PR_74106107_SOW__Fire_Alarm_SigCom.pdf
PDF 1 MB Posted
- Attached to
- FIRE ALARM/SIGNALING COMMUNICATION CONTROL UNIT Federal contract opportunity
- Solicitation number
- SP470318Q0061
- Issued by
- Defense Logistics Agency Aviation
About this file
STATEMENT OF WORK
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| PR_74106107_SOW__Fire_Alarm_SigCom_revised_9-26-2018.pdf | ||
| PR_74106107_SoleSource_StatementUnder150K_print_Redacted.pdf | ||
| SF30_SP470318Q00610005_Amendment.pdf | ||
| SF30_SP470318Q00610004_Amendment.pdf | ||
| PR_74106107_SOW__Fire_Alarm_SigCom_revised_9-19-2018.pdf | ||
| PR_74106107_SOW__Fire_Alarm_SigCom_revised_9-12-2018.pdf | ||
| SF30_SP470318Q00610003_Amendment.pdf | ||
| SF30_SP470318Q00610002_Amendment.pdf | ||
| PR_74106107_SOW__Fire_Alarm_SigCom_revised_8-29-2018.pdf | ||
| SF30_SP470318Q00610001_Amendment.pdf | ||
| PR_74106107__Fire_Alarm_SigCom_Attachment__2_Wage_Determinations__updated.pdf | ||
| SF1449_SP470318Q0061_RFQ.pdf | ||
| PR_74106107__Fire_Alarm_SigCom_Attachment__2_Wage_Determinations.pdf |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Defense Logistics Agency
DLA Installation Operations
(DF-FR)
STATEMENT OF WORK INSTALL FIRE
ALARM/SIGNALING COMMUNICATION
CONTROL UNIT FOR
MASS NOTIFICATION SYSTEMS
SOURCE SELECTION INFO - SEE FAR 2.101 & 3.104
Install Fire Alarm/Signaling Communication Control Unit For Mass Notification Systems
STATEMENT OF WORK
SCOPE
The contractor shall provide and install new fully functional Signal Communications (SigCom) brand fire alarm signaling communication and control unit for mass notification systems (MNS) in Building 201, Defense Supply Center Richmond (DSCR), Emergency Communications Center to communicate and interface with individual building fire alarm and mass notification systems on base. The contractor shall provide and install fully functional (SigCom) transceivers for each of the existing fire alarm/mass notification systems currently installed in the buildings on base. All communications equipment shall be capable of integrating and communicating with the existing fire alarm systems, Emergency Voice Activated Communications System (EVACS), and mass notification systems. There are currently fire alarm and mass notification systems provided by eight different manufacturers in various buildings on post. The newly installed systems shall comply with the requirements of National Fire Protection Association (NFPA) 72, Unified Facilities Criteria (UFC) 3-600-01 and UFC 4-021-01 governing the design, application, and performance characteristics of these systems. Only signaling systems capable of communicating fully addressable fire alarm and mass notification signals from existing fire alarm and mass notification systems on post shall be accepted. There are a total of three of these systems on DSCR: two at Building 201 in the Emergency Communications Center, a primary system and a redundant backup system; and one at Building 56 that strictly monitors water flow signals and engages the base-wide fire pumps upon receipt of a suppression system water flow signal from any individual building on post. The FRIMP shop shall have right of first refusal on all old SigCom equipment removed. The contractor shall execute all work associated with this scope of work without exceptions, exclusions, or limitations.
BACKGROUND
The current SigCom fire alarm signaling system is not capable of communicating mass notification messages and the current system is at the end of its service life. The new SigCom system will be fully compatible with all existing equipment on post. Incoming signals are de-coded, processed, and sent to two computers having rapid response software programs to display the information to the on duty dispatch personnel who have the ability to review, acknowledge, and end calls as needed. The existing systems have two features that shall be incorporated into the new systems. The first feature is that all addressable point information is transmitted from the individual building fire alarm, EVACS, and mass notification systems and is displayed to the on duty dispatcher who then relays this same information to the incident commander in route to the scene providing them with the same information as displayed on the LCD display screen on the fire alarm, EVACS, and mass notification systems in the building being responded to. The second feature is that the existing system in Building 56 has been programmed to automatically start the base-wide fire pumps upon receiving a suppression system water flow signal from any building on post.
TECHNICAL OBJECTIVES AND GOALS
The technical objectives and goals for this project are to provide a compatible, interoperable replacement SigCom system to communicate and interface with the currently installed fire alarm, mass notification and EVACS systems in all of the individual buildings on post. These mass notification systems are represented by fourteen systems from six different manufacturers and the fire alarm systems are represented by fifty-four systems from eight different manufacturers.
The systems are being replaced with the addition of the mass notification capabilities as part of an Enterprise approach.
As dictated by the nature and scope of the incident, the newly installed systems shall have the capability to:
• Communicate and interface with the seven currently installed high power speaker arrays known as “Giant Voice” located throughout the post
• Activate individual buildings, selected groups of buildings, or all buildings on post fire alarm, mass notification and EVACS systems, to broadcast pre-recorded messages and live voice announcements
• Provide command and control capability to shut down HVAC systems, ventilations systems, close dampers et cetera
• Transmit and receive addressable point data from the individual building’s fire alarm, mass notification and EVACS systems
• Display such data on a new graphical user interface for the dispatcher on duty
APPLICABLE DOCUMENTS
The publications listed below form a part of this specification.
Factory Mutual System (FM) Publication:
Approval Guide (Equipment, Materials, Services for Conservation of Property) 1989 with Quarterly Supplements.
National Fire Protection Association (NFPA) Standards:
NFPA 70 National Electrical Code.
NFPA 72 National Fire Alarm Code.
NFPA 90A Installation of Air Conditioning and Ventilating System.
NFPA 101 Life Safety Code
Underwriters Laboratories, Inc. (UL) Publications:
Fire Protection Equipment Directory (Jan 1989 with Quarterly Supplements).
UL 38 Manually Actuated Signaling Boxes for Use with Fire-Protective Signaling Systems.
UL 454 Standard for Audible Signaling Devices.
UL 1480 Standards for Speakers for Fire Alarm, Emergency, and Commercial and Professional Use.
UL 1971 Standard for Signaling Devices for Hearing Impaired.
UL 2572 Standard for Safety for Control and Communication Units for Mass Notification Units.
Unified Facility Criteria (UFC) 3-600-01, Design: Fire Protection Engineering for Facilities.
UFC 4-010-06 Cybersecurity of Facility-Related Control Systems, dated 19 September 2016.
DOD 5200.2-R Personnel Security Program, dated January 1987.
DOD Instruction (DODI) 8500.01, Cybersecurity, dated March 14, 2014.
DOD Instruction (DODI) 8510.01, Risk Management Framework (RMF) for DOD Information Technology (IT), incorporating Change 1, Effective May 24, 2016.
DOD 8570.01-M Information Assurance Workforce Improvement Program, Incorporating Change 4, 11/10/2015.
National Institute of Standards and Technology (NIST) Special Publication 800- 53 revision 4, Security and Privacy Controls for Federal Information Systems and Organizations, dated April 2013.
National Institute of Standards and Technology (NIST) Special Publication 800- 82 revision 2, Guide to Industrial Control Systems (ICS) Security, dated May 2015.
Unified Facility Criteria (UFC) 4-021-01 Design and O&M: Mass Notification Systems (dated April 08) Unified Facility Criteria (UFC) 3-601-02 Operations and Maintenance: Inspection, Testing, and Maintenance of Fire Protection Systems
4.1 DOCUMENTATION AND RECORDS
All documentation, records, and schedules, as described in this Statement of Work (SOW), which are the responsibility of the contractor and the property of the Government and shall remain so upon termination or completion of the contract. The contractor shall keep these items current.
Documentation, records, and schedules shall be turned over to the Government upon termination or completion of the contract. The contractor shall provide a copy of all licensing, product / user / administration manuals, software and software documentation to the Government.
REQUIREMENTS
5.1 CYERSECURITY REQUIREMENTS
The contractor shall install and configure all information technology necessary for the operation of the fire alarm/signal communication control units systems to meet the requirements specified in the applicable Security Technical Implementation Guides (STIGs), those specified in NIST SP 800-53r4, and NIST SP 800-82rev2.
All network components and applications shall be compatible with all applicable STIGs. Any STIG exceptions must be identified as part of the contractor’s proposal. Exceptions incurring risk found unacceptable to the DLA Authorizing Official are not permitted.
The Contractor shall perform all STIG requirements prior to installing any vendor specific software, and identify and deliver boundary IPs Architecture to the COR/COTR.
All devices and systems subject to periodic J6 cybersecurity scanning. Any vulnerabilities will be the responsibility of the Contractor to remediate.
The contractor shall provide all diagrams and documentation necessary for the assessment and Authorization to Operate (ATO) of the fire alarm/signal communication control units systems by the DLA Authorizing Official (i.e. DLA CIO) in accordance with DODI 8510.01 and NIST SP 800-82r2.
The contractor shall perform all tasks associated with this scope of work without exclusion, exception, or limitation in order to deliver complete and usable fire alarm and mass notification systems to the government.
5.2 TESTING
The contractor shall install and conduct a 100% post construction test of all new equipment installed to ensure complete functionality of the replacement equipment documenting the results of the test and correcting any deficient items prior to the scheduling of final acceptance testing by the COR in conjunction with the Authority Having Jurisdiction, the Chief Fire Protection Engineer for DLA. The contractor shall furnish the post construction test report results to the
COR.
The Contractor will test all systems in the presence of the COR / COTR and provide STIG compliant results. No external Internet connections are authorized as part of acceptance testing.
The final acceptance testing shall consist of but is not limited to inspection for conformance with UFC 3-600-01 9-18.1.2 that states fire alarm systems must be independent, stand-alone systems that are not an integral part of security, energy monitoring and control systems (EMCS) or other systems UFC 3-600-01 9-18.3.2 which states that the facility fire alarm system must be connected to the Fire Alarm Reporting System UFC 3-600-01 9-18.3.5 which states that Fire Alarm Reporting Systems must provide the transmission of coded signals to Fire Department headquarters or other central locations, a dedicated transceiver that will transmit alarm, supervisory and trouble signals for each facility and transceivers must be listed or approved for use with the existing fire alarm reporting systems UFC 3-600-01 9-18.5.2 which states detection systems must be arranged to alert facility occupants and transmit an alarm signal via a Fire Alarm Reporting System.
UFC 4-021-01 3-7.1 which states that primary communications shall use radio frequency-type systems that comply with National Telecommunications and Information Administration (NTIA) requirements UFC 4-021-01 3-7.2 which states redundant communication means (when required) should be established using several alternate wireless radio frequency paths to the radios.
In some cases, the redundant communication means might be accomplished by using the DOD installation’s communications backbone network (e.g., optical fiber cable). In this case, the central control units should accomplish this by being directly connected to the backbone network.
Note: All software and hardware to be installed on DOD Ethernet or Internet systems must first successfully complete an accreditation process. Accreditation often takes a relatively long time.
UFC-4-021-01; Design and O&M: Mass Notification Systems (dated April 08) which states system shall be capable of disseminating pre-recorded mass notification messages, live voice communications, and command and control signals to shut down HVAC and ventilation systems
5.3 SPECIFIC REQUIREMENTS
The existing fire alarm/signal communication control units shall remain active, in place, and fully functional during the installation of the replacement SigCom TRX50 fire alarm/signal communication control units for mass notification. No demolition or removal of equipment shall occur prior to the successful completion of final acceptance testing. The contractor shall provide an implementation plan to the COR to be forwarded to J6 COTR for review.
The systems shall be designed to minimize the potential for interference, jamming, eavesdropping, and spoofing. The contractor shall provide compliance documentation as evidentiary material that demonstrates that the system has minimal potential for interference, jamming, and no eavesdropping or spoofing.
The contractor shall connect the new SigCom TRX50 fire alarm/signaling communication control unit for mass notification systems into the existing uninterruptable power supply and shall verify that the uninterruptable power supply provides adequate service for two hours.
The contractor shall migrate all existing point and programming information from the existing SigCom (Vision21) system to the new SigCom TRX50 system.
The contractor shall install all electrical services required by the new fire alarm/signaling communication control unit for mass notification systems adding any required sub-panels to feed the system as needed.
The contractor shall integrate the new SigCom fire alarm/signaling communication control unit for mass notification systems into the existing “Giant Voice” system on post.
The contractor shall calculate the heating and cooling load factor for the area where the new SigCom fire alarm/signaling communication control unit for mass notification systems shall be installed to insure that the existing HVAC system is capable of cooling the new fire alarm/signaling communication control unit for mass notification systems. If the load factor is inadequate to keep the new fire alarm/signaling communication control unit for mass notification systems cooled, the contractor shall add the necessary HVAC equipment required by the new SigCom fire alarm/signaling communication control unit for mass notification systems.
The contractor shall replace up to fifty SigCom DTX transmitters with the latest SigCom supported model SigCom transceivers to eliminate “transmitter clash”. The existing SigCom transmitters shall remain in place and fully operational until final acceptance testing of the newly installed system is complete.
Installed devices shall support Windows 10 compliance, including all associated devices with embedded software and firmware. Non-Microsoft devices must be utilizing the vendor’s most current supported version of software and firmware, and be fully patched. All devices that are not Windows 10 compliant must be utilizing a software vendor supported operating systems (i.e., Windows 7), be fully patched and a plan of action and milestone provided to be Windows 10 compliant.
The contractor will maintain and / or replace any equipment no longer supported by the SigCom for the lifecycle of the contract. This includes all software and firmware.
The contractor shall provide manufacturer’s instruction to maintenance personnel resulting in maintenance personnel receiving manufacturer’s certification. Instruction sessions shall be held on site and shall be scheduled and coordinated through the COR.
All devices shall be listed and approved for use in fire alarm systems by Underwriters Laboratories and/or Factory Mutual.00 The system shall be capable of being expanded to provide service to additional buildings on site.
The contractor shall provide technical support for software and hardware issues for a two year period after the completion of the installation described in this SOW.
The contractor shall perform maintenance on the new SigCom system on a quarterly basis to provide and install any software updates or upgrades to keep the system in the most up to date status for a period of two years after installation of the new systems.
5.4 PRE-CONSTRUCTION MEETING
After contract award and prior to the initiation of work, a meeting will be held with the contractor, Contracting Officer, Contract Specialist/Contract Administrator, Contracting Officer’s Representative, Contracting Officer’s Technical Representative and any other individuals designated by the Government. The purpose of the Pre-Construction Meeting is to discuss matters of mutual interest including the resulting action items. General conditions, work schedules and coordination, security, safety, permits, and other matters pertinent to work accomplishments shall be discussed in this meeting.
5.5 QUALITY CONTROL PLAN
The contractor shall submit a Quality Control Plan within 10 business days of contract award.
This plan shall describe the contractor’s methodology for compliance with the Deliverables Summary below. The CO or his /her authorized representative will notify the contractor of concurrence or required modifications to the QCP within 10 business days of receipt. The contractor shall make appropriate modifications within 5 business days of the CO, or his/her authorized representative’s notification and provide a revised QCP within 5 business days.
5.6 EQUIPMENT DATA SHEET
Within five working days after the final inspection and acceptance, the contractor shall completely fill out the below equipment data sheet for all equipment removed and/or installed.
The contractor shall include the sheet(s) in the O&M binder, CD etc. as well and send the completed sheets electronically in Adobe PDF format to the COR by email. Equipment data sheets shall be legible and filled out in their entirety. The COR will provide the form below to the contractor in Adobe PDF format.
EQUIPMENT DATA SHEET
EQUIPMENT DESCRIPTION
FUNCTIONAL LOCATION
FUNCTIONAL LOCATION DESCRIPTION
EQUIPMENT INSTALLER INSTALLED DATE
MANUFACTURER MANUFACTURER SERIAL #
MANUFACTURER MODEL # MANUFACTURER YEAR
WARRANTY START DATE WARRANTY PERIOD
HORSEPOWER VOLTAGE PHASE AMP KVA
CUBIC FEET PER MINUTE WEIGHT GALLONS PER MINUTE
BTU FILTER SIZE (LxWxT) FILTER QUANTITY
REFRIGERANT TYPE BELT SIZE
PM CYCLE (0) (30) (90) (180) (365) WORK CENTER
IS THIS A REPLACEMENT OR NEW INSTALL
WHAT DID THIS REPLACE
ϒ Name ϒ Model ϒ Serial
INFORMATION PROVIDED ON NEW INSTALL
ϒ Copies of warranty paperwork ϒ Maintenance and Operation Manuals (Hard copies or electric) ϒ Copies of submittals (Hard copies or electric)
Additional Comments:
5.7 DELIVERABLES SUMMARY
The contractor shall provide the following deliverables:
M001 ATO DOCUMENTATION
M002 EQUIPMENT PRE-TEST REPORT
M003 ACCEPTANCE TEST PLAN AND SCENARIOS
M004 IMPLEMENTATION PLAN
M005 COMPLIANCE DOCUMENTATION
M006 MEETING MINUTES
M007 QUALITY CONTROL PLAN
M008 EQUIPMENT DATA SHEET
DELIVERABLES SCHEDULE
SOW
Reference Number
Deliverable ID# Deliverable Due Date in business days Quantity Distribution
5.1 ATO Documentation M001 Within 10 days of contract
award 1 COR
5.2 Equipment Pre-Test Report M002 5 days after test completion 1 COR
5.2 Acceptance Test Plan and
Scenarios M003 5 days before testing begins 1 COR
5.3 Implementation Plan M004 Within 10 days of contract
award 1 COR
5.3 Compliance Documentation M005 Within 10 days of contract
award 1 COR
5.4 Meeting Minutes M006 5 days after the meeting 1 COR
5.5 Quality Control Plan M007 Within 10 days of contract
award 1 COR
5.6 Equipment Data Sheet M008 Within 5 days of the final
inspection and acceptance 1 COR
GOVERNMENT FURNISHED FACILITES
The Government shall provide the contractor with suitable workspace, meeting rooms and telephones to be used during the duration of this contract.
SECURITY REQUIREMENTS
7.1 SYSTEM NETWORK REQUIREMENTS
a) All network components shall be connected using copper 10/100/1000 or fiber optic
SFP-based Gigabit Ethernet ports.
b) Network components shall allow configuration of IEEE 802.1x or port security for authentication.
c) Web servers, human-machine interface (HMI) and controller systems must be on separate VLANs.
d) Any external network connections must be permanently disconnected.
e) The vendor shall provide a complete list of all ports, protocols and services required for any computer system running control system applications or required to interface the control system applications. The listing shall include all ports and services required for normal operation as well as any other ports and services required for emergency operation. The listing shall also include an explanation or cross reference to justify why each service is necessary for operation.
f) The vendor shall identify any system wireless communication capability, enabled or disabled. All wireless communications shall meet applicable STIG requirements.
7.2 CYBERSECURITY REQUIREMENTS
1. Risk Management Framework (RMF) Authorization: The solution must be able to obtain an Authorizing Official (AO) Authorization to Operate (ATO) by utilizing the Department of Defense (DOD) processes and procedures as defined in the DoD Instruction 8510.1 “Risk Management Framework (RMF) for DoD Information Technology (IT)” as implemented by DLA. The contractor shall make every effort to mitigate risk identified through the RMF authorization process down to a level acceptable to the DLA Authorizing Official.
2. Cybersecurity Engineering Support: The contractor shall provide system and cybersecurity documentation including network diagrams and Purdue Enterprise Reference Architecture (PERA) diagrams.
3. The Contractor shall not store government information, to include configuration information.
4. Cybersecurity Controls: The solution shall comply with the security control requirements documented in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53r4, “Security and Privacy Controls for Federal Information Systems and Organizations” and NIST 800-82r2, “Guide to Industrial Control Systems (ICS) Security” as specified in this PWS. The vendor shall provide details of any alternative but equally effective security measures used to compensate for the inability to satisfy a particular derived security requirement (mitigation to control compliance findings). Guidance on the applicability and enforcement of controls by PERA level can be found in the United Facilities Criteria (UFC) 4-010-06, Cybersecurity of Facilities-Related Control Systems.
5. Changes to File System and Operating System Permissions. The Vendor shall configure hosts with least privilege file and account access and provide documentation of the configuration. The Vendor shall configure the necessary system services to execute at the least user privilege level possible for that service and provide documentation of the configuration. The Vendor shall document that changing or disabling access to such files and functions has been completed.
6. Hardware Configuration. The Vendor shall disable, through software or physical disconnection, all unneeded communication ports and removable media drives, or provide engineered barriers, and provide documentation of the results. The Vendor shall password protect the BIOS from unauthorized changes unless it is not technically feasible, in which case the Vendor shall document this case and provide mitigation measures. The Vendor shall provide a written list of all disabled or removed USB ports, CD/DVD drives, and other removable media devices. The Vendor shall configure the network devices to limit access to/from specific locations, where appropriate, and provide documentation of the configuration. The Vendor shall configure the system to allow the system administrators the ability to re-enable devices if the devices are disabled by software and provide documentation of the configuration.
7. Heartbeat Signals. The vendor shall identify heartbeat signals or protocols and recommend whether any should be included in network monitoring. Post-contract award, the Vendor shall provide packet definitions of the heartbeat signals and examples of the heartbeat traffic if the signals are included in the network monitoring.
8. Installing Operating Systems, Applications, and Third-Party Software Updates. The Vendor shall have a patch management and update process. Pre-contract award, the Vendor shall provide details on their patch management and update process. Responsibility for installation and update of patches shall be identified. Post-contract award, the Vendor shall provide notification of known vulnerabilities affecting Vendor-supplied or required OS, application, and third-party software within a pre-negotiated period after public disclosure.
Post-contract award, the Vendor shall provide notification of patches affecting security within a pre-negotiated period as identified in the patch management process. The Vendor shall apply, test, and validate the appropriate updates and/or workarounds on a baseline reference system before distribution. Mitigation of these vulnerabilities shall occur within a pre-negotiated period.
9. Disabling, Removing, or Modifying Well-Known or Guest Accounts. The Vendor shall recommend which accounts need to be active and those that can be disabled, removed, or modified. The Purchaser shall approve in writing the Vendor’s recommendation. The Vendor shall disable, remove, or modify all the accounts pursuant to the approved recommendation.
Post-contract award, the Vendor shall disable or remove all default and guest accounts prior to the FAT. Once changed, new accounts will not be published except that new account information and passwords will be provided by the Vendor via protected media. At delivery, the Vendor shall disable, remove, or modify all Vendor-owned accounts or negotiate account ownership with the Purchaser. Post-award Vendor updates shall not re-enable or re-install any of these accounts.
10. Session Management. The vendor shall not permit user credentials to be transmitted in clear text. Encryption shall as a minimum meet AES 256 and comply with FIPS 140.2. If this is not technically feasible, the Vendor shall provide the strongest encryption method commensurate with the technology platform and response time constraints and document the encryption used in the proposal. The vendor shall not allow multiple concurrent logins, applications to retain login information between sessions, provide any auto-fill functionality during login, or allow anonymous logins. The Vendor shall provide user account-based logout and timeout settings.
11. Password/Authentication Policy and Management. The Vendor shall implement two-factor authentication using DoD Common Access Card where technically feasible, with exceptions noted in the proposal. The vendor shall provide a configurable account password management system that allows for selection of password length, frequency of change, setting of required password complexity, number of login attempts, inactive session logout, screen lock by application, and denial of repeated or recycled use of the same password. The Vendor shall not store passwords electronically or in Vendor-supplied hardcopy documentation in clear text unless the media is physically protected.
12. Account Auditing and Logging. The vendor shall provide a system whereby account activity is logged and is auditable both from a management (policy) and operational (account use activity) perspective. The Vendor shall time stamp, encrypt, and control access to audit trails and log files. The Vendor shall ensure audit logging does not adversely impact system performance requirements.
13. Role-Based Access Control for Control System Applications. The Vendor shall provide for user accounts with configurable access and permissions associated with the defined user role. The Vendor shall adhere to least privileged permission schemes for all user accounts, and application-to-application communications. The Vendor shall configure the system so that initiated communications start with the most privileged application controlling the communication. Upon failed communication, the most privileged side will restart communications. The Vendor shall verify that the master network device initiates communications. The Vendor shall inform the Purchaser if this condition cannot be met. The Vendor shall verify that a user cannot escalate privileges, under any circumstances, without logging into a higher-privileged role first. The Vendor shall provide a mechanism for changing user(s) role (e.g., group) associations. Post-contract award, the Vendor shall provide documentation defining access and security permissions, user accounts, applications, and communication paths with associated roles.
14. Coding for Security. Pre-contract award, the Vendor shall provide documentation of development practices and standards applied to Vendor-written control system software, including firmware, used to ensure a high level of defense against unauthorized access. The Vendor shall provide the results of Code Reviews. Post-contract award, the Vendor shall provide documentation of coding practices used in developing the delivered software.
15. Problem Reporting. The vendor shall provide a process for users to submit problem reports and remediation requests to be included in the system security. The process shall include tracking history and corrective action status reporting. The Vendor shall review and report their initial action plan within 24 hours of submitting the problem reports. The vendor shall protect problem reports regarding security vulnerabilities from public discloser and notify Purchaser of all problems and remediation steps, regardless of origin of discovery of the problem. The Vendor shall inform the Purchaser in writing of flaws within applications and operating systems in a timely fashion and provide corrective actions, fixes, or monitoring guidance for vulnerability exploits associated with the flaw. The vendor shall provide an auditable history of flaws including the remediation steps taken for each.
16. End Devices. The Vendor shall provide physical and cyber security features including, but not limited to, authentication, encryption, access control, event and communication logging, monitoring, and alarming to protect the device and configuration computer from unauthorized modification or use. The Vendor shall clearly identify the physical and cyber security features and provide the methodology(ies) for maintaining the features including the methods to change settings from the Vendor-configured or manufacturer default conditions.
The Vendor shall verify that the addition of security features does not adversely affect connectivity, latency, bandwidth, response time, and throughput. The Vendor shall remove or disable all software components that are not required for the operation and maintenance of the device prior to delivery. The Vendor shall provide documentation on what is removed and/or disabled. The Vendor shall provide, within a pre-negotiated period, appropriate software and service updates and/or workarounds to mitigate all vulnerabilities associated with the product and to maintain the established level of system security.
17. Physical Access of Cyber Components. The Vendor shall provide a detailed plan for appropriate physical security mechanisms.
18. The Vendor shall provide a complete system hardware and software baseline configuration and asset inventory of control system components at delivery.
7.3 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS
• Work to be performed under this contract or task order may, in full or in part, be performed at the Defense Logistics Agency (DLA) Headquarters (HQ) or other DLA field activity office(s), with physical access to a Federally-controlled facility. Prior to beginning work on a contract, DLA and its field activity offices require all contractor personnel working on the Federally-controlled facility to have a minimum of a favorably adjudicated National Agency Check with Written Inquiries (NACI) or NACI equivalent.
• Additionally, in accordance with Department of Defense (DOD) Regulation 5200.2-R, Personnel Security Programs, and DLA Issuance 4314, Personnel Security Program, all DOD contractor personnel who have access to Federally-controlled information systems must be assigned to positions which are designated at one of three information technology (IT) levels, each requiring a certain level of investigation and clearance, as follows:
o (1) IT-I for an IT position requiring a Single Scope Background Investigation (SSBI) or SSBI equivalent;
o (2) IT-II for an IT position requiring a National Agency Check with Law and Credit (NACLC) or NACLC equivalent; and o (3) IT-III for an IT position requiring a NACI or equivalent.
Note: IT levels will be designated according to the criteria in DOD 5200.2-R.
• Previously completed security investigations may be accepted by the Government in lieu of new investigations if determined by the DLA Intelligence (DI) Personnel Security Office to be essentially equivalent in scope to the contract requirements. The length of time elapsed since the previous investigation will also be considered in determining whether a new investigation is warranted. To assist the Government in making this determination, the contractor must provide the following information to the respective DI Personnel Security Office immediately upon receipt of the contract. This information must be provided for each contractor employee who will perform work on a Federally-controlled facility and/or will require access to Federally-controlled information systems:
(1) Full name, with middle name, as applicable, with social security number;
(2) Citizenship status with date and place of birth;
(3) Proof of the individual’s favorably adjudicated background investigation or NACI, consisting of identification of the type of investigation performed, date of the favorable adjudication, and name of the agency that performed the investigation;
(4) Company name, address, phone and fax numbers with email address;
(5) Location of on-site workstation or phone number if off-site (if known by the time of award); and
(6) Delivery order or contract number and expiration date; and name of the contracting officer.
The contracting officer will ensure that the contractor is notified as soon as a determination is made by the assigned or cognizant DI Personnel Security Office regarding acceptance of the previous investigation and clearance level.
(1) If a new investigation is deemed necessary, the contractor and contracting officer will be notified by the respective DI Personnel Security Office after appropriate checks in DOD databases have been made.
(2) If the contractor employee requires access to classified information and currently does not have the appropriate clearance level and/or an active security clearance, the DI Personnel Security Office will relay this information to the contractor and contracting officer for further action.
(3) The contracting officer will ensure that the respective DI Personnel Security Office initiates the investigation for the required clearance level(s) of the contractor personnel.
(4) It is the contractor’s responsibility to ensure that adequate information is provided and that each contractor employee completes the appropriate paperwork, as required either by the contracting officer or by the DI Personnel Security Office, in order to begin the investigation process for the required clearance level.
The contractor is responsible for ensuring that each contractor employee assigned to the position has the appropriate security clearance level.
The contractor shall submit each request for IT access and investigation through the contracting officer to the assigned or cognizant DI Personnel Security Office. Requests shall include the following information and/or documentation:
(1) Standard Form (SF) 85, Questionnaire for Non-Sensitive Positions, or the SF 86, Questionnaire for National Security Positions Note: An investigation request is facilitated through use of the SF 85 or the SF
86. These forms with instructions as well as the Optional Form (OF) 306, Declaration for Federal Employment, which is required with submission of the SF85 or SF 86, are available at the Office of Personnel Management’s (OPM) system called Electronic Questionnaires for Investigations Processing (e-QIP).
Hard copy of the SF85 and SF86 are available at OPM’s web-site, www.opm.gov, but hard copies of the forms are not accepted.
(2) Proof of citizenship (i.e., an original or a certified copy of a birth certificate, passport, or naturalization certificate); and
(3) Form FD-258, fingerprint card (however, fingerprinting can be performed by the cognizant DI Personnel Security Office).
http://www.opm.gov/
Required documentation, listed above in paragraphs (f) (1) through (3), must be provided by the contractor as directed by the contracting officer to the cognizant DI Personnel Security Office at the time of fingerprinting or prior to the DI Security Office releasing the investigation to the Office of Personnel Management.
Upon completion of the appropriate investigation, the results of the investigation will be forwarded by the office performing the investigation to either the appropriate adjudication facility for eligibility determination or the DI Security Division for review and determination regarding the applicant’s suitability to occupy an unescorted entry position in performance of the DLA contract. Contractor personnel shall not commence work on this effort until the investigation has been favorably adjudicated or has been waived into the position pending completion of adjudication. The DI Personnel Security Office will ensure that results of investigations will be sent by the office performing the investigation to the Defense Industrial Security Clearance Office (DISCO) or DI Personnel Security Office.
A waiver for an IT-I or IT-II position to allow assignment of an individual contractor employee to commence work prior to completion of the investigation may be granted in emergency situations when it is determined that a delay would be harmful to national security. A request for waiver will be considered only after the Government is in receipt of the individual contractor employee’s completed forms. The request for a waiver must be approved by the Commander/Director or an authorized representative of the DLA organization for which the contractor will perform. The cognizant DI Personnel Security Office reserves the right to determine whether a waiver request will be forwarded for processing; however, there will be no waiver for an IT-III position.
The individual contractor employee for which the waiver is being requested may not be assigned to a position, that is, physically work at the Federally-controlled facility and/or be granted access to Federally-controlled information systems, until the waiver has been approved.
The requirements of this clause apply to the prime contractor and any subcontractors the prime contractor may employ during the course of this contract, as well as any temporary employees that may be hired by the contractor. The Government retains the right to request removal of contractor personnel, regardless of prior clearance or adjudication status whose actions, while assigned to this contract, who are determined by the contracting officer to conflict with the interests of the Government. If such removal occurs, the contractor shall assign qualified personnel, with the required investigation, to any vacancy.
All contractor personnel who are granted access to Government and/or Federally-controlled information systems shall observe all local automated information system (AIS) security policies and procedures as provided by the DLA site Information Systems Security Officer. Violations of local AIS security policy, such as password sharing, performing personal work, file access violations, or browsing files outside the scope of the contract, will result in removal of the employee from Government property and referral to the contractor for appropriate disciplinary action. Actions taken by the contractor in response to a violation will be evaluated and will be reflected in the contractor’s performance assessment for use in making future source selection decisions. In addition, based on the nature and extent of any violations of AIS security policy, the Government will consider whether it needs to pursue any other actions under the contract such as a possible termination.
The contractor is also required to obtain a Common Access Card (CAC) for each contractor employee in accordance with procedures established at the DLA HQ or field activity office. When a CAC is required, the contracting officer will ensure that the contractor follows the requirements of Homeland Security Presidential Directive 12.
Contractor personnel must additionally receive Operations Security (OPSEC) and Information Security (INFOSEC) awareness training. The DLA annual OPSEC refresher training and DLA annual INFOSEC training will satisfy these requirements and are available through the DI Security Office.
When a contractor employee who has been granted a clearance is removed from the contract, the contractor shall provide an appropriately trained substitute who has met or will meet the investigative requirements of this clause. The substitute may not begin work on the contract without written documentation, signed by the contracting officer, stating that the new employee has met one of the criteria set forth in paragraphs (c), (d), or (i) of this clause, (i.e., acceptance of a previously completed security investigation, satisfactory completion of a new investigation, or a waiver allowing work to begin pending completion of an investigation). Individuals removed from this contract as a result of a violation of local AIS security policy are removed for the duration of the contract.
The contractor shall notify the contracting officer in writing, within 12 hours, when an employee working on this contract resigns, is reassigned, terminated or no longer requires admittance to the Federally-controlled facility or access to Federally-controlled information systems. When the contractor employee departs, the contractor will relay departure information to the cognizant DI Security Office so appropriate databases can be updated. The contractor will ensure each departed employee has completed the DLA J6 Out-Processing Checklist, when applicable, for the necessary security briefing, has returned any Government-furnished equipment, returned the DOD CAC and DLA (or equivalent) badge, returned any DOD or DLA vehicle decal, and requested deletion of local area network account with a prepared Department of Defense (DD) form 2875.
The contractor will be responsible for any costs involved for failure to complete the out-processing, including recovery of Government property and investigation involved.
These contractor security requirements do not excuse the contractor from meeting the delivery schedule set forth in the contract, or waive the delivery schedule in any way.
The contractor shall meet the required delivery schedule unless the contracting officer grants a waiver or extension.
The contractor shall not bill for personnel, who are not working on the contract while that employee’s clearance investigation is pending.
The cognizant security office for this contract is DLA Intelligence at Richmond:
Mailing address:
DSCR
8000 Jefferson Davis Highway Richmond, VA 23297-5100 Attn: DLA Intelligence (at Richmond) Security Office
7.4 INSTALLATION SECURITY
CONTRACTOR ACCESS AND USE OF PREMISES
1. SECURITY REQUIREMENTS DEFENSE SUPPLY CENTER RICHMOND
(DSCR):
No employee or representative of the contractor will be admitted to the work site unless he/she furnishes satisfactory proof that he is a citizen of the United States or an alien who has been lawfully admitted for permanent residence, or who presents evidence from the Immigration and Naturalization Service that employment will not affect his immigration status.
Personnel Information: All authorized non-military personnel utilizing the base are required to have in their possession at all times an installation visitor pass or access control badge. This pass is issued by the DSCR Welcome Center, located at Building
210. The Welcome Center is open Monday through Friday except federal holidays from 6:30 a.m. to 4:30 p.m. In order to obtain pass/badge, the Contracting Officer or designee will request personal identifiable information (PII) from each contractor and submit it to Security a minimum of 7 working days prior to start of work.
Official Capacity: The contractor shall comply with visitor pass requirements for the performance of work at DSCR.
The DSCR Security Department will run a criminal history check on contractor employees as a condition of employment. Official proof of identity or naturalization papers may be required, which will be returned once entered into the security computer system. Based on the results of the criminal history check, the Vetting Official (VO) will or will not grant entry to the installation based on guidance set forth by the Installation Commander. If entry is denied, the contractor will be immediately notified.
DSCR Security may require updating or rechecking criminal history based on the duration of the contract.
Note: The VO will deny access to any person who the Installation commander has deemed unfit for unaccompanied access.
Proof of Identity: Official identification consists of any current Government issued picture identification. Examples- of official identification are valid state issued driver's license, military ID card, military dependent ID card, green card, etc. Expired identification is not valid.
Pass or Badge Management: Expired, invalid, inaccurate, inoperative or terminated Pass or Access Control Badge shall be returned to the Contracting Officer or his designee for disposition. These cards are the property of the U.S. Government and shall not be retained by the cardholder upon expiration, replacement, or when the DOD affiliation of the employee has been terminated. If the Pass or Access Control Badge is lost or stolen, a police report will be completed and a new request will be submitted by the Contracting Officer or designee. Compliance with this requirement is mandatory and certification thereof to the Contracting Officer is required prior to submitting final invoices. Failure to return badges will hold up contractor's final payment.
Contractor Security Responsibilities: The contractor is responsible for employees and subcontractors under their employment. Contractors will ensure that employees are familiar with and obey installation traffic, safety, and security regulations. Contractor employees, including subcontractors, are required to wear the ID card conspicuously on their outer clothing and above the waist at all times while working on this Center.
Personnel are subject to challenge and removal from the work area if the ID card is not being worn. It is the COR/designee’s responsibility to enforce this requirement.
Failure to do so is just cause for ordering that work on a contract be stopped.
Unofficial photography, cameras, or photographs are prohibited on DSCR property.
When official photographs are required, submit a written approval request containing specific justification and details to the Contracting Officer 5 days prior.
Firearms, Weapons, Alcoholic Beverages, Illegal Drugs, and Contraband are prohibited on DSCR property. Violators may be prosecuted. State issued/authorized concealed weapons permits are not valid on Federal (DSCR) property.
Trusted Traveler Program (TTP): Contractors are not authorized to use the TTP to escort individuals on to the installation.
DSCR is not responsible for job site security. Removal of material from job-site and Installation are subject to security checks. The contractor is to notify DSCR security of any special measures (watchmen, alarm, etc.), security concerns, security problems, or unusual activities within the job site.
2. TRAFFIC LAWS AND ENFORCEMENT:
Motor Vehicle Operation: Ingress and egress of personnel will be subject to the DSCR security regulations. All personnel must be made aware of the base speed limits which is 25 mph (unless otherwise posted). Speed limits are enforced and violators will be ticketed. DSCR traffic violations are processed through the federal court system.
Seatbelts are MANDATORY.
Use of cellphones while driving is prohibited.
Parking is in designated areas only, between two white lines. No parking is permitted in fire lanes, on seeded areas, in reserved parking slots, or assigned handicapped parking. Any equipment or vehicle that does not fit within a standard parking space must contact the Contracting Officer to determine a designated area for parking such equipment or vehicle.
Traffic accidents should be reported immediately to the DSCR Emergency Dispatch by calling 911 or (804) 279-4888 for non-emergencies.
All personnel entering the installation are subject to random vehicle inspections/searches at any time while on the Installation. The purpose of these inspections is to detect the theft of Government and private property, firearms, weapons, alcoholic beverages, illegal drugs, or contraband.
3. TRUCK DELIVERIES:
It is the contractors’ responsibility to notify the Contracting Officer of truck deliveries and escort trucks from the truck gate to its destination. This will not be done by DLA Police.
All commercial vehicles will enter the installation through the Commercial gate adjacent to the North Gate access control point (ACP). All commercial vehicles will also depart the installation via the North Gate. Commercial vehicles include, but are not limited to, semi-trucks, box trucks, passenger busses, cargo vans, dump trucks and walk-in vans. All such vehicles entering the gate will be processed through an entrance security inspection point before continuing onto the Installation.
Vehicle Inspection: Commercial/large vehicle inspections will be conducted on all vehicles by DLA police per the most current Police Standard Operating Procedure. The inspection may be upgraded based upon Force Protection Conditions (FPCON).
Shipment Validation: All deliveries to DSCR will have some form of identifying documentation.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.