IESS Attachment 8 Task Order PWS 3-29-2024.docx

DOCX document 88 KB Posted

Attached to
IESS/ECK Systems Support Services Federal contract opportunity
Solicitation number
SP470324R0004
Issued by
Defense Logistics Agency

About this file

This document is a Performance Work Statement (PWS) for the maintenance of Electronic Security Systems (ESS) and Electronic Key Control (EKC) systems at the Defense Supply Center Columbus (DSCC) in Ohio. The PWS outlines requirements for the contractor to provide preventative maintenance, corrective maintenance, emergency maintenance, and software upgrades for the Lenel OnGuard, Lenel Milestone, Keystone, and Morse Watchman Key systems. The contractor must manage the total work effort, implement work control procedures, and provide fully qualified personnel. The PWS includes specific requirements for cybersecurity, configuration management, records and reporting, and staffing. It also details government-furnished equipment and contractor-furnished equipment. The related federal contract opportunity is a pre-solicitation notice for the requirement of IESS/EKC Systems Support Services, which will be a small business set-aside contract with a NAICS code of 561621 and a size standard of $25 million. The solicitation is expected to be posted on or around February 5, 2024.

View the file

Other files for this federal contract opportunity

Show all 18

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

1.0 Title: Maintenance of ESS Systems for Defense Supply Center Columbus (DSCC), Columbus, Ohio

2.0 Introduction:

The Defense Logistics Agency (DLA) is a United States (U.S.) Department of Defense (DoD) agency providing worldwide logistics support to the missions of the Military Departments and the Combatant Commands. In support of these missions, DLA Installation Management (DM) maintains a presence at DLA locations for the life, health, and safety systems including Electronic Security Systems (ESS) and Electronic Key Control (EKC).

DM serves as the functional proponent for all ESS and EKC requirements, policy, and procedures. ESS encompasses Intrusion Detection Systems (IDS), Access Control Systems (ACS), and Closed-Circuit Television (CCTV) systems, for DLA facilities, personnel, and property. EKC controls and logs the access to key cabinets located around the installation that authorized users can operate to remove specific keys for facility access. The ESS and EKC, includes all subcomponents, are located within the DLA Defense Supply Center Columbus, Ohio (DSCC) and currently reside on the DLA network.

3.0 Background:

This Performance Work Statement (PWS) outlines requirements for Preventative Maintenance (PM), Corrective Maintenance (CM), Emergency Maintenance (EM), software upgrades for associated equipment/hardware for the Lenel OnGuard, Lenel Milestone, Keystone, and Morse Watchman Key System at DSCC.

The Contractor shall provide installation and/or maintenance support to include but not limited to daily operations testing, cybersecurity support and artifacts, upgrades, patches, migrations, enhancements, inspection, and corrective and preventive maintenance. The Contractor shall assist with supporting information, protection needs and system security requirements for Commercial off-the-Shelf (COTS) ESS and EKC solutions.

4.0 Scope and Tasks:

A. Service Plan The contractor shall provide a program management plan. The plan shall clearly establish the scope of work to include Preventative Maintenance (PM), Corrective Maintenance (CM), Emergency Maintenance (EM), software upgrades for associated equipment/hardware for the Lenel OnGuard, Lenel Milestone, Keystone, and Morse Watchman Key System at DSCC. At a minimum, the plan shall include all personnel to conduct services, the licenses and certifications for each individual, the methods, and tools to be used to conduct service for each building, and a schedule.

B. Work Effort The Contractor shall manage the total work effort associated with the PWS herein to assure timely completion of all PWS items including, but not limited to, planning, developing, and implementing project plans, scheduling, report preparation, communication and coordinating with stakeholders, escalation procedures, establishing and maintaining records, monitoring, and quality control. The Contractor shall provide fully qualified personnel with the necessary management expertise, training, and certifications to assure the performance of the work in accordance with sound and efficient management practices.

C. Work Control The Contractor shall implement all necessary work control procedures to ensure timely accomplishment of work requirements, as well as to permit tracking of work in progress. The Contractor shall plan and schedule work to assure material, labor and equipment of all contracted items are available to complete work requirements within the specified time limits and in conformance with the quality standards established herein.

The Contractor shall submit a Quality Control Plan (QCP) within ten business days of contract start date to the COR and updated monthly in the MSR. This plan shall describe the Contractor’s methodology of compliance with the Deliverables and Performance Requirements Summary outlined above. The COR will notify the Contractor of concurrence or required modifications to the QCP within ten business days of receipt. The Contractor shall make appropriate modifications within five (5) business days of the COR’s notification and provide a revised QCP within five (5) business days.

The Contractor shall provide operations, sustainment, and maintenance support including mechanical Preventative Maintenance (PM), Corrective Maintenance (CM), and technical services support of software/hardware including any required manufacturer support plan products. Specifically, the Contractor shall provide the personnel, equipment, spares, mechanical hardware, software/firmware including licensing required for fully operational ESS and EKC systems including, but not limited to, testing, inspection, maintenance, services, patching, upgrading, migrating, and/or enhancing ESS and EKC systems.

Preventative Maintenance (PM) includes a recurring set of scheduled services and actions which the Contractor shall provide to keep systems fully operational and compliant.

