IESS Attachment 1 - PWS 20240228.docx

DOCX document 196 KB Posted

Attached to
IESS/ECK Systems Support Services Federal contract opportunity
Solicitation number
SP470324R0004
Issued by
Defense Logistics Agency

About this file

This pre-solicitation notice is for indefinite delivery indefinite quantity contracts to provide Integrated Electronic Security Systems and Electronic Key Control Systems support services. The requirement is set aside for small businesses with a NAICS code of 561621 and size standard of $25 million. Multiple awards are anticipated. The solicitation number is SP4703-24-R-0004 and will be posted to SAM.gov on or around February 5, 2024. The Defense Logistics Agency is the contracting agency. Services required include life cycle program and project management, acquisition support, sustainment and maintenance for security systems. All inquiries must be submitted by email to the point of contact, Heesun Redmond, by the specified date. The contracting office address is provided.

View the file

Other files for this federal contract opportunity

Show all 18

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

INTEGRATED ELECTRONIC SECURITY SYSTEMS (IESS)

AND ELECTRONIC KEY CONTROL (EKC) SYSTEMS SUPPORT

PERFORMANCE WORK STATEMENT

DRAFT 20240228

1.0 BACKGROUND

Defense Logistics Agency (DLA) Information Operations (J6) executes program management responsibility through their Enterprise Capabilities Portfolio, Installation Support Program Management Office (PMO), providing enterprise-wide policy, program and worldwide operational support for DLA’s Integrated Electronic Security Systems (IESS) and Electronic Key Control (EKC) systems. The IESS is part of an overall physical security plan to maintain S24-7 operability to ensure continuous protection and monitoring of DLA facilities, personnel and property resources. The IESS is used in areas where controlled or restricted physical access is needed to safeguard DLA’s critical resources, which could include Arms, Ammunition and Explosive (AA&E) storage areas, sensitive or classified equipment storage areas, areas processing, transmitting and/or storing classified information, and other related scenarios. The DLA IESS consists of several systems which may include Access Control Systems (ACS), Facility‐Related Physical Access Control Systems (PACS), internal and external Closed-Circuit Television (CCTV) systems, Video Surveillance Systems (VSS), Network Video Recording (NVR) devices, interior and exterior Intrusion Detection Systems (IDS), Data Transmission Media (DTM) systems (a means to communicate information internally and externally to DoD sites) and provision of local or regional dispatch centers/security command centers. In addition to the IESS, DLA has a requirement to support Electronic Key Control (EKC) systems.

DLA Installation Management, Security and Emergency Services (DM-S) is the functional proponent for DLA’s ESS and EKC. These systems are currently operated and managed on a site-by-site basis with the hardware and software products, design, integration, maintenance, and acquisition lifecycle support provided through DLA Contracting Services Office (DCSO) and through several different Government acquisition offices outside of DLA. Many of DLA’s disparate ESS and EKC systems are legacy systems with outdated software versions and maintenance fragmented across the Agency, creating uneven levels of support in the event of system outages or equipment degradation. The overall goal of this requirement is to provide acquisition lifecycle management support for all DLA ESS and EKC systems so that the Portfolio/PMO have centralized management to consolidate and standardize the ESS and the EKC efforts. By taking an integrated approach to support these security systems, the DLA will gain efficiencies across ESS and EKC programs and provide the necessary services to comply with DoD security guidance and improve DLA’s ability to protect property and people. At this time, DLA is not planning to implement an ESS or EKC solution to integrate all DLA sites into one centralized system; therefore, the ESS and EKC systems at the DLA sites will continue operating on a site-by-site basis until a consolidated approach becomes possible.

2.0 SCOPE

This Performance Work Statement (PWS) is for an Indefinite Delivery Indefinite Quantity (IDIQ) contract with Task Orders (TOs) supporting Life Cycle Program/Project, Acquisition and Customer support for the DLA ESS and EKC systems at the DLA-hosted installations, the DLA Headquarters Complex (HQC) as well as other DLA facilities at various locations throughout CONUS and OCONUS (see Table 5). DLA maintains ESS and EKC systems at locations where DLA activities are tenant organizations. Some DLA locations also have additional sub-site locations (remote sites). The ESS and EKC systems at these locations are often integrated with the military service host’s ESS or EKC system but in some cases are stand-alone systems. The ESS and EKC systems at the DLA locations will be evaluated by DLA on a case-by-case basis to determine if that site can be executed/supported under this requirement.

This requirement includes support for the DLA ESS and EKC systems described below. Depending on the requirements at the specific DLA location, some systems are integrated, and some are separate systems. The TO PWS will provide details including but limited to the system type, product brand, current/desired network configuration (DLA Production, Operational Technology (OT), Test Development (T&D), or other DLA network) and other details as required.

· ACS monitors/controls access to areas and logs activities. It includes electric locks/card readers, biometric readers, door contacts, request-to-exit devices, intercom devices with integration for access requests/door release, security controllers, and server(s), database, software and workstation(s) for system configuration, enrolling authorized users, monitoring and running reports.

· IDS provides alarm monitoring and protection to secure areas. It consists of sensors, local processors, arm/disarm devices, duress buttons/switches, data transmission infrastructure, and server(s), database, software and workstation(s) for system configuration and monitoring or integration into the ACS system. Alarm monitoring is projecting for the DLA host sites, HQC and other locations with DLA-owned IDS (vice using their host site’s IDS). Locations with DLA-owned IDS require alarm monitoring with Federal Agency to respond only, no requirements for local municipality response.

· PACS includes Installation Entry Control (IEC) systems which are part of the installation or facility perimeter defense and may consist of vehicle pop‐up barriers, mantraps (entry portals), entry gates (both vehicle and pedestrian (turnstiles)), rejection/holding areas, lighting, and messaging/way finding signage. All PACS/IEC must comply with relevant UFCs and DoDM 5200.08, Volume 3. These systems can be self-contained or can be integrated with existing ESS to enhance ACS/IDS/CCTV functionality, based on local site requirements.

· CCTV/VSS monitors, records and stores video. It consists of cameras, Network Video Recorders, server(s), storage devices, streamers, switches, keyboards, and software, workstation(s) and displays for central monitoring that allow viewing and recording of security events.

· DTM systems provide a means to communicate status and alarm information internally and externally to DoD sites and provision of local or regional dispatch centers/security command centers.

· EKC systems automate the key control process and provide physical control over keys, combinations, pins and codes for locks, doors, facilities and other locking mechanisms. It consists of a secure steel container and server(s), database, workstation(s) and software to alert security personnel when preset parameters exist.

When applicable, the TO PWS will indicate whether the DLA will provide ESS software licenses and associated support plan products for those licenses from the DLA Enterprise ESS Software Blanket Purchase Agreement (BPA), which includes for Lenel ACS/IDS products and Milestone CCTV/VSS products. The Contractor shall have established reseller relationships with Lenel and Milestone manufacturers. Additional information and specific products numbers for ESS Software BPA are available from the J6 Contracting Officer’s Representative (COR)/ Contracting Officer’s Technical Representative (COTR) upon request. Otherwise, the Contractor may be required to provide products and support for existing products already in use at a site.

Table 1 – ESS and EKC Systems. The table below identifies the different ESS and EKC products currently in use at the DLA locations, including but not limited to:

Current ACS, IDS, CCTV/VSS, EKC and Intercom Systems/Products

ACS and IDS:

1. Lenel On-Guard

1. AMAG

1. Honeywell Enterprise Building Integrator, Rapid Response

1. IQ MultiAccess

1. BOSCH

1. LG

1. DAQ Electronics

1. DEA System SPA

1. Honeywell Vindicator IDS

1. Hirsch Electronics

Intercom: AIPHONE

CCTV/VSS:

1. Bosch

1. Honeywell DVM

1. Valerus

1. Pelco

1. Lenel OnGuard

1. IDIS

1. Panasonic

1. Axis Communication

1. Milestone

EKC:

1. Global Facilities Management System (GFMS)

1. Morse Watchman Key-Pro III, KeyWatcher, TrueTouch

1. KeyTrak Guardian

1. Stanley Security Solutions Keystone 600N5

1. Matrix Key Control

The Contractor is expected to provide on-site support as required but, in some cases, may be able to perform diagnostics and support from remote locations when this technique speeds the response or otherwise proves time and cost effective (remote connections are in accordance with (IAW) DLA procedures and are subject to cybersecurity Certification and Accreditation (C&A) requirements). The Contractor shall obtain approval from the J6 COR/COTR for this in advance.

A COR and/or COTR will be designated for the IDIQ contract. Each TO will have a COR and/or a COTR designated from either DLA J6 or DM and the TO PWS will detail the COR/COTR roles as point of contact or deliverables recipient.

The Contractor shall provide support IAW with applicable policies, procedures and statutes listed in PWS 19.0 References and/or throughout the PWS.

3.0 TASKS

The Contractor shall provide support for the task areas listed below. All TO(s) issued will be performance-based acquisitions utilizing a PWS. The specific scope of each effort will be based on the specific tasks to be set forth in individual TO(s), but may include tasks in one or more of the following areas below. Task 6 will be included on every TO that has cybersecurity requirements.

· Task 1 - Project Management Support

· Task 2 - ESS Design Support

· Task 3 - ESS Acquisition and Build Support

· Task 4 - EKC Design, Acquisition and Build Support

· Task 5 - ESS and EKC Sustainment and Maintenance Support

· Task 6 - Cybersecurity Support

3.1 Task 1 – Program/Project Management Support

The Contractor shall provide various program and project management support for the IDIQ and TOs. This support includes providing planning, direction, coordination, control, monitoring, and reporting necessary for effective and efficient accomplishment the PWS requirements. The Contractor shall provide support for contract matters; senior subject matter expert; management of contract personnel; reporting on status on cost, schedule, performance and risk; collaboration with the COR, COTR, PMO, and DLA technical, functional, and user representatives; managing contract deliverables; and other support as needed. The program and project manager shall be available as required Monday through Friday, excluding Federal holidays, during business hours. Upon request of the Contracting Officer (KO) or COR/COTR, the Contractor shall provide personnel to meet at the DLA site location as required to discuss problem areas.

3.1.1 Project Plan/Schedule

The Contractor shall provide and maintain an Integrated Master Schedule (IMS) showing outlining significant milestones and timelines for all TOs awarded to the Contractor and an individual schedule for each TO. Contractor shall submit to COR/COTR for duration of IDIQ or TO POP.

The Contractor shall provide a TO project schedule as a comprehensive, implementable timeline that aligns with the approach in the technical proposal including as applicable significant milestones for design, deployment and installation, testing, sustainment and maintenance, and activities related to cybersecurity compliance for certification and accreditation. The Contractor shall create, submit, and maintain/update project plan(s)/schedule(s) including Work Breakdown Structure (WBS), communication and escalation plan/procedures, maintenance/sustainment, upgrades, installations, or replacement of device(s) and or application(s). Microsoft Project is the preferred software/format for project plans/schedules. Project plans/schedules shall include Task ID, Task Name, Baseline Start, Baseline Finish, Actual Start, Actual Finish, % complete, resource name/title, with the critical path defined utilizing predecessors and/or successors.

3.1.2 Meetings

The Contractor shall coordinate a post award Kickoff meeting prior to the initiation of work on a TO and conduct monthly In Process Review (IPR) meetings and provide minutes. These meetings will be held with the Contractor, KO, Contract Specialist (KS), COR, and COTR to discuss an overview of Contractor’s plans to manage scope, schedule, and resources. The Contractor will discuss stakeholders’ expectations, details of contract execution including incident management, triage support, technology road map plans including current and future software/hardware landscape, general conditions, project schedule/plan, work schedules, coordination, security, safety, deliverables, permits, and other matters pertinent to work accomplishments shall be discussed in this meeting. Contractor shall attend other meetings and provide minutes as required in support of contract tasks for the TOs and/or the IDIQ.

3.1.3 Status Reports

For the IDIQ contract, the Contractor shall provide a monthly report with overall status and financials for all awarded TOs. For each TO, the Contractor shall provide a monthly status report to the COR/COTR. Status report shall include TO/project description, work accomplished, planned work, potential problems or issues that may affect ability of the Contractor to perform, whether Contractor is on schedule and percentage complete, financials, and other related items. The Contractor shall inform the COR/COTR immediately if an issue arises that affects the performance or continuance of work.

3.1.4 Staffing

Contractor shall maintain a certified work force to complete work IAW the time and quality standards specified. The Contractor shall provide fully qualified personnel with the necessary management expertise, training, and certifications to assure the performance of the work is in accordance with sound and efficient management practices. Contractor shall provide a monthly Contractor Tracking Report listing all personnel working on the contract/TO and various administrative information (template will be provided by J6 COR/COTR).

3.1.5 Phase-In Training

A phase-in period shall be established to allow the Contractor sufficient time to integrate personnel and transition into duties required to perform the requirements of the contract and ensure employees who will require access to the Installation and DoD Information Technology (IT) systems obtain a Common Access Card (CAC) IAW PWS. Instructions for all Phase in Training are available upon request.

· The phase-in period shall begin at the effective date of the TO and shall not exceed one (1) month, at which time full performance shall commence.

· The Contractor shall ensure that all Contractor personnel are ready to begin working on the first day of full performance including obtaining any account access, permissions, and/or roles required to administer the application software/hardware. Training and documentation such as rules of behavior and cyber awareness are required for accesses.

· During the phase-in period, Contractor personnel shall complete security and safety training on site. Training will be scheduled through the DLA site’s training office and will at a minimum include the following classes. Estimated time to complete is three (3) hours.

· Active Shooter Briefing

· Safety Briefing

· Shelter in Place/Evacuation Awareness Briefing

· During the one-month phase-in period ensure all Contractor personnel know and understand regulations and policy pertaining to physical, information, operations, and personnel security. The Contractor shall provide security and antiterrorism training to all employees in accordance with applicable DoD regulatory requirements. Training, as required by the DLA Issuances and other applicable DoD guidance, will be completed annually for the following on-line training.

· Cyber Awareness Challenge

· Safety Briefing

· Shelter in Place/Evacuation Awareness Briefing

· Antiterrorism (AT) Level 1

· Operations Security (OPSEC)

· Counterintelligence Awareness Training

· Personally Identifiable Information Awareness

· Trafficking in Persons

· The security training is web-based, and access will be provided by the Government. The Contractor shall ensure Contractor personnel have taken the required security training to meet DoD guidance and that the personnel continue to maintain their certifications. The Government may add, delete, or change the annual training requirements.

· The Contractor shall provide status and confirmation of completion of Phase-In tasks/training in the TO Status Report and provide certificates as needed.

3.1.6 Work Effort and Control

The Contractor shall manage total work effort to assure timely completion items including, but not limited to planning, developing, and implementing project plans, scheduling, report preparation, communication and coordinating with stakeholders, escalation procedures, establishing and maintaining records, monitoring, and quality control. The Contractor shall implement all necessary work control procedures to ensure timely accomplishment of work requirements, as well as to permit tracking of work in progress. The Contractor shall plan and schedule work to assure material, labor and equipment of all contracted items are available to complete work requirements within the specified time limits and in conformance with the quality standards.

3.1.7 Work Schedule

The Contractor shall schedule and arrange work to cause the least interference with the normal occurrence of DLA business and mission. In those cases where some interference may be essentially unavoidable, the Contractor shall make every effort to minimize the impact of the interference, inconvenience, equipment downtime, interrupted service, and/or customer discomfort. Non-scheduled visits will be coordinated with the COR/COTR in advance and notify the COR/COTR if the work being performed may cause interference. Notification shall include the type of work to be done and the estimated completion date/time. The Contractor shall reschedule any work that the KO/COR/COTR deems necessary to avoid unacceptable disruptions in the Government's business.

3.1.8 Work Records/Reports

The Contractor shall maintain management, maintenance, repair records, and reports. All records and copies of reports shall be turned over to the COR/COTR.

3.1.9 Enterprise Configuration Management

The Contractor shall adopt DLA Enterprise Configuration Management ensuring all hardware and software changes are approved by the J6 COR/COTR. The Contractor shall use the DLA Business Capability Management (BCM) ServiceNow (or the current DLA system in use), Change Implementation Plans (CIPs), and provide technical expertise to develop Enterprise Change Requests (ECRs) that addresses product management and version control for software (changes) and hardware (changes). The Contractor shall support DLA business processes documentation such as Scheduled Maintenance Requests and Information Technology Operations Center (ITOC) notice (INFOSPOT) and all other control items such as customer notifications. The Contractor shall evaluate all changes to the approved system requirements baseline for risk to security, and for schedule and cost impact, provide evaluations in writing and with sufficient detail to allow for review and approval by the configuration governance structure as required.

3.1.10 Configuration Audit

In support of configuration management, the Contractor shall conduct a configuration audit is conducting an inventory of all existing hardware, software, drawings and technical documentation. The Contractor shall recommend the criteria to be collected to the COR/COTR for approval. The Contractor performs the initial configuration audit, provide this information to the Government in an agreed upon format and perform updates to that as needed. The Contractor shall report the completed updates in the status reports.

· Validate and maintain the inventory of system hardware.

· Validate and maintain an inventory of all system software, license information, versions, system and security patches.

· Review and validate technical drawings. The Contractor shall redline drawings to indicate the actual configuration of the system, subsystem, equipment, device, or component. The Contractor shall have updated all as-built drawings 30 days before the completion date of the task.

· Validate the existence of technical manuals as part of Preventive Maintenance. Replace or update any manuals that are outdated or nonexistent.

· Summarize actions taken to validate and update drawings and technical documentation as part of the Contractor’s monthly status report to the government.

3.1.11 Transition Support

The Contractor shall provide knowledge transfer to Government and any follow-on provider to include all necessary documentation for landscape and assets, orientation, collaboration, status of any work planned or in-process, lessons learned, and recommendations, and training to facilitate the comprehensive understanding and execution of tasks, processes, procedures, schedules, and deliverables. Contractor shall provide a plan and schedule for all transition activities to COR/COTR for approval to ensure continuity and continuation of services without interruption.

3.1.12 Accident Prevention Plan

The Contractor shall provide Accident Prevention Plan to the COR/COTR as listed in the TO PWS. No work shall start prior to COR/COTR receiving the approved Accident Prevention Plan. Contractor shall provide IAW PWS 6.1.2.4 Deliverables & Performance Tables, Table 2: Contract Deliverables.

3.2 Task 2 - ESS Design Support

The contractor shall provide design and engineering support (to include surveys if required) for ESS (ACS, IDS, PACS, and CCTV/VSS systems) to include lifecycle replacements, expansions, upgrades, new installations and other related requirements. The Government’s overall functional and technical requirements are listed in this section. The Government’s specific requirements and location(s) will be detailed in the TO PWS.

The Contractor shall ensure their design solution and recommendations meet all requirements in order to be installed on a DLA network IAW all applicable cybersecurity policies, procedures and statutes. The Contractor shall follow all National Electrical Code (NEC), Unified Facilities Criteria (UFC), National Fire Protection Association (NFPA), Security Technical Implementation Guides (STIGs), Data Encryption standards, Intelligence Community Directive (ICD/ Intelligence Community Standard (ICS) 705, DLA Physical Security Manual and DLA building codes and National Defense Authorization Act (NDAA). The Contractor shall obtain DLA approval for their design through technical reviews. The Contractor shall provide a design plan/Technical Data Package (TDP) that includes a narrative describing their recommended solution, schematics (drawings, network/system diagrams, data flows and other related items), list of all required material items (to include the use of any government-furnished software), delivery schedule, implementation plan/schedule and any other pertinent information. When requested, the Contractor shall provide a Rough Order of Magnitude (ROM) Cost Estimate for all labor and materials that would be required in order to implement the design.

The Contractor shall identify all Government-furnished items in their TDP, such as government-furnished servers, clients, and other items IAW specifications in PWS 3.6 Task 6 - Cybersecurity Support. When possible, the Contractor shall use/incorporate the government furnished Lenel ACS/IDS products and Milestone CCTV/VSS products (from the DLA Enterprise ESS Software BPA) in their design plan. In scenarios where that is not possible, the Contractor shall use other ESS software (already in use at their site) for their design. The Contractor shall get approval for this in advance from J6 COR/COTR.

The Contractor’s TDP shall identify all Commercial off the Shelf (COTS) products (hardware, software and other materials) needed to fulfill the Government’s requirements. The Contractor shall identify and provide a detailed list of all existing equipment and software that is compatible and could be reutilized. As applicable, the Contractor shall provide a list of all existing items to be removed and disposed.

3.2.1 The Contractor shall provide overall design solutions for DLA ESS systems that are IAW the criteria listed below.

3.2.1.1 Overall Hardware/Device Requirements.

· Data shall be encrypted at rest using the National Institute of Standards and Technology (NIST) Federal Information Processing Standard 140-2 (FIPS 140-2).

· Devices shall have ability to be updated real time when changes occur (updates, password protect, and other applicable situations.) as a whole, not individually.

· Transaction data shall be secured at Service Station pedestals, handhelds or during data transfers.

· User shall not be able to manipulate, update or change data once a transaction has been completed.

· Systems shall have an alternate method for obtaining data in the event that the communication link is broken.

· All direct interfaces with computers shall meet all IT/ OT and cybersecurity requirements in PWS 3.6 Task 6 - Cybersecurity Support (these specifications may be updated during the IDIQ POP and will be included in the TO PWS).

· Systems shall be able store 3 days of data in the event that communications have failed.

· Contractor-furnished software shall be compatible with the server and client workstation specifications listed in PWS 3.6 Task 6 - Cybersecurity Support.

3.2.1.2 Custody Transfer Device Requirements

· Capability to transmit transactional data IAW data transfer standards for information integrity assurance.

· Utilizes current industry best practices to meet the DLA needs and consists of established commercial items having documented commercial installation history and performance records, which demonstrate the system has a proven record of reliable field performance.

· Supports Audit Readiness and DoD reporting requirements for validation of source media and transactional integrity by authenticating against the enterprise repository.

· In the event that authentication does not occur within 15 seconds the device will failback to authenticate against a self-contained blacklist.

· Provides secure data transfer technology that meets DoD/DLA IT/OT security standards.

3.2.1.3 Environmental Requirements

· Equipment must meet or exceed environmental conditions at the specific site location where it is installed.

· Waterproof: The device shall control and mitigate degradation of its effectiveness, reliability and maintainability due to exposure to rain, water spray, ice, humidity, or dripping water during storage, transit, or operation.

· Sand and Dust: The device shall resist the effects of sand and dust obstructing openings, penetrating into cracks, crevices, bearings, and joints degrading its effectiveness, reliability and maintainability due to abrasions or clogging.

· Visibility: The device screen (if applicable) shall be easily viewable in low light and high glare environments.

· High Temperature: 120 Degrees F Radiant, Low Temperature: 0 Degrees F ambient

· Devices deployed in locations where the environment exceeds the operating range shall have the capability of adding a Contractor provided retrofit of heating and cooling mechanisms.

· Retrofitted equipment shall not change the Intrinsically Safe rating of the device.

· High temperatures in some environments may exceed 120 degrees Radiant and may fall below 0 degrees.

3.2.1.4 Electronic Communication Requirements

· All communications shall be secured in transit using the NIST FIPS 140-2.

· The device shall electronically transmit captured transactional data as required.

· All transmissions shall occur in the background and not prohibit the continued use of the device.

3.2.1.5 Key Performance Parameters

· Accuracy and Availability - The system should employ numerous data/availability quality assurance techniques, including but not limited to: Time stamped events/alarms, 98% system availability/up-time, daily data/system backups. The system must be available 24 hours per day, 365 days per week with the exception of scheduled and pre-notified system maintenance downtimes.

· Capacity Limits (User, Data, Physical) - The ESS per site user capacity licenses/clients vary based on staffing. The ESS software must be capable of supporting a range of 1 to 1,000 ESS hardware components at a single site and a range of 1 to 300 users at a single site. It must also be able to incorporate at least an additional 25% expansion capacity for scalability (i.e., a system designed to support 100 users must support expansion to 125 users without major overhaul).

· Failure Contingencies - Minimum requirement for ESS component backup power is 8 hours (i.e., battery, generator, Uninterrupted Power Supplies (UPS), or a combination of these) with an automatic transfer switch to prevent system loss and rebooting. Emergency backup power will not generate the requirement for generator or UPS.

· In the event of power loss and the ESS hardware is unable to regain power, the ESS hardware must fail in the secure mode. Additionally, an offline manual functionality must be available in the event of long-term power loss.

· CAC + Pin enabled access for users (vice username/password or card swipe). Due to government restrictions associated with the use of CAC, CAC readers will be supplied by the government. DLA J6 group has the responsibility to determine the method for installation and confirmation of proper function.

3.3 Task 3 - ESS Acquisition and Build Support

3.3.1 The Contractor shall furnish all required materials, hardware and software (not government-furnished) and provide deployment, implementation and integration support for DLA ESS systems for lifecycle replacements, expansions, upgrades, and new installations IAW an approved TDP and/or specifications listed in the TO PWS. When listed in the TO PWS, DLA may furnish the server and client workstation hardware/operating system, IAW PWS 3.6 Task 6 – Cybersecurity Support, and may also furnish Lenel ACS/IDS products and Milestone CCTV/VSS products (from the DLA Enterprise ESS Software BPA). The Contractor shall coordinate with J6 COR/COTR for any government-furnished items (servers, workstations, ESS Lenel and/Milestone software) in advance of deployment. The Contractor shall present any deviations or recommendations to the KO, J6 COR/COTR for approval. The Contractor shall submit proposed hardware and software list by the J6 COR/COTR for approval prior to any procurement and installation.

3.3.2 The Contractor shall install all ESS hardware and software, as indicated in the TDP and/or listed in the TO PWS. The contractor shall provide technicians certified for the ESS hardware/software, when specified in the TO PWS. All contract personnel requiring elevated/privileged access to any system or the network, either during provisioning or post award, shall meet the requirements listed in PWS 3.6 Task - Cybersecurity Support.

The Contractor shall complete all support activities necessary to prepare the physical site for the installation work to ensure the electrical, patch cable connectivity and other applicable items are adequate to support the TDP and/or specifications listed in the TO PWS. The Contractor shall submit their recommendations for any modification requests to the physical site to the J6 COR/COTR for approval. The contractor shall obtain all applicable permits, access (including off-base easements and leases), agreements, licenses and certificates required to perform and complete the project. The Contractor shall comply with all applicable permit conditions and shall provide a copy of the permit to COR/COTR and keep all permits current until the work is complete.

The Contractor shall turnover a complete and fully operational system to the Government. The Contractor shall complete all required actions/support and provide all required documentation IAW PWS 3.6 Task 6 - Cybersecurity Support in order for the DLA to obtain a favorable cybersecurity assessment for the system.

3.3.3 Configuration Management

The Contractor shall follow the DLA Configuration Management (CM)/ Configuration Control Working Group (CCWG) process to address product management and version control for software (changes), hardware, business processes documentation and all other control items; and recreate all baseline deliveries from any point in time. The Contractor shall support the Configuration Control governance structure; evaluate all changes to the approved system requirements baseline for risk to security, and for schedule and cost impact; provide evaluations in writing and with sufficient detail to allow for review and approval by the Configuration Control governance structure as required.

3.3.4 Systems Engineering

The Contractor shall provide engineering expertise to integrate the technical efforts described in the TO PWS related to the design, testing, configuration, implementation and sustainment of the system baselines and their life cycles. The Contractor shall follow all National Electrical Code (NEC), Unified Facilities Criteria (UFC), National Fire Protection Association (NFPA), Security Technical Implementation Guides (STIGs), Data Encryption standards, ICD/ICS 705, DLA Physical Security Manual and DLA building codes and National Defense Authorization Act (NDAA). Contractor shall not turn off any power for an outage unless authorized by COR/COTR. The Contractor is required to provide a written request to the COR/COTR at least 14 days in advance of any required outages and for any after duty hour work requirements.

3.3.5 System Deployment, Installation/Configuration

The Contractor shall develop and provide an Implementation Plan to the COR/COTR for approval. The Contractor shall provide installation and configuration support for the ESS system(s) to include but not limited to implementing hardware, software, infrastructure, cabling and any other related items; address issues with systems interface/integration, compatibility and platforms; recommend changes for approval by the J6 COR/COTR; resolve problems; and work with project teams and end users to ensure system meets requirements and is functioning properly.

3.3.6 The Contractor shall provide support for this task IAW the criteria below as well as the criteria listed in the subsequent paragraphs.

· The Contractor shall install, and de-install hardware and software as required to ensure consistent and reliable service.

· The Contractor shall ensure that all installations shall include appropriate functional verifications to ensure serviceability and documentation IAW DoD and DLA policies and regulations.

· The Contractor shall provide recommendations for detail and direct coordination of testing activities on all ESS systems.

· The Contractor shall assign, report and mark applicable ESS property IAW DoD Federal Acquisition Regulation Supplement (DFARS) 252.211-7007 Reporting of Government Furnished Equipment in the DoD Item Unique Identification (IUD) Registry.

· The Contractor shall support records being maintained IAW DLA Records Schedule, Schedule 6055; Rules 12, 14, 25, 26, 30, and 49.

· The Contractor shall configure and make the system(s) operational.

· The Contractor shall provide help desk support to DLA during deployment and configuration of ESS Systems.

3.3.7 The Contractor shall establish and configure Central Monitoring Capabilities IAW the following criteria:

· Enables clients/capability specific to monitoring/acknowledging intrusion alarms, viewing video surveillance/multiple video streams/simultaneous camera images, and video playback/retrieval.

· Supports alarm printing.

· Provides CCTV/Alarm interface where available for situational awareness to Dispatch/First Responder personnel.

3.3.8 The Contractor shall install and configure ACS Capabilities IAW the following criteria:

· Supports any and all ACS components which may include electric locks/card readers, biometric readers, door contacts, request-to-exit devices, intercom integration for access requests/door release, and client workstations for enrolling authorized users and running reports.

· All ACS equipment must comply with HSPD 12 and FIPS 201-2 and be included on the FICAM FIPS 201 Evaluation Program Approved Product List (APL).

· Supports badging and enrollment capabilities for DoD and non-DoD credential holders, which includes functionality for electronically enrolling individuals in the ACS and issuing ACS-compatible badges for additional access.

· Supports ACS scalability to allow enrollment of the required number of users and the required number of hardware components.

3.3.9 The Contractor shall install and configure CCTV/VSS Capabilities IAW the following criteria:

· Supports all CCTV/VSS components, which may consist of cameras, video recorders, streamers, switches, keyboards, and monitors that allow viewing and recording of security events.

· CCTV/VSS must be capable of integrating with ACS/IDS (i.e., slew-to-cue/rapid alarm assessment).

· Supports ability to process live video streams and recording capability for all the cameras per site.

· Cameras must be capable of recording at least 15 frames-per-second (FPS) for forensic cameras and 24 FPS for cameras used for continuous monitoring.

· Supports a minimum of 30 days of video footage storage and scalability to support additional storage if required by the site. Camera solutions to meet a wide variety of environments/operational needs (outdoors, indoors, low light, fixed, PTZ, dome, bullet, high definition, infrared, 360/180 degree coverage, IP, ONVIF).

· Solutions must support camera monitoring at central dispatch/security operations center or locally at camera’s location.

3.3.10 The Contractor shall install and configure Intrusion Detection Capabilities IAW the following criteria:

· Supports any or all IDS components, which could consist of sensors, local processors, arm/disarm devices, duress buttons/switches, data transmission infrastructure, and workstations for monitoring.

· Communicate/report to an installation central monitoring location for alarm annunciation, monitoring, acknowledgment, and response.

· Supported sensors must include balanced magnetic switch(s) (BMS), passive infrared (PIR), acoustic, and vibration.

· Ability to detect intruders through a variety of deployed sensors.

The IDS for DLA Sensitive Compartmented Information Facilities (SCIFs) must comply with all requirements in ICD 705 and Underwriters Laboratories (UL) 2050. Installation shall comply with an Extent 3 installation as referenced in UL 2050, and all system components and elements shall be installed IAW requirements of ICD 705, UL 2050, and manufacturer’s instructions and standards. Upon completion of the work, a UL 2050 Certification must be provided. Installation and testing within the U.S. shall be performed by U.S. companies using U.S. citizens. Line security must be performed to NIST FIPS Advanced Encryption Standard (AES) encryption. Repairs shall be initiated by a service technician within 4 hours (or as required in the TO PWS) of the receipt of a trouble signal or a request for service for the duration of the TO POP. Additionally, the system hosting the IDS shall be issued Authority to Connect (ATC) by the agency Authorizing Official (AO), following the Federal Information Security Management Act (FISMA) Risk Management Framework (RMF) as outlined in NIST Special Publication (SP) 800-53. DLA is projecting UL-2050 monitoring requirements at mainly the four DLA-hosted locations and HQC and there may be a few DLA tenant locations that may require this. For those locations with UL-2050 monitoring requirements, only Federal Agency response is used, there is no local municipality response required. References:

· Technical Specifications for Construction and Management of Sensitive Compartmented Information Facilities, Version 1.3, IC Tech Spec‐for ICD/ICS 705, September 10, 2015.

· Underwriters Laboratories (UL) Standard for National Industrial Security Systems for the Protection of Classified Material, UL 2050.

· NIST Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, April 2013.

3.3.11 The Contractor shall configure Physical Access Control Systems (PACS) IAW the following criteria:

· Support installation or facility perimeter defense using vehicle pop‐up barriers, mantraps (entry portals), entry gates (both vehicle and pedestrian (turnstiles)), rejection/holding areas, lighting, and/or messaging/way finding signage.

· All PACS and Installation Entry Control systems must comply with relevant UFCs and DoDM 5200.08, Volume 3.

· Operate self-contained or integrated with existing ESS to enhance ACS/IDS/CCTV functionality based on TO requirements.

3.3.12 The Contractor shall configure Reporting/Notification Capabilities IAW the following criteria:

· Ability to generate system, alarm, access, and user activity reports.

· Ability to print and send reports electronically.

3.3.13 The Contractor shall configure System Access Capabilities IAW the following criteria:

· Workstation/Mobile Access to include use of tablets other IT devices for monitoring and notification.

· Remote access capability for system notifications not for system configuration changes.

3.3.14 Interface/Integration. The contractor shall coordinate with external and internal entities (the host site organizations, DLA J6 or other DLA organizations) that require interfacing or integration; identify, configure, integrate and test necessary interfaces with external and internal systems; develop interface test integration requirements, strategies, devices and systems; participate in integration testing; and resolve problems. The Contractor shall develop Interface Control Documents, as required. As required, the Contractor shall work with the local site Fire Alarm/Fire Suppression systems POC to connect the existing fire control relay at the site location to the new ESS IAW National Fire Protection Association (NFPA) 72.

3.3.15 Testing. The Contractor shall provide a Test Plan and Migration Plan to keep the existing ESS system active and available during the installation and migration of the new system. The Contractor shall submit a complete test plan, which shall detail all steps to ensure the system, is properly working and meets all of the requirements in the PWS. The Contractor shall test to ensure system requirements are met; develop and maintain test scripts and architectures for application products; write, implement and report status for system test cases; analyze test cases and provide regular progress reports; provide testing procedures for the support of user requirements in applications; provide input to risk management assessments on test design and test tools selection, and all test results to the COR/COTR. The Contractor shall support Section 508 testing, unit testing, integration testing, system testing, regression testing, performance testing, user acceptance testing, and security testing as required to ensure that the solution fully supports existing and proposed functionality. The Contractor shall perform acceptance testing on all applicable items in IAW UFGS 28 08 10, Electronic Security System Acceptance Testing, and witnessed by the COR/COTR. The Contractor shall provide documentation of all testing completed to the COR/COTR for review and approval.

· As required, Section 508 Testing. Testing of enterprise Web applications shall ensure compliance with Section 508 of the Rehabilitation Act Amendment of 1998, which requires Federal agencies acquiring electronic and information technology to ensure that Federal employees with disabilities have access to and use of information and data that are comparable to the access and use by Federal employees who are not individuals with disabilities. IT products and services developed in response to a Task 2 TO PWS are required to comply with Section 508 standards (available on the U.S. Access Board Website at: www.access board.gov/508.htm) and the Federal Acquisition Regulation (FAR) both Subpart 7.103 and Subpart 39.2. The tools required by the DLA CIO include e.g., JAWS, Zoom Text, Dragon Naturally Speaking, and Kurzweil.

· Unit Testing. The Contractor shall conduct unit testing on multiple code modules or components to execute the entire series of events surrounding a development object or configured transaction. The test shall include the transactions, the flow of data from the source system to the destination system through the architecture, and the completion of the developed actions in the destination system. The Contractor shall also test all system equipment to ensure proper functionality is occurring with the software.

· Integration Testing. The Contractor shall conduct Integration testing that combines and tests units to expose problems with the interfaces among solution components. All interfaces and integration of system components will be tested, and problems or issues will be resolved to ensure a fully functioning system.

· System Testing. The Contractor shall conduct a system test that involves performing a formal end-to-end test of business processes using a series of controlled test cycles, test plans, test cases, configured test cases, and data sheets. The system test confirms interoperability between systems (interface testing), test objects, verifies that new system functionality does not adversely impact existing system functionality and confirms security profiles for each job and role. This tests the solution at the business transaction level to ensure that all business events can support DLA’s mission and that end-to-end business processes function properly. The Contractor shall identify, document and resolve defects. The Contractor shall develop the documents and components that support the execution of system test, including test passes, test cycles, test plans, test cases, configured test cases, and data sheets.

· Regression Testing. The Contractor shall conduct regression testing that involves retest of all existing functionality to verify new release functionality that does not adversely impact existing functionality.

· Performance Testing. The Contractor shall verify that the production system is capable of handling production-level user and transaction volumes while maintaining pre-determined system performance requirements. The Contractor shall assess the performance characteristics of the hardware and software to manage risks by identifying performance issues as early as possible.

· User Acceptance Testing. The Contractor shall conduct user acceptance testing that will be facilitated by end-users, partnered with functional analysts, to provide confirmation that the product is ready for production and acceptable to the users.

· Security Testing. The Contractor shall support cybersecurity testing (reference Task 6 for details).

3.3.16 System Documentation

The Contractor shall develop and provide documentation for all capabilities delivered/supported and deliver documents in the specified format. The Contractor shall provide installation instructions and detailed systematic instructions on the operation and usage of the items installed. This documentation should include list of all ESS materials, hardware, and software; warranty information; system manuals; installation instructions; integration requirements and any other documents necessary to implement and utilize the system. The Contractor shall provide all manuals, installation guidelines and instructions, and all other required documentation for the system. The Contractor shall develop new as-built drawings or updated existing as-built drawings to reflect final equipment location, layout, connectivity and other details associated with the system.

3.3.17 Training

The Contractor shall conduct on-site or virtual training sessions and provide training materials to DLA functional users. The Contractor shall provide lesson plans and training manuals for the training phases, including description of training and a list of reference material.

· All training materials must be submitted and approved by the COR/COTR prior to use.

· End-user training and documentation shall come with the product and shall be provided by the Contractor upon initial fielding.

· User manual should be written in non-technical, easy to understand language.

· No formal in-residence training post initial fielding training should be required to operate the ESS system.

3.3.18 Post-Production Support

The Contractor shall provide post-production support for all newly installed ESS systems, hardware, software, and other associated items for 30 days or for the duration listed in the TO PWS. The contractor shall develop and execute a release plan and transfer knowledge to the Government-designated sustainment point of contact. The Contractor shall fix all defects found in production and provide support to users, business process analysts, and others as designated by the Government. The Contractor shall provide post-production support until the capability is within acceptable process and system performance thresholds and support the complete acceptance of the capability as it transitions to normal operations, support and sustainment.

3.3.19 Capability Decommission

Upon completion of work, the Contractor shall turn over to DLA a complete and working system. Once the Contractor has implemented, fully tested and received J6 COR/COTR approval of the system, the Contractor shall remove the existing legacy ESS based on the approved Migration Plan. Upon J6 COR/COTR approval, the Contractor shall remove and dispose of all decommissioned equipment, software, components, documentation IAW DLA policies and procedures.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .