authorized by the Government, wireless IP communication may be used to communicate with an existing wireless network.
3.2.1.2 Non-IP Wireless Communication
For LOW Impact Systems: When non-IP wireless communication is explicitly authorized by the Government, use the maximum level of encryption supported by the specific protocol employed and select signal strength and radiated power to the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .