RAMEY Specs V3 25-32.pdf

PDF 2 MB Posted

Attached to
Ramey Unit School Replacement Federal contract opportunity
Solicitation number
Not on record
Issued by
Department of the Army Corps of Engineers Engineering District Savannah

View the file

Other files for this federal contract opportunity

Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AGUADILLA,

PUERTO RICO

Solicitation Number

W912HN-22-R-3001

Ramey Unit School Replacement Volume 3 of 5: Specifications Divisions 25 - 32

PN AM00049

May 2022

U.S. ARMY ENGINEER DISTRICT, SAVANNAH

CORPS OF ENGINEERS

100 WEST OGLETHORPE AVENUE

SAVANNAH, GEORGIA 31401-3640

US Army Corps Of Engineers Savannah District

RAMEY UNIT SCHOOL REPLACEMENT 22R3001

AGUADILLA, PUERTO RICO

PROJECT TABLE OF CONTENTS

DI VI SI ON 01 - GENERAL REQUI REMENTS

01 11 00 08/15, CHG 2: 08/21 SUMMARY OF WORK

01 14 00 11/11, CHG 14: 02/22 WORK RESTRICTIONS

01 23 00 03/14 BID OPTIONS

01 30 00 09/21 ADMINISTRATIVE PROCEDURES

01 32 01 01/22 PROJECT SCHEDULE

01 33 00 02/22 SUBMITTAL PROCEDURES

01 33 29 02/15 SUSTAINABILITY REPORTING

01 33 29.37 07/14 LEED(TM) DOCUMENTATION

01 35 26 12/21 GOVERNMENTAL SAFETY REQUIREMENTS

01 42 00 11/14 SOURCES FOR REFERENCE PUBLICATIONS

01 45 00 03/20 RESIDENT MANAGEMENT SYSTEM CONTRACTOR

MODE (RMS CM)

01 45 00.00 10 11/16 QUALITY CONTROL

01 45 04 02/22 CONTRACTOR QUALITY CONTROL

01 45 35 11/20 SPECIAL INSPECTIONS

01 50 02 02/22 TEMPORARY CONSTRUCTION FACILITIES

01 52 10 02/22 CONTRACTING OFFICER'S FIELD OFFICE

01 55 26 01/22 TRAFFIC CONTROL

01 57 19 11/15, CHG 5: 08/21 TEMPORARY ENVIRONMENTAL CONTROLS

01 57 20 ENVIRONMENTAL PROTECTION

01 74 19 02/19, CHG 3: 11/21 CONSTRUCTION WASTE MANAGEMENT AND

DISPOSAL

01 78 00 05/19, CHG 1: 08/21 CLOSEOUT SUBMITTALS

01 78 23 08/15, CHG 2: 08/21 OPERATION AND MAINTENANCE DATA

01 91 00.15 10 05/19, CHG 2: 08/20 TOTAL BUILDING COMMISSIONING

DI VI SI ON 02 - EXI STI NG CONDI TI ONS

02 41 00 05/10, CHG 2: 02/19 DEMOLITION

02 42 91 11/18 REMOVAL AND SALVAGE OF HISTORIC

CONSTRUCTION MATERIALS

02 81 00 11/18 TRANSPORTATION AND DISPOSAL OF

HAZARDOUS MATERIALS

02 82 00 11/18, CHG 1: 11/19 ASBESTOS REMEDIATION

02 83 00 11/18 LEAD REMEDIATION

02 84 16 05/20 HANDLING OF LIGHTING BALLASTS AND

LAMPS CONTAINING PCBs AND MERCURY

02 84 33 05/20 REMOVAL AND DISPOSAL OF

POLYCHLORINATED BIPHENYLS (PCBs)

DI VI SI ON 03 - CONCRETE

03 30 00 02/19, CHG 2: 05/21 CAST-IN-PLACE CONCRETE

03 33 00 11/09 CAST-IN-PLACE ARCHITECTURAL CONCRETE

03 52 00 08/11 LIGHTWEIGHT CONCRETE ROOF INSULATION

DI VI SI ON 05 - METALS

05 50 13 05/17, CHG 1: 08/18 MISCELLANEOUS METAL FABRICATIONS

05 51 00 02/17, CHG 1: 05/17 METAL STAIRS

05 51 33 02/16, CHG 2: 02/18 METAL LADDERS

05 52 00 02/18, CHG 1: 02/20 METAL RAILINGS

DI VI SI ON 06 - WOOD, PLASTI CS, AND COMPOSI TES

PROJECT TABLE OF CONTENTS Page 1

06 10 00 08/16, CHG 2: 11/18 ROUGH CARPENTRY

06 41 16.00 10 08/10, CHG 1: 11/18 SOLID PHENOLIC ARCHITECTURAL CABINETS

06 61 16 08/20 SOLID SURFACING FABRICATIONS

DI VI SI ON 07 - THERMAL AND MOI STURE PROTECTI ON

07 05 23 08/19 PRESSURE TESTING AN AIR BARRIER SYSTEM

FOR AIR TIGHTNESS

07 17 00 02/16 BENTONITE WATERPROOFING

07 21 16 11/11, CHG 4: 08/18 MINERAL FIBER BLANKET INSULATION

07 27 10.00 10 08/19, CHG 1: 02/20 BUILDING AIR BARRIER SYSTEM

07 52 00 05/12, CHG 5: 11/19 MODIFIED BITUMINOUS MEMBRANE ROOFING

07 60 00 05/17, CHG 2: 11/18 FLASHING AND SHEET METAL

07 84 00 05/10, CHG 1: 08/13 FIRESTOPPING

07 92 00 08/16, CHG 3: 11/18 JOINT SEALANTS

DI VI SI ON 08 - OPENI NGS

08 11 13 08/20 STEEL DOORS AND FRAMES

08 14 00 08/16, CHG 1: 08/18 WOOD DOORS

08 33 13 05/09, CHG 2: 11/12 COILING COUNTER DOORS

08 33 23 08/20, CHG 1: 02/22 OVERHEAD COILING DOORS

08 34 73 11/19, CHG 1: 02/21 SOUND CONTROL DOOR ASSEMBLIES

08 39 54 08/09 BLAST RESISTANT DOORS

08 41 13 08/18, CHG 1: 08/18 ALUMINUM-FRAMED ENTRANCES AND

STOREFRONTS

08 44 00 05/19 CURTAIN WALL AND GLAZED ASSEMBLIES

08 71 00 02/16, CHG 4: 02/22 DOOR HARDWARE

08 81 00 05/19 GLAZING

08 91 00 08/20 METAL WALL LOUVERS

DI VI SI ON 09 - FI NI SHES

09 06 00 05/09, CHG 1: 11/13 SCHEDULES FOR FINISHES

09 22 00 02/10, CHG 2: 08/18 SUPPORTS FOR PLASTER AND GYPSUM BOARD

09 29 00 08/16, CHG 4: 02/20 GYPSUM BOARD

09 30 10 08/20 TILING

09 51 00 08/20 ACOUSTICAL CEILINGS

09 65 00 08/10, CHG 3: 08/18 RESILIENT FLOORING

09 65 66 08/16, CHG 1: 08/18 RESILIENT ATHLETIC FLOORING

09 66 23 08/16, CHG 1: 08/18 RESINOUS MATRIX TERRAZZO FLOORING

09 67 23.13 11/19 STANDARD RESINOUS FLOORING

09 68 00 11/17, CHG 2: 08/20 CARPETING

09 72 00 08/17, CHG 1: 08/18 WALLCOVERINGS

09 84 20 08/16, CHG 1: 08/18 ACOUSTICAL WALL AND CEILING PANELS

09 90 00 02/21 PAINTS AND COATINGS

DI VI SI ON 10 - SPECI ALTI ES

10 11 00 08/20 VISUAL DISPLAY UNITS

10 14 00.10 08/17, CHG 1: 11/18 EXTERIOR SIGNAGE

10 14 00.20 08/20 INTERIOR SIGNAGE AND GRAPHIC BOARDS

10 21 13 08/20 TOILET COMPARTMENTS

10 21 23.16 04/06 CUBICLE TRACK AND HARDWARE

10 22 39 08/20 FOLDING PANEL PARTITIONS

10 26 00 08/20 WALL AND DOOR PROTECTION

10 28 13 08/20 TOILET ACCESSORIES

10 44 16 11/19 FIRE EXTINGUISHERS

10 51 26 PLASTIC LOCKERS

PROJECT TABLE OF CONTENTS Page 2

10 56 28 HIGH DENSITY STORAGE

10 71 36 CANOPIES

10 75 00 FLAGPOLES

DI VI SI ON 11 - EQUI PMENT

11 05 40 3/16/2022 COMMON WORK RESULTS FOR FOODSERVICE

EQUIPMENT

11 13 00 LOADING DOCK EQUIPMENT

11 31 13 08/17, CHG 1: 08/18 ELECTRIC KITCHEN EQUIPMENT

11 61 00 STAGE EQUIPMENT

11 66 00 ATHLETIC EQUIPMENT

11 68 13 08/17, CHG 1: 08/18 PLAYGROUND EQUIPMENT

11 68 43 SCOREBOARDS

11 81 29 FACILITY FALL PROTECTION

11 90 00 MISCELLANEOUS EQUIPMENT

DI VI SI ON 12 - FURNI SHI NGS

12 24 13 08/20 ROLLER WINDOW SHADES

12 61 13 08/20 UPHOLSTERED AUDIENCE SEATING

12 63 33 BLEACHERS

DI VI SI ON 13 - SPECI AL CONSTRUCTI ON

13 34 23 11/11 PRE-FABRICATED GUARD BOOTHS

13 48 73 05/20, CHG 1: 08/20 SEISMIC CONTROL FOR MECHANICAL

EQUIPMENT

DI VI SI ON 14 - CONVEYI NG EQUI PMENT

14 24 23 05/16 HYDRAULIC PASSENGER ELEVATORS

DI VI SI ON 21 - FI RE SUPPRESSI ON

21 13 13 08/20 WET PIPE SPRINKLER SYSTEMS, FIRE

PROTECTION

21 30 00 04/08, CHG 1: 08/13 FIRE PUMPS

21 30 01 PACKAGED FIRE PUMP SYSTEM ENCLOSURE

21 41 00 STEEL WATER STORAGE TANKS FOR

FIRE-SUPPRESSION WATER

DI VI SI ON 22 - PLUMBI NG

22 00 00 11/15, CHG 4: 05/21 PLUMBING, GENERAL PURPOSE

DI VI SI ON 23 - HEATI NG, VENTI LATI NG, AND AI R CONDI TI ONI NG ( HVAC)

23 05 15 02/14 COMMON PIPING FOR HVAC

23 05 48.19 05/18, CHG 2: 08/20 SEISMIC BRACING FOR HVAC

23 05 93 11/15 TESTING, ADJUSTING, AND BALANCING FOR

HVAC

23 07 00 02/13, CHG 7: 05/20 THERMAL INSULATION FOR MECHANICAL

SYSTEMS

23 09 00 02/19, CHG 3: 05/21 INSTRUMENTATION AND CONTROL FOR HVAC

23 09 13 11/15, CHG 2: 05/21 INSTRUMENTATION AND CONTROL DEVICES

FOR HVAC

23 09 23.01 02/19, CHG 1: 02/20 LONWORKS DIRECT DIGITAL CONTROL FOR

HVAC AND OTHER BUILDING CONTROL SYSTEMS

PROJECT TABLE OF CONTENTS Page 3

23 11 20 05/20 FACILITY GAS PIPING

23 23 00 10/07 REFRIGERANT PIPING

23 30 00 05/20 HVAC AIR DISTRIBUTION

23 64 10 11/16, CHG 2: 08/18 WATER CHILLERS, VAPOR COMPRESSION TYPE

23 64 26 08/09, CHG 5: 11/19 CHILLED, CHILLED-HOT, AND CONDENSER

WATER PIPING SYSTEMS

23 81 00 05/18, CHG 1: 02/21 DECENTRALIZED UNITARY HVAC EQUIPMENT

DI VI SI ON 25 - I NTEGRATED AUTOMATI ON

25 05 11.01 05/21 CYBERSECURITY FOR BUILDING MANAGEMENT

SYSTEMS (BMS)

25 05 11.02 05/21 CYBERSECURITY FOR FACILITY-RELATED

CONTROL SYSTEMS - FIRE ALARM AND MASS

NOTIFICATION SYSTEMS

25 05 11.03 05/21 CYBERSECURITY FOR LIGHTING CONTROL

SYSTEM

25 05 11.04 05/21 CYBERSECURITY FOR FACILITY-RELATED

CONTROL SYSTEMS

25 10 10 02/19, CHG 1: 05/21 UTILITY MONITORING AND CONTROL SYSTEM

(UMCS) FRONT END AND INTEGRATION

DI VI SI ON 26 - ELECTRI CAL

26 05 48.00 10 10/07 SEISMIC PROTECTION FOR ELECTRICAL

EQUIPMENT

26 08 00 08/08, CHG 1: 02/15 APPARATUS INSPECTION AND TESTING

26 12 19.10 05/19, CHG 1: 11/19 THREE-PHASE, LIQUID-FILLED PAD-MOUNTED

TRANSFORMERS

26 20 00 08/19, CHG 2: 05/21 INTERIOR DISTRIBUTION SYSTEM

26 24 13 05/15, CHG 1: 08/17 SWITCHBOARDS

26 28 01.00 10 10/07 COORDINATED POWER SYSTEM PROTECTION

26 29 23 02/20, CHG: 1 - 05/21 ADJUSTABLE SPEED DRIVE (ASD) SYSTEMS

UNDER 600 VOLTS

26 31 00 05/15 SOLAR PHOTOVOLTAIC (PV) COMPONENTS

26 32 15.00 05/20 ENGINE-GENERATOR SET STATIONARY

15-2500 KW, WITH AUXILIARIES

26 36 23 05/20 AUTOMATIC TRANSFER SWITCHES AND

BY-PASS/ISOLATION SWITCH

26 41 00 11/13 LIGHTNING PROTECTION SYSTEM

26 51 00 05/20, CHG 1: 05/21 INTERIOR LIGHTING

26 56 00 05/20 EXTERIOR LIGHTING

DI VI SI ON 27 - COMMUNI CATI ONS

27 10 00 08/11 BUILDING TELECOMMUNICATIONS CABLING

SYSTEM

27 51 23.10 05/11 INTERCOMMUNICATION SYSTEM

DI VI SI ON 28 - ELECTRONI C SAFETY AND SECURI TY

28 10 05 05/16 ELECTRONIC SECURITY SYSTEMS (ESS)

28 31 76 08/20 INTERIOR FIRE ALARM AND MASS

NOTIFICATION SYSTEM, ADDRESSABLE

DI VI SI ON 31 - EARTHWORK

31 00 00 08/08, CHG 2: 02/21 EARTHWORK

31 11 00 11/18 CLEARING AND GRUBBING

PROJECT TABLE OF CONTENTS Page 4

31 31 16.13 08/16 CHEMICAL TERMITE CONTROL

31 32 11 08/08 SOIL SURFACE EROSION CONTROL

DI VI SI ON 32 - EXTERI OR I MPROVEMENTS

32 05 33 08/17 LANDSCAPE ESTABLISHMENT

32 11 23 08/17 AGGREGATE BASE COURSES

32 12 13 05/17 BITUMINOUS TACK AND PRIME COATS

32 12 16.16 11/20 ROAD-MIX ASPHALT PAVING

32 15 00 05/17 AGGREGATE SURFACING

32 16 19 05/18 CONCRETE CURBS, GUTTERS AND SIDEWALKS

32 17 23 08/16, CHG 5: 11/18 PAVEMENT MARKINGS

32 18 16.13 08/17 PLAYGROUND PROTECTIVE SURFACING

32 31 13 11/16 CHAIN LINK FENCES AND GATES

32 31 19 11/16 DECORATIVE METAL FENCES AND GATES

32 92 19 08/17 SEEDING

32 92 23 04/06 SODDING

32 93 00 08/17 EXTERIOR PLANTS

32 96 00 08/17 TRANSPLANTING EXTERIOR PLANTS

DI VI SI ON 33 - UTI LI TI ES

33 11 00 02/18, CHG 1: 02/22 WATER UTILITY DISTRIBUTION PIPING

33 12 33.00 30 11/11 WATER METERS

33 16 00 02/18 UNDERGROUND POTABLE WATER STORAGE TANKS

33 30 00 05/18 SANITARY SEWERAGE

33 40 00 02/10 STORM DRAINAGE UTILITIES

33 71 01 05/19, CHG 1: 11/19 OVERHEAD TRANSMISSION AND DISTRIBUTION

33 71 02 02/15, CHG 1: 11/19 UNDERGROUND ELECTRICAL DISTRIBUTION

33 82 00 04/06 TELECOMMUNICATIONS OUTSIDE PLANT (OSP)

DI VI SI ON 35 - WATERWAY AND MARI NE CONSTRUCTI ON

35 45 02.00 10 05/21 SUBMERSIBLE WELL PUMPS AND CONTROLS

-- End of Project Table of Contents --

PROJECT TABLE OF CONTENTS Page 5

PROJECT ATTACHMENTS TABLE OF CONTENTS Page 1

PROJECT ATTACHMENTS TABLE OF CONTENTS

DIVISION 01 – GENERAL REQUIREMENTS

01 45 35 11/20 SPECIAL INSPECTIONS ATTACHEMNT 1-STATEMENT

OF SPECIAL INSPECTIONS

01 45 35 11/20 SPECIAL INSPECTIONS ATTACHMENT 2-SCHEDULE

OF SPECIAL INSPECTIONS

01 91 00 05/19 TOTAL BUILDING COMMISSIONING-COMMISSIONING

PLAN

08 71 00 02/16 DOOR HARDWARE-HARDWARE SETS

SECTION 25 05 11.01

CYBERSECURITY FOR BUILDING MANAGEMENT SYSTEMS (BMS)

05/21

PART 1 GENERAL

Many subparts in this Section contain text in curly braces ("{" and "}") indicating which cybersecurity control and control correlation identifier (CCI) the requirements of the subpart relate to. The text inside these curly braces is for Government reference only and enables coordination of the requirements of this Section with the RMF process throughout the design and construction process. Text in curly braces are not contractor requirements.

This Section refers to Security Requirements Guide (SRGs) and Security Technical Implementation Guide (STIGs). STIGs and SRGs are available online at the Information Assurance Support Environment (IASE) website at https://public.cyber.mil/stigs/downloads/ and an SRG/STIG Applicability Guide and Collection Tool is available at https://public.cyber.mil/stigs/SCAP/ . Not all control system components have applicable STIGs or SRGs. The "Control Systems SRG" does not apply to work performed under this Section; all requirements within this section to apply applicable SRGs DO NOT include the "Control Systems SRG".

1.1 CONTROL SYSTEM APPLICABILITY

There are multiple versions of this Section associated with this project.

Different versions have requirements applicable to different control systems. This specific Section applies only to the following control systems: BMS.

1.2 RELATED REQUIREMENTS

This section does not contain sufficient requirements to procure a control system and must be used in conjunction with other Sections which specify control systems. This Section adds cybersecurity requirements to the control systems specified in other Sections, and as these requirements are conditioned on the control system being provided, there may be requirements in this Section that will not apply to this project. All Sections containing facility-related control systems or control system components are related to the requirements of this Section. Review all specification sections to determine related requirements.

In cases where a requirement is specified in both this Section and in another Section, the more stringent requirement must be met. In cases where a requirement in this Section conflicts with the requirements of another Section such that both requirements cannot be met at the same time, request direction from the Contracting Officer Representative to determine which requirement applies to the project.

SECTION 25 05 11.01 Page 1

1.3 REFERENCES

The publications listed below form a part of this specification to the extent referenced. The publications are referred to within the text by the basic designation only.

INSTITUTE OF ELECTRICAL AND ELECTRONICS ENGINEERS (IEEE)

IEEE 802.1x (2010) Local and Metropolitan Area Networks - Port Based Network Access Control

INTERNET ENGINEERING TASK FORCE (IETF)

IETF RFC 2819 (2000) Remote Network Monitoring (RMON) Management Information Base (MIB)

NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST)

NIST FIPS 140-2 (2001) Security Requirements for Cryptographic Modules

NIST FIPS 201-2 (2013) Personal Identity Verification (PIV) of Federal Employees and Contractors

U.S. DEPARTMENT OF DEFENSE (DOD)

DODI 8551.01 (2014) Ports, Protocols, and Services Management (PPSM)

DTM 08-060 (2008) Policy on Use of Department of Defense (DoD) Information Systems - Standard Consent Banner and User Agreement

1.4 DEFINITIONS

1.4.1 Administrator Account

An administrator account is an account with full permissions to a device, application, or operating system, including the ability to create and modify other user accounts.

Note that the operating system Administrator Account may be different than Administrator Accounts for applications hosted on that operating system.

Also, most controllers will not have any support for accounts and will therefore not have an 'Aministrator Account'.

1.4.2 Computer

A computer is one of the following:

a. a device running a non-embedded desktop or server version of Microsoft Windows

b. a device running a non-embedded version of MacOS

SECTION 25 05 11.01 Page 2

c. a device running a non-embedded version of Linux

d. a device running a version or derivative of the Android Operating System, where Android is considered separate from Linux

e. a device running a version of Apple iOS

Unless otherwise indicated or clear from context use of the word "device" in this Section includes computers.

1.4.3 Controller

A device other than a computer or Ethernet switch.

1.4.4 Mission Space

A device or media is in mission space if physical access to the device or media is controlled by the organization served by the device. For example, a VAV box controller in a suspended ceiling is in mission space if the VAV box serves that room; an electrical switchgear in an electrical room or an AHU in a mechanical room or on a rooftop may still be considered to be in mission space if the organization (mission) served by that switchgear or AHU controls access to the electrical room, mechanical room or rooftop.

1.4.5 Network

A network is a group of two or more devices that can communicate using a network protocol. Network protocols must provide a method for addressing devices on the network; a communication method that does not provide an addressing scheme is not a networked form of communication. Devices that communicate using a method of communication that does not support device addressing are not using a network.

1.4.6 Network Connected

A component is network connected (or "connected to a network") only when the device has a network transceiver which is directly connected to the network and implements the network protocol. A device lacking a network transceiver (and accompanying protocol implementation) can never be considered network connected. Note that (unlike many IT definitions of "Network Connected") a device connected to a non-IP network is still considered network connected (an IP connection or IP address is not required for a device to be network connected).

1.4.6.1 Wireless Network Connected

Any device that supports wireless network communication is network connected to a wireless network, regardless of whether the device is communicating using wireless. Unless physically disabled, devices with wireless transceivers support wireless, it is not sufficient to disable the wireless in software.

1.4.7 Network Media

The thing that provides the communication channel between the devices on a network. Typically wire, but might include wireless, fiber optic, or

SECTION 25 05 11.01 Page 3 even power line (some network protocols allow sending network signals over power wiring).

1.4.8 User Account Support Levels

The support for user accounts is categorized in this Section as one of three levels:

1.4.8.1 FULLY Supported

Device supports configurable individual accounts. Accounts can be created, deleted, modified, etc. Privileges can be assigned to accounts.

These devices support user-based (as opposed to role-based) authentication.

1.4.8.2 MINIMALLY Supported

Device supports a small, fixed number of accounts (perhaps only one).

Accounts cannot be modified. A device with only a "User" and an "Administrator" account would fit this category. Similarly, a device with two PINs for logon - one for restricted and one for unrestricted rights would fit here (in other words, the accounts do not have to be the traditional "username and password" structure). These devices typically only support role-based authentication.

Examples of devices which MINIMALLY support accounts are a) a variable frequency drive with a single account which requires a PIN for access to configuration; and b) a room lighting control touchpad interface that has a single account.

1.4.8.3 NOT Supported

Device does not support any Access Enforcement therefore the whole concept of "account" is meaningless.

1.4.9 Manual Local Input

Manual Local Inputs are system analog or binary inputs that are adjustable by a person but are, by intrinsic hardware design, very limited in potential capabilities. Manual Local Inputs do not have touch screens or full keyboards, but may have a few buttons or dials to allow input.

Manual Local Inputs do not have full graphic screens or dot-matrix displays, but may have simple lights (LEDs) or 7-segment displays. Manual Local Inputs do not have any sort of menu structure, each button has a single well-defined function.

Examples of Manual Local Inputs are H-O-A switches, simple thermostats, and disconnect switches.

1.4.10 Card Reader

A card reader is an input/output device whose primary function is to assist in two-factor authentication. A card reader must have an interface to read data from a card and may be able to write data to a card. A card reader may have a means (such as buttons, keypad, touchscreen, etc.) for a user to input a PIN or password, as well as a limited display.

1.4.11 User Interface

A User Interface (UI) is something other than a Manual Local Input or Card

SECTION 25 05 11.01 Page 4

Reader that allows a person to interact with the system or device. Note that while a Card Reader is not by itself a User Interface, a User Interface may contain a Card Reader in order for it to authenticate its user. Within control systems, there are a wide range of User Interfaces.

Two important distinctions are 1) whether the user interface is Local or Remote, and 2) the effective capabilities of the User Interface to alter data, which is the "privilege" of the user interface (where effective privilege available to a specific user at a specific user interface is the combination of the greatest privilege offered by the user interface and the specific account the user is logged into).

1.4.11.1 Local User Interface

A Local User Interface is a user interface where the physical hardware the user interacts with (keyboard, buttons, display, etc.) is physically part of the device being affected. All of the relevant characteristics of the user interface are embodied within a single device.

Note that a Local UI may be able to access data in a different device, Local versus Remote in this context refers to the user interface itself;

the capability to access data in a different device is covered under "Full User Interface".

1.4.11.2 Remote User Interface

A Remote User Interface implements a Client/Server model where the physical hardware the user interacts with (Client) is physically distinct from the device being affected (Server). Most or all of the security and functionality characteristics of the user interface are defined by the Server, not the Client. The Client and Server communicate via a network connection. A common example of a remote user interface is a web-based interface where the browser (client) is generally on different hardware than the web server (server). A Remote UI remains a Remote UI even if the user happens to be at a Client on the same hardware as the Server. What is important is that a) the Client may be on different hardware than the Server and b) the majority of the security and functional characteristics of the interface are defined at the Server.

Note that this definition of "remote" is consistent with that generally used in the control industry but is not aligned with the NIST 800-53 definition of "Remote", which refers to "outside the system". The term "Remote" here better aligns with the NIST 800-53 definition of "Network" (remote from within the system) Access.

1.4.11.3 Types of User Interface (by capability)

User interfaces are also categorized by their capabilities as being Read Only, Limited, or Full.

1.4.11.3.1 Read-Only User Interface

A Read Only User Interface (also referred to as a View-Only User Interface) is a user interface that only allows for reading data, it does not allow (have the capability to) modify data. A Read Only User Interface may be either Local or Remote. A User Interface that is configured to be Read Only (by some other means than the interface itself, such as using configuration software on a laptop) is a Read-Only

SECTION 25 05 11.01 Page 5

Interface. Note a Read Only User Interface may have buttons (or touch screen, etc.) allowing the user to navigate through the presentation of data.

Examples of a Read Only User Interfaces are a) a publicly viewable "energy dashboard" showing weather data and energy usage within a building and b) digital wayfinding signage.

1.4.11.3.2 Limited User Interface

A Limited User Interface is a user interface that - by design - can only alter information local to the user interface. Note that the determination of "alter" includes only direct interactions, it explicitly excludes interactions that might occur as secondary effects. For example, an interface changing the flow setpoint in a pump controller is a direct interaction, the subsequent change in flow (as well as any subsequent downstream changes in valve position) are not direct interactions.

Two examples of LIMITED UIs are: a) a variable speed drive has a Limited Local User Interface which allows the user to change properties within the drive, but does not allow affecting things outside the drive; and b) a typical home WiFi Router has a Limited Remote User Interface which allows configuration of the Router, but does not allow direct interaction with other devices.

1.4.11.3.3 Full User Interface

A Full User Interface can alter information in devices outside the device with the user interface. For example, a typical Local Display Panel is a Full Local User Interface while a browser-based front end is a Full Remote User Interface.

1.4.11.3.4 View-Only User Interface

See Read-Only User Interface

1.4.11.4 Other User Interface Terminology

In addition to defining whether a user interface is a Hardware Limited, Read-Only, Limited or Full, and whether it is Local or Remote, user interfaces are classified by whether they are writable or privileged.

1.4.11.4.1 Writable User Interface

Any User Interface that is not Read-Only is Writable. (Limited User Interfaces and Full User Interfaces are both writable user interfaces (as they are capable of changing a value)).

1.4.11.4.2 Privileged User Interface

A Privileged UI is a UI that has sufficient capabilities or functionality that it requires specific cybersecurity measures to be put in place to limit its unauthorized use. Ultimately, whether a specific user interface is considered a Privileged User Interface must be determined by usage.

Unless otherwise specified, user interfaces can be determined to be privileged or not using the following:

a. Read-Only User Interfaces are not privileged user interfaces.

SECTION 25 05 11.01 Page 6

b. Full User Interfaces are privileged user interfaces.

c. User interfaces that allow for configuration of auditing or allows for modification or deletion of audit logs are privileged user interface.

d. User interfaces that allow for reprogramming a network connected device is a privileged user interface.

e. Except as specified above, a Limited User Interface must be determined to be privileged or not based on the specific capabilities and use case of the user interface. In general however, user interfaces that do not offer significant capabilities above and beyond those available at that location via other means (e.g. such as a disconnect switch, breaker, or hand-off-auto switch, or physical attack) are not privileged.

1.4.12 Wireless Network

Any network that communicates without using wires or fiber optics as the communication media. Wireless networks include: WiFi, Bluetooth, ZigBee, cellular, satellite, 900 MHz radio, 2.4 GHz, free space optical, point-to-point laser, and IR.

1.4.13 Wired Broadcast Network

Wired Broadcast Networks are any network, such as powerline carrier networks and modem (wired telephony), that use wire-based technologies where there is not a clearly defined boundary for signal propagation.

1.5 ADMINISTRATIVE REQUIREMENTS

1.5.1 Points of Contact

Coordinate with the following Points of Contact as indicated in this Section and as required. Not all projects will require coordination with all Points of Contact. When coordination is required and no Point of Contact is indicated, coordinate with The Contracting Office Representative (COR).

a. Government Computer Access Point of Contact: The Contracting Office Representative (COR)

b. HTTPS Certificate Point of Contact: The Contracting Office Representative (COR)

c. Email Address Point of Contact: The Contracting Office Representative

(COR)

d. Password Point of Contact: The Contracting Office Representative (COR)

e. Mobile Code Point of Contact: The Contracting Office Representative

(COR)

f. PKI Infrastructure Point of Contact: The Contracting Office Representative (COR)

SECTION 25 05 11.01 Page 7

1.5.2 Coordination

Coordinate the execution of this Section with the execution of all other Sections related to control systems as indicated in the paragraph RELATED REQUIREMENTS. Items that must be considered when coordinating project efforts include but are not limited to:

a. If requesting permission for wireless or wired broadcast communication, the Wireless and Wired Broadcast Communication Request submittal must be approved prior to control system device selection and installation.

b. If requesting permission for alternate account lock permissions, the Device Account Lock Exception Request must be approved prior to control system device selection and installation.

c. If requesting permission for the use of a device with multiple physical connections to IP networks, the Multiple IP Connection Device Request must be approved prior to control system device selection and installation.

d. Wireless testing may be required as part of the control system testing. See requirements for the Wireless Communication Test Report submittal.

e. If the Device Audit Record Upload Software is to be installed on a computer not being provided as part of the control system, coordination is required to identify the computer on which to install the software.

f. The Cybersecurity Interconnection Schedule must be coordinated with other work that will be interconnected to, and interconnections must be approved by the Government before relying on them for system functionality.

g. Cybersecurity testing support must be coordinated across control systems and with the Government cybersecurity testing schedule.

h. Passwords must be coordinated with the indicated contact for the project site.

i. If applicable, HTTPS web server certificates must be obtained from the indicated HTTPS Certificate Point of Contact.

j. Contractor Computer Cybersecurity Compliance Statements must be provided for each contractor using contractor owned computers.

1.6 SUBMITTALS

Government approval is required for submittals with a "G" or "S" classification. Submittals not having a "G" or "S" classification are for Contractor Quality Control approval. Submit the following in accordance with Section 01 33 00 SUBMITTAL PROCEDURES:

SD-01 Preconstruction Submittals Wireless and Wired Broadcast Communication Request ; GDevice Account Lock Exception Request ; G

SECTION 25 05 11.01 Page 8

Multiple Ethernet Connection Device Request ; G

Contractor Computer Cybersecurity Compliance Statements ; G

Contractor Temporary Network Cybersecurity Compliance Statements ; G

Cybersecurity Interconnection Schedule ; G

Proposed STIG and SRG Applicability Report ; G

SD-02 Shop Drawings

Network Communication Report ; G

Cybersecurity Riser Diagram ; G

SD-03 Product Data

Control System Cybersecurity Documentation ; G

SD-06 Test Reports

Wireless Communication Test Report ; G

Control System Cybersecurity Testing Procedures ; G

Control System Cybersecurity Testing Report ; G

SD-07 Certificates

Software Licenses ; G

SD-11 Closeout Submittals

Confidential Password Report ; G

Password Change Summary Report ; G

Enclosure Keys ; G

Software and Configuration Backups ; G

Auditing Front End Software ; G

Device Audit Record Upload Software ; G

System Maintenance Tool Software ; G

Control System Scanning Tools ; G

STIG, SRG and Vendor Guide Compliance Result Report ; G

Control System Inventory Report ; G

SECTION 25 05 11.01 Page 9

1.7 CYBERSECURITY DOCUMENTATION

{For Government Reference Only: This subpart (and its subparts) relates to PL-7; CCI-003071}

1.7.1 Proposed STIG and SRG Applicability Report

For each model of network connected or network infrastructure device, use the DISA SRG/STIG Applicability Guide and Collection Tool (available at https://public.cyber.mil/stigs/SCAP/ to identify applicable STIGs or SRGs and provide a report indicating applicable STIGs and SRGs for each model.

1.7.2 Cybersecurity Interconnection Schedule

Provide a completed Cybersecurity Interconnection Schedule documenting network connections between the installed system and other systems.

Provide the following information for each device directly communicating between systems: Device Identifier, Device Description, Transport layer Protocol, Network Address, Port (if applicable), MAC (Layer 2) address (if applicable), Media, Application Protocol, Service (if applicable), Descriptive Purpose of communication. For communication with other authorized systems also provide the Foreign Destination and POC for Destination. If other control system Sections used on this project include submittals documenting this information, provide copies of those submittals to meet this requirement.

In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Cybersecurity Interconnection Schedule as an editable Microsoft Excel file (a template Cybersecurity Interconnection Schedule in Excel format is available at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11

1.7.3 Network Communication Report

{For Government Reference Only: This subpart (and its subparts) relates to CA-9, PL-8; CCI-003075; CCI-002102, CCI-002103, CCI-002104, CCI-002105, CCI-003072, CCI-003073, CCI-003075 and also the submittal requirements associated with CM-6, CM-7, SC-8 and SC-41 including CM-7(3), CCI-000388. }

Provide a network communication report. For each networked device, document the communication characteristics of the device including communication protocols, services used, encryption employed, and a general description of what information is communicated over the network. For each device using IP, document all TCP and UDP ports used. For non-IP communications, document communication protocol and media used. If other control system Sections used on this project include submittals documenting this information, provide copies of those submittals to meet this requirement.

In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Network Communication Report as an editable Microsoft Excel file.

1.7.4 Control System Inventory Report

{For Government Reference Only: This subpart (and its subparts) relates

SECTION 25 05 11.01 Page 10 to CM-8(a), SI-17, IA-3; CCI-000389, CCI-000392, CCI-000398, CCI-002773, CCI-002774, CCI-002775, CCI-000777, CCI-000778, CCI-001958}

Provide a Control System Inventory report using the Inventory Spreadsheet listed under this Section at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11 documenting all networked devices, including network infrastructure devices. For each device provide all applicable information for which there is a field on the spreadsheet in accordance with the instructions on the spreadsheet.

In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Control System Inventory Report as an editable Microsoft Excel file.

1.7.5 Software and Configuration Backups

{For Government Reference Only: This subpart (and its subparts) relates to CP-10; CCI-000550, CCI-000551, CCI-000552}

For each computer on which software is installed under this project, provide a recovery image of the final as-built computer. This image must allow for bare-metal restore such that restoration of the image is sufficient to restore system operation to the imaged state without the need for re-installation of software. If additional user permissions are required to meet this requirement, coordinate the creation of the image with the identified Government Computer Access Point of Contact.

For all ethernet switches provide a backup of the switch configuration.

For all controllers, provide a backup of the controller configuration and the source code for all loaded application programs (all software that is not common to every controller of the same manufacturer and model).

If any or all of these are provided under another Section, provide documentation indicating this and referencing those submittals.

1.7.6 Cybersecurity Riser Diagram

{For Government Reference Only: This subpart (and its subparts) relates to PL-2(a), PL-8; CCI-003051, CCI-003053, CCI-003072, CCI-003073, CCI-003075}

Provide a cybersecurity riser diagram of the complete control system including all network and device hardware. If the control system specifications require a riser diagram submittal, provide a copy of that submittal as the cybersecurity riser diagram. Otherwise, provide a riser diagram in one-line format overlayed on a facility schematic.

1.7.7 STIG, SRG and Vendor Guide Compliance Result Report

For every component (device or software) with an applicable STIG or SRG in the Proposed STIG and SRG Applicability Report, provide a result report documenting compliance with the STIG or SRG requirements. For components which are scannable by the SCAP (security content automation protocol) tool (available online at https://public.cyber.mil/stigs/scap ), provide the SCAP report and raw scan results.

For every component (device or software) with manufacturer provided

SECTION 25 05 11.01 Page 11 cybersecurity documentation, procedure, or method for secure configuration or installation, provide a report documenting how the component was configured and any deviation from the manufacturer instructions.

1.7.8 Control System Cybersecurity Documentation

{For Government Reference Only: This subpart (and its subparts) relates to SA-5 (a),(b),(c); CCIs: CCI-003124, CCI-003125, CCI-003126, CCI-003127, CCI-003128, CCI-003129, CCI-003130, CCI-003131}

Provide a Control System Cybersecurity Documentation submittal containing the indicated information for each device and software application.

1.7.8.1 Software Applications

For all software applications running on computers provide:

a. administrator documentation that describes secure configuration of the software {For Government Reference Only: relates to CCI-003124}

b. administrator documentation that describes secure installation of the software {For Government Reference Only: relates to CCI-003125}

c. administrator documentation that describes secure operation of the software {For Government Reference Only: relates to CCI-003124}

d. administrator documentation that describes effective use and maintenance of security functions or mechanisms for the software {For Government Reference Only: relates to CCI-003127}

e. administrator documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the software {For Government Reference Only: relates to

CCI-003128}

f. user documentation that describes user-accessible security functions or mechanisms in the software and how to effectively use those security functions or mechanisms {For Government Reference Only:

relates to CCI-003129}

g. user documentation that describes methods for user interaction which enables individuals to use the software in a more secure manner {For Government Reference Only: relates to CCI-003130}

h. user documentation that describes user responsibilities in maintaining the security of the software {For Government Reference Only: relates to CCI-003131}

1.7.8.2 For HVAC Control System Devices

1.7.8.2.1 HVAC Control System Devices FULLY Supporting User Accounts

For all HVAC Control System Devices which FULLY support user accounts, provide:

a. Documentation that describes secure configuration of the device {For Government Reference Only: relates to CCI-003124}

SECTION 25 05 11.01 Page 12

b. Documentation that describes secure operation of the device {For Government Reference Only: relates to CCI-003124}

c. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {For Government Reference Only:

relates to CCI-003127}

d. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {For Government Reference Only: relates to CCI-003128}

e. Documentation that describes user-accessible security functions or mechanisms in the device and how to effectively use those security functions or mechanisms; or a specific indication that there are no user-accessible security functions or mechanisms in the device {For Government Reference Only: relates to CCI-003129}

f. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {For Government Reference Only: relates to CCI-003130}

1.7.8.2.2 All Other HVAC Control System Devices

For all HVAC Control System Devices which do not FULLY support user accounts, provide:

a. Documentation that describes secure configuration of the device; or a specific indication that there are no secure configuration steps that apply {For Government Reference Only: relates to CCI-003124}

b. Documentation that describes effective use and maintenance of security functions or mechanisms for the device; or a specific indication that there are no security functions or mechanisms in the device {For Government Reference Only: relates to CCI-003127}

c. For devices which include a user interface, documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {For Government Reference Only:

relates to CCI-003130}

1.7.8.3 Default Requirements for Control System Devices

For control system devices where Control System Cybersecurity Documentation requirements are not otherwise indicated in this Section, provide:

a. Documentation that describes secure configuration of the device {For Government Reference Only: relates to CCI-003124}

b. Documentation that describes secure installation of the device {For Government Reference Only: relates to CCI-003125}

c. Documentation that describes secure operation of the device {For Government Reference Only: relates to CCI-003124}

d. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {For Government Reference Only:

relates to CCI-003127}

SECTION 25 05 11.01 Page 13

e. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {For Government Reference Only: relates to CCI-003128}

f. Documentation that describes user-accessible security functions or mechanisms in the device and how to effectively use those security functions or mechanisms {For Government Reference Only: relates to

CCI-003129}

g. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {For Government Reference Only: relates to CCI-003130}

h. Documentation that describes user responsibilities in maintaining the security of the device {For Government Reference Only: relates to

CCI-003131}

1.8 SOFTWARE LICENSING

{For Government Reference Only: This subpart (and its subparts) relates to SI-2(a), SI-2(c), SI-7(14); CCI-001227, CCI-002605, CCI-002737}

For all software provided that has not already been licensed to the government or project site, provide a license to the Government for a period of no less than 5 years, and the license must also include the following software updates:

a. Security and bug-fix patches issued by the software manufacturer.

b. Security patches to address any vulnerability identified in the National Vulnerability Database at http://nvd.nist.gov with a Common Vulnerability Scoring System (CVSS) severity rating of MEDIUM or higher.

Provide a single Software Licenses submittal with documentation of the software licenses for all software provided

1.9 CYBERSECURITY DURING CONSTRUCTION

{For Government Reference Only: This subpart (and its subparts) relates to

AC-18, SA-3; CCI-000258}

In addition to the control system cybersecurity requirements indicated in this section, meet following requirement throughout the construction process.

1.9.1 Contractor Computer Equipment

Contractor owned computers may be used for construction. Contractor computers connected to the control system, control system network, or a control system component at any point during construction must meet the following requirements:

1.9.1.1 Operating System

The operating system must be an operating system currently supported by the manufacturer of the operating system. The operating system must be

SECTION 25 05 11.01 Page 14 current on security patches and operating system manufacturer required updates.

1.9.1.2 Anti-Malware Software

The computer must run anti-malware software from a reputable software manufacturer. Anti-malware software must be a version currently supported by the software manufacturer, must be current on all patches and updates, and must use the latest definitions file. Computers used on this project must be scanned using the installed software at least once per day.

1.9.1.3 Passwords and Passphrases

The passwords and passphrases for computers, applications, and web-based applications supporting passwords must be changed from their default values. Passwords must be a minimum of eight characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.

1.9.1.4 User-Based Authentication

Each user must have a unique account; sharing of a single account between multiple users is prohibited.

1.9.1.5 Demonstration of Compliance

The Government has the right to require demonstration of computer compliance with these requirements at any time during the project.

1.9.1.6 Contractor Computer Cybersecurity Compliance Statements

Provide a single submittal containing completed Contractor Computer Cybersecurity Compliance Statements for each company using contractor owned computers. Contractor Computer Cybersecurity Compliance Statements must use the template published at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11 Each Statement must be signed by a cybersecurity representative for the relevant company.

1.9.2 Temporary IP Networks

Temporary contractor-installed IP networks may be used during construction. When used, temporary contractor-installed IP networks connected to the control system, control system network, or a control system component at any point during construction must meet the following requirements:

1.9.2.1 Network Boundaries and Connections

The network must not extend outside the project site and must not connect to any IP network other than those specifically provided or furnished for this project. Any and all access to the network from outside the project site is prohibited.

1.9.3 Government Access to Network

Government personnel must be allowed to have complete and immediate access to the network at any time in order to verify compliance with this

SECTION 25 05 11.01 Page 15 specification.

1.9.4 Temporary Wireless IP Networks

In addition to the other requirements on temporary IP networks, temporary wireless IP (WiFi) networks, when permitted, must not interfere with existing wireless networks, must use WPA2 security and must not broadcast the network name (SSID). Network names (SSID) for wireless networks must be changed from their default values.

1.9.5 Passwords and Passphrases

The passwords and passphrases for all network devices and network access must be changed from their default values. Passwords must be a minimum 8 characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.

1.9.6 Contractor Temporary Network Cybersecurity Compliance Statements

Provide a single submittal containing completed Contractor Temporary Network Cybersecurity Compliance Statements for each company implementing a temporary IP network. Contractor Temporary Network Cybersecurity Compliance Statements must use the template published at https://www.wbdg.org/ffc/dod/unified-facilities-guide-specifications-ufgs/ufgs-25-05-11 Each Statement must be signed by a cybersecurity representative for the relevant company. If no temporary IP networks will be used, provide a single copy of the Statement indicating this.

1.10 CYBERSECURITY DURING WARRANTY PERIOD

All work performed on the control system after acceptance must be performed using Government Furnished Equipment or equipment specifically and individually approved by the Government.

PART 2 PRODUCTS

All products used on this project must meet the indicated requirements, but not all products specified here will be required by every project.

2.1 ETHERNET SWITCH

Provide Open Systems Interconnection (OSI) Layer 2 Ethernet switches with the following capabilities, and with an interface to support switch configuration for these capabilities:

2.1.1 Required Functionality

Switches must:

a. Copper Ethernet ports must auto negotiate for 10, 100 and 1000 megabits-per-second links.

b. Be capable of implementing port level access control by MAC address and limit the number of MAC addresses to one MAC address per port.

d. Support Remote Network Monitoring (RMON) Port Analysis in accordance with IETF RFC 2819

SECTION 25 05 11.01 Page 16

e. Configure target port and analysis port such that switch clones all target port traffic to analysis port.

f. Support authentication via RADIUS server (for management and 802.1x)

g. Support IEEE 802.1x network login.

2.1.2 Configuration Requirements

Switches must:

a. Support configuration save and restore.

b. Support both manual IP address assignment and acquisition of a dynamic IP address via Dynamic Host Configuration Protocol (DHCP).

c. Be capable of limiting access for configuration to one or more of: a web interface using HTTPS, a command line interface using SSH, or an SNMP connection using SNMP version 3 or later.

d. Support the ability to lock configuration capability to a dedicated management port.

2.2 DAISY CHAIN IP CONTROLLERS

Controllers used as Daisy Chain IP Controllers must be IP controllers with exactly two Ethernet network connections and basic built-in switch capabilities to allow implementation of an Ethernet network in a daisy chain architecture. Switches incorporated by Daisy Chain IP Controllers are not required to meet the requirements for Ethernet Switches as defined in this Section.

PART 3 EXECUTION

3.1 CYBERSECURITY HARDENING AND CONFIGURATION GUIDES

Install, configure, and harden all hardware and software furnished on this project in accordance with manufacturer provided documentation, procedures, or methods for secure configuration or installation. Do not implement specific hardening actions if that action would conflict with requireed functionality or another requirement of this Section.

3.2 NETWORK REQUIREMENTS

3.2.1 Wireless and Wired Broadcast Communication

{For Government Reference Only: This subpart (and its subparts) relates to AC-18, AC-18(3); CCI-001438, CCI-001439, CCI-002323, CCI-001441, CCI-002252}

Unless explicitly authorized by the Government, do not use any wireless or wired broadcast communication. If requesting authorization for wireless or wired broadcast communication, wired broadcast media such as powerline carrier is preferred to wireless.

SECTION 25 05 11.01 Page 17

3.2.1.1 Wireless and Wired Broadcast IP Communications

Do not install wireless or wired broadcast IP networks, including: do not install a wireless access point; do not install or configure an ad-hoc wireless network; do not install or configure a WiFi Direct communication.

When explicitly authorized by the Government, wireless IP communication may be used to communicate with an existing wireless network.

3.2.1.2 Non-IP Wireless Communication

For LOW Impact Systems: When non-IP wireless communication is explicitly authorized by the Government, use the maximum level of encryption supported by the specific protocol employed and select signal strength and radiated power to the…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .