SCADA_Upgrade_Maint_Plan.docx
DOCX document 27 KB Posted
- Attached to
- Supervisory Control and Data Acquisition (SCADA) System Upgrades & Maintenance State and local contract opportunity
- Solicitation number
- 26-035-RFP
- Issued by
- Bell County, Kentucky
About this file
This is a SCADA Upgrades and Maintenance Plan document for the Kenton County Airport Board (KCAB) in Kentucky, which outlines the technical requirements and security standards for upgrades to the Spent Aircraft Deicing Fluid Recovery SCADA system. The project requires the contractor to perform quarterly security operating system updates on HMIs and servers, quarterly SCADA application updates to the latest minor versions, and annual major version upgrades when available. Additional maintenance includes annual updates to network switch firmware and PLC firmware, with quarterly reporting on all software and firmware versions. A pre-proposal meeting and site visit are scheduled for Tuesday, June 2, 2026 at 10:00 am at CVG Centre, Admin. Offices, 77 Comair Blvd., Erlanger, KY 41018. Questions must be submitted by 11:59 pm on Monday, June 22, 2026, with answers posted by Thursday, June 25, 2026 at 11:59 pm. Proposals are due by Thursday, July 2, 2026 at 2:00 pm.
The proposal requires adherence to comprehensive cybersecurity standards including NIST, CIS, and IEC compliance measures. Critical severity vulnerabilities (CVSS 9.0-10.0) must be patched within 60 calendar days, while high severity vulnerabilities (CVSS 7.0-8.9) must be patched within 120 calendar days across all system components. The contractor must implement Endpoint Detection and Response (EDR) software on all HMIs and servers, provide unique Active Directory accounts with multi-factor authentication (MFA) for remote VPN access, and maintain network separation between industrial control and remote workstations using a jump box or bastion host. The plan emphasizes unique user identities for administrative access while allowing shared read-only accounts when administratively necessary. For SaaS-based components, Single Sign-On (SSO) integration with Entra ID is preferred, with MFA required as an alternative.
View the file
Other files for this state and local contract opportunity
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SCADA Upgrades for Spent Aircraft Deicing Fluid Recovery
· Describe any compliance and/or standards (NIST, CIS, IEC, etc.) to which the proposed system adheres.
· Contractor will perform quarterly (4 times per year) security operating system (OS) updates on HMIs and server(s)
· Contractor will perform quarterly (4 times per year) SCADA application updates. This includes updating to the latest minor version of the application (i.e update from version 1.0 to 1.1).
· Contractor will perform application upgrades to the latest major version of the application, when available. (i.e upgrade from version 1.0 to 2.0), up to once per year.
· Contractor will perform updates/upgrades to the latest supported firmware/OS version for network switches, once per year.
· Contractor will Perform updates/upgrades to the latest supported firmware version for PLCs, once per year.
· Contractor will provide a quarterly report (4 times per year) with current software and firmware versions for all HMIs, server(s), network switches and PLCs
· Endpoint Detection and Response (EDR) software installed on all HMIs and server(s)
· Operating system or firmware version(s) that have been identified as having vulnerabilities with a severity level of ‘Critical’ must be patched within 60 calendar days. The Critical severity level is as measured by the Common Vulnerability Scoring System (CVSS) version 3, which identifies severity level ‘Critical’ for vulnerabilities with a CVSS score of 9.0 – 10.0. High severity vulnerabilities must be patched within 120 calendar days. The High severity level is as measured by the Common Vulnerability Scoring System (CVSS) version 3, which identifies severity level ‘High’ for vulnerabilities with a CVSS score of 7.0 – 8.9. This requirement includes servers, client machines, PLCs, and network switches.
· Each contractor employee who requires remote VPN access to the SCADA system will be provided with a unique CVG Active Directory account for VPN authentication.
· VPN access must be supplemented via MFA. Available MFA methods include the Microsoft Authenticator app. SMS (text), or voice call. If contracted employees do not have a corporate-owned device, they must agree to receive a text message or voice call to their personal phone to complete MFA. They can also install the Microsoft Authenticator app, if they choose. MFA for VPN will be implemented and maintained by the CVG IT department.
· The SCADA system must maintain a level of separation between industrial control /OT components and remote user workstations. Currently CVG utilizes a jump box/bastion host for this purpose. If needed, CVG will provide a jump box for the new SCADA implementation.
· Unique user identities are preferred for SCADA system access. If the administrative overhead to maintain these accounts becomes too high, shared identities for low privilege (read only) user roles may be an option. User accounts with high level permissions (administrators) will require unique user identities for authentication into the SCADA system.
· MFA for privileged access into the SCADA system is highly encouraged and preferred. Contractor will submit any MFA methods that are supported and available for the proposed SCADA system.
· For any SaaS based components of the SCADA system, SSO with Entra ID is preferred. If SSO is not supported, all user access to the SaaS platform must be supported with MFA.
File details come from the government source that posted it. Updated .