Corrective Maintenance (CM) is the non-recurring unscheduled repairs or services required to make the systems fully operational.

Emergency Maintenance (EM) is any activity that requires immediate action. DSCC security personnel are the first line of defense for responding and assessing mission critical situations. DSCC security personnel must assess what the problem is and determine the correct response prior to the ESS Support contractor being notified. The contractor shall:

1. Respond to requests for emergency maintenance.

2. Perform troubleshooting functions of the IESS (Hardware and Software).

3. Contact the DISA Global Service Desk and request an incident be opened and assigned to J62BK – OT Security for ESS issues as necessary.

4. Coordinate with the Information Technology Operations Center (ITOC) as necessary.

5. Locate the cause of the faults, replace defective components/equipment, and make necessary adjustments to the system (Hardware and Software).

6. Follow-up with the DSCC security POC detailing the emergency, arrival time to the site, and repair/corrections needed to return the system to full functionality.

7. Follow-up with the DSCC security POC upon completion of the repair.

Technical services support includes daily operations support, version upgrades, patching, security updates, enhancements, data migrations, and/or network migrations required for ESS and EKC systems. All required cyber updates and patches shall be done through Preventative Maintenance including Information Assurance Vulnerability Alert (IAVMs), Cyber Task Order (CTO), Assured Compliance Assessment Solution (ACAS) scan remediations or any other cyber requirements to include updating or creating any supporting cybersecurity documentation required for assessment and accreditation.

1. Operations The Contractor shall support daily operations of systems including system monitoring, break/fix triage support, incident management, project management, configuration management and PM/CM required in day-to-day operations support. Contractor shall provide an Incident Response Plan (IRP) for incident management to the COR and J6 TPOC for approval.

2. Sustainment The Contractor shall develop and implement a Sustainment Plan for all systems, subsystems, and equipment IAW with original equipment manufacturer and/or Federal/DoD/DLA policies and procedures. The Sustainment Plan shall include the periodic maintenance, repair, replacement, and overhaul of existing systems, hardware, and software including planned version upgrades of the application and Operating System (OS). The Contractor shall provide the Sustainment Plan which includes the technology road map, the PM schedule, and Corrective Maintenance (CM) approach to the COR for approval within five (5) days of contract award. The CM approach should include:

1. Position qualified and certified personnel, test equipment, and other pertinent information needed to quickly diagnose and make repairs.

2. Plan, perform, and document system confidence tests, periodic inspections, and preventive maintenance of the application and servers.

3. Identify critical system operations and implement strategies to prevent potential failures or administrative downtime from creating a critical system outage.

4. Provide after-hours support response times within 4 hours for tickets/issues.

5. Since these applications are health and safety systems, they require high uptime ~ 99.6%, 24/7, 365 and the Contractor should maintain and support as such.

6. Analyze fault histories and fault trends to proactively predict and mitigate repetitive issues.

7. Respond to and take corrective action to resolve vulnerabilities identified by the Contractor or the Government. Lead the efforts to resolve the vulnerabilities associated with the ESS applications, servers, clients, or equipment, coordinate resolution with appropriate DLA Technical Reps that support OS, hardware, etc. as required.

8. Provide ongoing training for Government personnel as requested in support of the existing ESS/EKC.

9. As a software upgrade becomes available, the Contractor shall develop a plan for the upgrade and present that plan to the COR for approval. The COR will present this plan to the J6 Technical Point of Contact (TPOC) for routing for J62 approval. Once approved, the Contractor shall execute their plan to install the upgrade(s) and return the ESS system(s) to an operational state.

10. The Contractor will be responsible for all IAT- II level version upgrades, patching, device enhancements, device replacements that reach end of life/support and for device replacements of hardware equipment that does not meet cyber standards/requirements including migrations required for ESS and EKC systems compliance.

The Contractor shall perform preventive maintenance service on all equipment which consists primarily of inspection, testing, cleaning, lubrication, adjustment, and calibration to verify proper system operation; minimize malfunction, breakdown, and deterioration of systems and equipment. The Contractor shall perform PM services in accordance with the information specified in Appendix A - Equipment Listing.

All replacement parts, materials, environmental compliance, and Contractor personnel transportation used for PM shall be included in the contract unit price for PM services.

BATTERY MAINTENANCE

Battery voltage and charge levels will be checked as part of the maintenance visit. Any battery incapable of maintaining a 75% charge will be replaced immediately.

QUARTERLY COMPLETE SYSTEM TEST OF INTRUSION DETECTION SYSTEM (IDS)

All quarterly IDS testing shall be scheduled to be performed during normal working hours. All Restricted and Controlled Areas and duress alarms will be tested quarterly.

MONTHLY ARMS VAULT TEST OF THE INTRUSION DETECTION SYSTEM (IDS)

All monthly Arms Vault IDS testing shall be scheduled to be performed during normal working hours. Preventative maintenance test of all ESS will be conducted annually. Preventative maintenance of Morse Watchmans Keypro Touch will be in accordance with manufacturers requirements.

3. Maintenance The Contractor shall perform Preventive Maintenance (PM) services on all equipment which consists primarily of routine recurring inspection, testing, cleaning, lubrication, adjustment, and calibration to verify proper system operation to minimize malfunction, breakdown, and deterioration of systems and equipment. The Contractor shall submit and maintain an up-to-date schedule with status for all PM tasks. Any modifications, changes, additions, or deletions shall be submitted to the COR for approval and once approved and implemented, documented in as-built drawings, and provided to the site.

D. Enterprise Configuration Management (ECM) The Contractor shall adopt DLA Enterprise Configuration Management (ECM) plans ensuring all hardware and software changes are approved by the J6 TPOC and coordinated with the COR. The Contractor shall use the DLA Business Capability Management (BCM) ServiceNow, Change Implementation Plans (CIPs), and provide technical expertise in Enterprise Change Requests (ECRs) that addresses product management and version control for software (changes) and hardware (changes). The Contractor shall support business processes documentation such as Scheduled Maintenance Requests and Information Technology Operations Center (ITOC) notice (INFOSPOT) and all other control items such as customer notifications. The Contractor shall evaluate all changes to the approved system requirements baseline for risk to security, and for schedule and cost impact, provide evaluations in writing and with sufficient detail to allow for review and approval by the configuration governance structure as required. CIPs and ECRs are normally required 21 business days in advance of required change.

E. Configuration Audit A configuration audit is an inventory of all existing hardware, software, data, drawings, devices, and technical documentation and is a function of Configuration Management. The Contractor shall perform an initial configuration audit and provide to the COR within ten (10) business days of performance start. Asset lists shall be provided upon request and include product details such as hosting location, model, versioning, product type, and other details about the product, software, hardware, or device. The Contractor shall report updates to asset list(s) within the monthly status reports. Additionally, a data dictionary is required.

The contractor shall:

1. Manage the site inventory of equipment and material spares using a Microsoft Excel spreadsheet for tracking purposes. The government will use this spreadsheet to monitor purchases, repairs, and disposals. The Contractor is responsible for coordinating with the DSCC Accountable Property Officer (APO) for inspection of property, components, replaced parts and material prior to disposal to determine suitability as potentially accountable property, and for coordinating this with the J6 TPOC. Items will not be disposed of without concurrence from the COR.

2. Maintain the following categories on the Microsoft Excel spreadsheet.

a. Item configuration number

b. Item nomenclature (Common Name)

c. Current Item Quantity

d. Item low level (Lowest quantity allowable before ordering replacements)

e. Warranty expiration date

f. Date order placed.

g. Date order received (on-site)

3. The contractor shall NOT include any contractor consumables as part site inventory. Examples of contractor provided consumables are, electrical tape, cleaning rags, brushes, etc. Approved consumables for site inventory are cleaners, lubricants, fuses, lamps, etc.

4. Validate and maintain the inventory of security system hardware.

5. Validate and maintain an inventory of all system software, license information, versions, and system and security patches.

6. Keep, appropriately secured, copies of site-specific support documentation to include software license information, versions and patches, technical manuals, and design plans at the government facility.

7. Review and validate technical drawing as part of the configuration audit.

8. Validate the existence of technical manuals as part of preventive maintenance

9. Summarize actions taken to validate and update drawings and technical documentation as part of the contractor’s monthly status report to the government.

F. Schedule The Contractor shall schedule and arrange work to cause the least interference with the normal occurrence of Government business and mission. In those cases where some interference may be essentially unavoidable, the Contractor shall make every effort to minimize the impact of the interference, inconvenience, equipment downtime, interrupted service, and/or customer discomfort. Non-scheduled visits will be coordinated with the COR at least five (5) working days in advance and notify the COR if the work being performed may cause interference. Notification shall include the type of work to be done and the estimated completion date/time. The Contractor shall reschedule any work that the KO/COR deems necessary to avoid unacceptable disruptions in the Government's business.

Performance Work Statement (PWS) Maintenance of Electronic Security Systems (ESS) for Defense Supply Center Columbus

The Contractor shall create, maintain, and submit project plan(s)/schedule(s). Initial plans and schedules are due within five (5) business days after award and will be updated monthly (on 1st Monday of month) until the final inspection is completed. The Contractor shall create, maintain, and submit project plan(s)/ schedule(s) 15 business days following a request for any upgrade, installation, or replacement of device(s) and or application(s). Microsoft Project is the preferred software/format for project plans/schedules.

Project plans/schedules shall include Task ID, Task Name, Actual Start, Actual Finish, Baseline Start, Baseline Finish, % complete, resource name/title, with the critical path defined utilizing predecessors and/or successors. The Government may return unacceptable plans and schedules for re-work, and the Contractor shall update and re-submit project plans and schedules within five (5) business days of request.

The Contractor shall coordinate a post award Kickoff meeting prior to the initiation of work and conduct monthly In Process Review (IPR) meetings. These meetings will be held with the Contractor, CPM, KO, Contract Specialist (KS), COR, and the J6 TPOC to discuss an overview of Contractor’s plans to manage scope, schedule, and resources. The Contractor will discuss stakeholders’ expectations, details of contract execution including incident management, triage support, technology road map plans including current and future software/hardware landscape general conditions, project schedule/plan, work schedules, coordination, security, safety, deliverables, permits, and other matters pertinent to work accomplishments shall be discussed in this meeting. Contractor shall attend other meetings as required in support of contract tasks.

G. Hours of Operation Regular working hours for DLA DSCC are 0730-1600 Monday through Friday. Maintenance and repairs will be performed during these hours unless coordinated with COR/TPOC.

Work under this order will be performed during normal working hours when practical. However, due to operational requirements, schedules, and the availability of required resources and/or downtime of those resources, overtime (OT) may be required. OT allowances are in accordance with the identified labor categories and estimated labor hours specified in the Government pricing model. Prior to OT hours being worked, the contractor shall obtain COR concurrence for the specific hours per labor category and applicable dates. Specifically, the contractor shall not exceed the estimated OT allowable hours as identified at time of task order award.

H. Federal Holidays The Contractor is normally not required to provide services on Federal holidays observed at DLA unless requested by the KO/COR. The following holidays are observed:

Observed Federal Holidays

New Year Day
Martin Luther King Day
Presidents Day
Memorial Day
Juneteenth Day
Independence Day
Labor Day
Columbus Day
Veterans Day
Thanksgiving Day

Christmas Day

When one of the above holidays falls on Sunday, the following Monday will be observed as a legal holiday. When the federal holiday falls on a Saturday, the preceding Friday is observed as the holiday. In the event an Executive Order issued by the President of the United States declares Agencies of the Federal Government closed for a regularly scheduled workday, the Contacting Officer (KO) or designee will determine and advise the Contractor on whether services are required for that day.

I. Records/Reports The Contractor shall maintain management, maintenance, repair records, and reports. All records and copies of reports shall be turned over to the COR within seven (7) calendar days prior to contract completion.

The Contractor shall maintain a separate set of redline drawings, elementary diagrams, and wiring diagrams of the system to be used for As-Built Drawings and shall keep this set accurately and neatly up to date with all changes and additions throughout the contract. All changes to or additions to security systems and equipment will be updated quarterly, with update pages provided to the COR. As-Built Drawings shall be developed and maintained by the Contractor and depict actual conditions. As-Built Drawings are to be submitted to the COR in 11X17 hard copy, original Auto Computer Aided Design (AutoCAD) and Adobe Portable Document Format (PDF) format and shall not be overlays.

J. Cybersecurity Requirements The Contractor shall provide cybersecurity (CS) in accordance with all current policies, procedures, and statutes, to include (but not restricted to) the following, as applicable, to specific task orders (most current version):

System Identification Reference Documents:

a. Committee on National Security Systems Instruction 1253, Security Categorization and Control Selection for National Security Systems, July 29, 2022

b. Federal Information Processing Standards Publication 199, Standards for Security Categorization of Federal Information and Information Systems, February 2004

c. Federal Information Processing Standards Publication 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006

d. Federal Information Security Management Act (P.L. 107-347, Title III), December 2002

e. Department of Defense Instruction 5000.02, Operation of the Defense Acquisition System, January 23, 2020

f. Department of Defense Instruction 5200.39, Critical Program Information (CPI) Identification and Protection within the Research, Development, Test, and Evaluation (RDT&E) Incorporating Change 3, Effective October 1, 2020 System Compliance, Instructions and Guidelines Reference Documents:

a. 44 U.S.C. § 3542, January 2012

b. Department of Defense Instruction 8500.01, Cybersecurity, Incorporating Change 1, Effective October 7, 2019

c. Department of Defense Instruction 8510.01, Risk Management Framework (RMF) for DoD Information Technology, July 19, 2022

d. Department of Defense Instruction 5200.44, Protection of Mission Critical Functions to Achieve Trusted Systems & Networks, Incorporating Change 3, October 15, 2018

e. DoD Program Manager’s Guidebook for Integrating the Cybersecurity Risk Management Framework (RMF) into the System Acquisition Lifecycle

f. Defense Acquisition Guidebook (DAG)

g. Department of Defense Directive 8140.01, Cyberspace Workforce Management, October 5, 2020

h. Department of Defense Instruction 8330.01, Interoperability of Information Technology (IT), Including National Security Systems (NSS), September 27, 2022 System Cybersecurity Implementation Reference Documents:

a. Department of Defense Instruction 8580.1, Information Assurance (IA) in the Defense Acquisition System, July 9, 2004

b. National Institute of Standards and Technology Special Publication 800-82 Revision 2, Guide to Industrial Control Systems (ICS) Security, February 2015

c. UFGS-25 50 00.00 20 Cybersecurity of Facility-Related Control Systems

d. United Facilities Criteria (UFC) 4-010-06, Cybersecurity of Facilities-Related Control Systems Personnel Requirements Reference Documents:

a. Department of Defense DoD 8570.01-M, Information Assurance Workforce Improvement Program, change 3 dated 24 Jan 2012

b. DoD Manual (DoDM) 8140.03 Cyberspace Workforce Qualification & Management Program, dated 15 Feb 2023

FRCS Guidelines Reference Documents:

a. Deputy Under Secretary of Defense (Installations and Environment) Memo dated 19 Mar 14, subject:

Real Property Related ICS Cybersecurity

b. Defense Logistics Agency Risk Management Framework Standard Operating Procedures, April 2021

c. Office of the Assistant Secretary of Defense Facility Related Control Systems (FRCS) Master List Memo, October 2020

d. Defense Logistics Agency Approved Cybersecurity Computing Environment List, October 2021

e. Department of Defense Control Systems Security Requirements Guide Version 1, Release 1, July 14, 2021

2. The Contractor shall provide the following accreditation artifacts:

a. System Diagrams

Architecture Network Diagram Authorization Boundary Diagram Data Flow Diagram Purdue Diagram

b. Comprehensive Hardware Inventory Report

c. Comprehensive Software Inventory Report

d. Concept of Operations (CONOPS)

e. Plan of Actions and Milestones (POAM)

f. Software Upgrade and Support Plan (SUSP)

g. Ports, Protocols, and Services Management (PPSM) Documentation for Registration

h. Federal Information Processing Standard 199 (FIPS-199) Cybersecurity Strength Requirements

i. PII Confidentiality Impact Level (PCIL) Categorization Worksheet

j. Enterprise Configuration Management Plan

k. Security Technical Implementation Guide (STIG) and Security Requirement Guides (SRG) Mitigations

1. Cybersecurity Strength Requirements The Contractor shall provide the following cybersecurity strength requirements including, but not limited to the following:

The Contractor shall adhere to all existing authorities and policies of the Director of National Intelligence regarding the protection of sensitive compartmented information (SCI), as directed by Executive Order 12333 and other laws and regulations.

The Contractor shall satisfy the Risk Management Framework (RMF) requirements of subchapter III of chapter 35 of Title 44, United States Code (U.S.C.), also known as the “Federal Information Security Management Act (FISMA) of 2002”.

The Contractor shall enable DLA to meet the standards required by the Office of Management and Budget (OMB) and the Secretary of Commerce, pursuant to FISMA and section 11331 of Title 40, U.S.C.

FIPS 199 / CNSSI 1253 Security Categorization: The Contractor shall participate in categorization discussions with the DLA J6 PM, functional lead, and the Information System Security Manager (ISSM) and provide all required FIPS 199 documentation as requested to support security categorization.

The Contractor shall provide a recommendation on system categorization based on sound technical expertise in accordance with FIPS 199 then work in coordination with the prescribed DLA System Owner (SO) and ISSM to support the categorization IAW FIPS 199, CNSSI 1253 and OSD Facility Related Control Systems (FRCS) Master List including DLA specific systems, then document the results of the security categorization in the System DLA FIPS 199 document and the Concept of Operations (CONOPs).

Assigned DLA PM will coordinate with the Contractor to identify and document Confidentiality, Availability, Integrity (CIA) of the system in a DLA FIPS 199 document for approval by DLA ISSM personnel.

2. Completion Of System Hardening (Scan/Fix/Scan) Testing and Analysis The Contractor shall harden systems using a scan, fix, scan methodology remediating findings IAW current DOD, DLA, and Defense Information Systems Agency (DISA) standards. This includes automated and manual STIG application, Assured Compliance Assessment Solution (ACAS) scanning, and any other hardening efforts required to make the system ready to connect to a DOD network. Whenever findings occur, as required periodically, and/or following any major system change, the Contractor shall scan/fix/scan until all issues have been fixed and/or properly and acceptably mitigated. Any Critical or High impact level findings that cannot be fixed are to be reported to the J6 TPOC/ISSM immediately along with a valid reason the vulnerability cannot be fixed and a POAM. Once the Contractor has completed hardening efforts, system monitoring and audits shall occur to ensure STIG compliance is maintained.

3. Cybersecurity Assurance Requirements

The Contractor shall design, develop, and integrate cybersecurity solutions supporting the Department of Defense and all other applicable Government agencies.

This will be achieved through abiding by all applicable cybersecurity policies, regulations, and directives to ensure a favorable Assessment and Authorization (A&A), Assessment and Incorporate (A&I), or FRCS Assess Only Risk Assessment (FRCS AORA) decision, as well as obtaining an Authority to Connect (ATC) to DLA’s network. The Contractor shall mitigate risk identified through the RMF authorization process down to a level acceptable to the DLA Authorizing Official (AO).

Coding for Security. The Contractor shall provide documentation of development practices and standards applied to Government approved Contractor-written control system software, including firmware, used to ensure a high level of defense against unauthorized access.

The solution shall comply with the security control requirements documented in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53r4, “Security and Privacy Controls for Federal Information Systems and Organizations” and NIST 800-82r2, “Guide to Industrial Control Systems (ICS) Security”. The Contractor shall provide details of any alternative but equally effective security measures used to compensate for the inability to satisfy a particular derived security requirement (mitigation to control compliance findings). This information shall be submitted in writing to the DLA J6 PM for cybersecurity approval as soon as the alternative is identified.

K. Application Network and Infrastructure All system/network components and applications shall be compatible with all applicable Defense Information System Agency (DISA) Security Technical Implementation Guides (STIGs). Any STIG exceptions must be identified as part of the Contractor’s proposal to the Government and approved by J6 Cybersecurity. Exceptions incurring risk found unacceptable to the DLA Authorizing Official are not permitted.

All network components and applications shall be IPv4 and IPv6 compatible.

Network components shall allow configuration of IEEE 802.1x or port security for authentication.

The Contractor shall provide a complete list of all ports, protocols and services required for any computer system running control system applications or required to interface the control system applications. The listing shall include all ports and services required for normal operation as well as any other ports and services required for emergency operation. The listing shall also include an explanation or cross reference to justify why each service is necessary for operation.

The Contractor shall identify any system wireless communication capability, enabled, or disabled. All wireless communications shall meet applicable STIG requirements to include FIPS 140-2 certification. Any requirement to use wireless or cellular must be approved in writing by DLA J6, coordinated with the J62B PM and documented with the DLA Frequency Manager.

L. Information and Operational Technology Infrastructure Requirements

In general, the DLA expects to furnish the IT Infrastructure to host the OT solution(s) and/or system(s) (including VLANs, and Virtual Machines (VMs)) unless there is a hardware, compatibility, or mission issue preventing it. As such, the Contractor must clearly identify “what” anticipated Government IT Infrastructure is required to host and operate the OT solution(s) and/or system(s) within the design documentation submitted for Government approval at time of award. These anticipated designs will be incorporated into the system CONOPs. The Contractor will be responsible for all installation, configuration, and deployment of the OT solution(s) and/or system(s) (including but not limited to) its subsystem(s), application(s), and patch cabling, if required.

Any requirement for the Contractor to provide their own IT Infrastructure, standalone server, or management workstation hardware due to compatibility issues must be documented in the Contractor’s proposal and approved by J6 prior to contract award. All Contractor provided IT Infrastructure must meet DoD STIG requirements. If the Contractor provides their own IT Infrastructure for the OT solution(s) and/or system(s), upon AO approval of the security authorization package (and prior to final OT solution(s) and/or system(s) acceptance or go-live), all Contractor provided IT Infrastructure will become the property of the Government.

All specialized software provided by the Contractor to the Government must have the applicable license key(s) as well as sales/transaction records, ownership control(s), manuals, technical publications, documentation, and any other information supporting ownership accompanying it. At the time of Contractor hand-off of Contractor owned IT Infrastructure to the Government, all design information for Enterprise Architecture (EA) for the “as built” OT solution(s) and/or system(s) will be provided. Any Contractor provided operating system (OS), software, and firmware throughout the duration of the contract will be upgraded by the Contractor prior to the Contractor’s end of mainstream support for the OS, software, or firmware.

DLA’s preference is for maximized virtual IT Infrastructure. As such, the Government will provide the virtual infrastructure to support deployment of Contractor supplied virtual servers or virtual appliance (OVA files). DLA will provide a virtual server up to the following:

CPU: 4 RAM: 16GB

Disk 1 (OS Drive): 100 GB Disk 2 (Data Drive): 100 GB

Any requirements exceeding these specifications shall be submitted in writing and approved by the DLA J6 with supporting documentation prior to contract award.

Other PWS contractor content considerations as applicable:

1. Level 1-2 OT and Level FRCS Role-based authorization tools requirements and integration

2. Level 2 Challenge/response authentication

3. Physical/token authentication

4. Location/local-based L 0 -2 authentication

5. Password distribution and management technologies requirements

6. Device-to-device authentication and switching

7. Filtering/blocking/access control technologies

8. Host-based firewalls/firewall

9. FRCS Network Segmentation and Firewalls as applicable

a. Unidirectional Gateways

b. Local Area Networks (VLAN)

c. Software-Defined Networking (SDN)

d. Network Monitoring/Security Information and Event Management (SIEM)

The Contractor will be responsible for the implementation including meeting all required STIG compliance.

The Contractor shall be responsible for all configuration and deployment which meet DoD, NIST and USG regulatory and cybersecurity policy requirements.

Any OT solution(s) and/or system(s) with IT Infrastructure provided by the Contractor must be upgradeable and remain compliant to cybersecurity specifications during the lifecycle of the solution. Contractor supplied systems must meet DoD STIG requirements, with any exceptions noted in the design documentation.

The Contractor is responsible for all software maintenance activities for any/all appliances including but not limited to, firmware updates, OS patching, software patches etc. for the duration of the contract period.

The Contractor will be responsible for all physical maintenance activities for any/all appliances including but not limited to, replacement of defective components such as hard drives (to be destroyed onsite per DoD policy, guidance), motherboards, daughterboards etc. for the duration of the contract period.

(NOTE 1: The maintenance service provider can be an organization within the asset owner’s organization.)

(NOTE 2 There can be one or more maintenance service providers maintaining the Automation Solution at the same time or in sequence.)

Maintenance activities start after handover of the DLA Automation Solution to the DLA asset owner and may continue until the asset owner no longer requires them.

Activities are typically short and frequently recurring, and may include one of more of the following:

a. Patching and anti-virus updates

b. Equipment upgrades and maintenance, including small engineering adjustments not directly related to control algorithms

c. Component and system migration

d. Change management

e. Contingency plan management

All maintenance activities will include completion of identified DoD/DLA Security Awareness training, independent of other training received.

System(s) shall operate using a Contractor fully supported operating system (OS), software, and firmware throughout the duration of the contract. All operating systems, software, and firmware shall be upgraded prior to the Contractor’s end of mainstream support for the operating system, software, or firmware. The solution must be upgradeable and remain compliant to DoD cybersecurity specifications during the lifecycle of the solution.

Any removable flash media required for system operation must be reviewed and approved in writing by the DLA J6 Flash Media Approval Program prior to implementation.

All FRCS OT solution(s) and/or system(s) must use the PERA Model for Control Hierarchy (reference ISBN 1-55617-265-6) to provide logical and/or physical architecture for networking, security hardware, software, and methods. The PERA Model is an industry standard for manufacturing and/or industrial control systems that segments hardware, devices, and equipment into a hierarchical based design.

M. Software

The Contractor shall provide all software and hardware updates when an upgrade/patch is released from the Original Equipment Manufacturer (OEM). The Contractor shall maintain an accurate software and hardware configuration and coordinate through the Lenel Value Added Reseller (VAR) for all equipment. Any software or hardware updates will need to be coordinated directly with the J6 TPOC prior to procuring to be evaluated and approved. This includes any utilities required to develop, communicate, and make configuration updates to a system. All hardware must be National Defense Authorization Act (NDAA) compliant. The Contractor shall provide all STIG documentation for application upgrades. The Contractor shall provide documentation identifying they changed all appliance passwords and disabled or removed all unnecessary accounts. The Government should receive a complete listing of all new passwords.

The Contractor shall observe all copyright agreements and shall be held liable for any infringement of copyrighted software licensing agreements and shall compensate the appropriate Contractor for each instance of copyright violation. In the interest of protecting Government systems from computer viruses, the Contractor shall not use public domain software nor shall Contractor personnel download software from public bulletin boards. The Contractor shall use only J6 TPOC/ISSM approved COTS, Contractor-developed, or Government-furnished software in performance of this statement of work. The Contractor shall use the Microsoft Office suite of software for preparation of all documentation required in the delivery order. Should the introduction of a computer virus or malicious destruction of computer software, stored information, or hardware result from the use of public domain software or from software taken from a public bulletin board, the Contractor shall be required to repair the damage at no expense to the Government and without impact on delivery schedules or daily operation.

The Contractor shall be responsible for all software maintenance activities in this PWS not limited to firmware updates, OS patching, software patches, and security enhancements for the duration of the contract period.

N. Data Usage The Contractor will maintain, transmit, retain in strictest confidence, and prevent the unauthorized duplication, use, and disclosure of information. The Contractor will provide information only to employees, Contractors, and subcontractors having a need to know such information in the performance of their duties for this project.

Information made available to the Contractor by the Government for the performance or administration of this effort shall be used only for those purposes and shall not be used in any other way without the written agreement of the Contracting Officer. Contractor personnel will be required to sign a non- disclosure statement.

If proprietary information is provided to the Contractor for use in performance or administration of this effort, the Contractor may not use such information for any other purpose except with the written permission of the Contracting Officer. If the Contractor is uncertain about the availability or proposed use of information provided for the performance or administration, then the Contractor will consult with the COR regarding use of that information for other purposes.

The Contractor agrees to assume responsibility for protecting the confidentiality of Government records which are not public information. Each employee of the Contractor to whom information may be made available or disclosed shall be notified in writing by the Contractor that such information may be disclosed only for a purpose and to the extent authorized herein.

Performance of this effort may require the Contractor to access and use data and information proprietary to a Government agency or Government Contractor which is of such a nature that its dissemination or use, other than in performance of this effort, would be averse to the interests of the Government and/or others.

Contractor and Contractor personnel shall not divulge, or release data or information developed or obtained in performance of this effort, until made public by the Government, except to authorized Government personnel or upon written approval of the Contracting Officer. The Contractor will not use, disclose, or reproduce proprietary data that bears a restrictive legend, other than as required in the performance of this effort. Nothing herein shall preclude the use of any data independently acquired by the Contractor without such limitations or prohibit an agreement at no cost to the Government between the Contractor and the data owner that provides for greater rights to the Contractor.

All data received, processed, evaluated, loaded, and/or created because of a task order shall remain the sole property of the Government unless specific exception is granted by the Contracting Officer.

Contractor and Contractor personnel shall sign a Non-Disclosure Agreement prior to commencing work on a task order.

O. Government Furnished Office The Government will furnish workspace and the following utility services at existing outlets for use in those facilities provided by the Government, and as may be required for the work to be performed under the contract: electricity, natural gas, fresh water, and sewage service. Information concerning the location of existing outlets may be obtained from the COR. Utilities specified above will be furnished at no cost to the Contractor.

In most cases, the Contractor will access existing Government Furnished Equipment (GFE). All specialized software required by the Contractor must be provided to the Government by the Contractor at the time of the contract award. All Contractor provided software that will be required to be installed on GFE will be evaluated and will require approval prior to installation. This includes utilities required to develop, communicate, and make configuration updates to a system.

A GFE provided laptop (thick client) will be supplied.

The Contractors are responsible for maintaining and supplying , hardware, or networks for DSCC as needed. The Government will not be responsible for Contractor supplied equipment.

Contractor shall promptly report to the COR and Contracting Officer all lost and/or damaged Government property.

P. Contractor Furnished Equipment The Contractor shall provide all services to perform the requirements of this contract.

The Contractor shall provide new parts and components when providing the services described herein. The Government will not accept factory reconditioned parts. All replacement units, parts, components, and materials to be used shall be compatible with that existing equipment on which it is to be used.

Shall be of equal or better quality than original equipment specifications; shall comply with applicable Government, commercial, or industrial standards such as National Board of Underwriters or Underwriters' Laboratories, Inc. National Electrical Manufacturer's Association, and used in accordance with original design and manufacturer’s intent. If the original manufacturer has updated the quality of parts for current production, parts supplied under this contract shall equal or exceed the updated quality.

The Contracting Officer may require the Contractor to submit manufacturer's descriptive data and certifications for materials and equipment used. This applies to all equipment hardware and software installed by the Contractor or existing equipment hardware and software. Such submittals shall be delivered to the Contracting Officer within fifteen (15) calendar days of request. Manufacturer's descriptive data and certificates shall include the name of the manufacturer, model number or other identifying information, catalog cut, and other identifying data and information describing the performance, capacity, rating, and application/installation instructions which clearly illustrate that the proposed item meets all applicable standards.

Prior to items being purchased, the contractor shall obtain COR concurrence. All items procured by the contractor shall be utilized or staged at the contractor’s facility transported by the contractor to the installation, integrated or consumed in a system, or returned to the government at the completion of the task order.

Q. Staffing Contractor shall maintain a certified work force to complete work in accordance with the time and quality standards specified. Contractor shall maintain 3 full time staff members at DSCC, Columbus, Ohio for the duration of the contract. Staff shall include 2 Electronics Technician III, and 1 system administrator meeting the following criteria:

1. GENERAL STAFFING REQUIREMENTS:

a. If a certification becomes obsolete during the life of the contract, the Contractor shall be responsible for ensuring applicable personnel obtain an acceptable replacement certification prior to the IT/OT product’s end of support or end of life.

b. Each Contractor employee shall be a citizen of the United States of America, or an alien who has been lawfully admitted for permanent residence, or who presents evidence from the Immigration and Naturalization Service that employment will not affect his immigration status.

c. Most work to be performed under this requirement is unclassified, however, a security clearance maybe required. All Contractor personnel proposed to work on the network, or any IT capabilities/functions (at a minimum) will be required to have an IT-II, a clearance requiring a National Agency Check with Law and Credit (NACLC) or NACLC equivalent, or an IT-I, a clearance requiring a Single Scope Background Investigation, prior to the work commencing.

d. All Contractor personnel requiring elevated/privileged access to any system or network components, either during provisioning or post award, shall also meet DoD 8570.1-M IA Technical (IAT) II baseline and Computing Environment (CE) certifications, applicable to the existing computing environment. Provide a copy of all current certifications in proposal and to the COR in the 8570- deliverable report, a spreadsheet, at time of award then monthly in the MSR, and within two (2) days of any changes. Certifications are to remain in good standing during the contract period of performance.

e. Contractor personnel must be proficient in reading and capable of communicating effectively in English.

f. Each Contractor employee shall be a citizen of the United States of America, or an alien who has been lawfully admitted for permanent residence, or who presents evidence from the Immigration and Naturalization Service that employment will not affect his immigration status.

g. Contractors are required to comply with the DOD 5220.22-M National Industrial Security Program Operating Manual (NISPOM) in the handling, protection, and safeguarding of classified information in their possession.

h. All work shall be performed by Contractor personnel specifically qualified and trained to work on all applicable systems cited in this PWS.

i. Identification Badges / Common Access Card (CAC): Every Contractor employee including those of sub-contracts is required to obtain an identification card badge (ID card) / Common Access Card (CAC) prior to starting work on this contract. Not later than fifteen (15) calendar days prior to contract full performance start date, the Contractor shall provide the COR access rosters of all personnel requiring access to restricted or controlled access areas. The roster shall include each employee’s full name, identification card number (if assigned), branch or section (if applicable), and security clearance (level of clearance and last investigation date, if applicable). The Contractor shall update the roster and provide to the COR No Later Than (NLT) five (5) workings days prior to the date of required access. The Contractor shall make all modifications to the rosters and provide an update to the COR within twelve (12) hours for employees whose employment has been terminated and for employees who no longer require access to restricted or controlled access areas. Lost or stolen Contractor employee badges must be reported to security before a replacement ID/CAC card will be issued. The Contractor will be processed for badges in accordance with DLA Access Control Policies and Regulations. The Contractor shall return all Government-furnished CAC, Access ID Badges, electronic key cards, and any other Government issued passes, e.g., vehicle pass, to the COR within twenty-four (24) hours of the completion of the contract or upon termination of an individual’s employment, whichever comes first. Contractor personnel failing to return their CAC, Access ID Badges, and electronic key cards are subject to criminal charges under United States Code (USC) Title 18, Chapter 1, Section 499 and 701.

j. The Homeland Security Presidential Directive 12 (HSPD-12) has established criteria for Contractors who require a Common Access Card (CAC) for either physical access to an Installation or access to Government information…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .