Statement_of_Work__CG_Station_Bodega_Bay_ESS.pdf

PDF 186 KB Posted

Attached to
Electronic Security Systems Upgrades at USCG Station Bodega Bay Federal contract opportunity
Solicitation number
30462PR260000128
Issued by
Department of Homeland Security US Coast Guard

About this file

This is a Statement of Work (SOW) for the modernization of Electronic Security Systems (ESS) at Coast Guard Station Bodega Bay, requiring the contractor to provide a complete, turn-key solution to replace legacy Video Surveillance System (VSS) and Physical Access Control System (PACS) infrastructure.

The contract encompasses five primary tasks: (1) development of a comprehensive ESS Security Plan including site survey, Bill of Materials with GSA Approved Products List (APL) certification numbers, scaled floor plans, and network diagrams; (2) procurement and verification of all required materials, including functional testing of any Government-Furnished Equipment (GFE) with results documented in a test report; (3) decommissioning and removal of legacy equipment with secure handover of data-bearing devices to the Government in accordance with NIST SP 800-88 media sanitization standards; (4) physical installation, system configuration, and commissioning with comprehensive System Acceptance Testing (SAT) including functional validation, FICAM compliance validation using PIV credentials, and security validation with vulnerability scanning and remediation of critical/high findings; and (5) fulfillment of mandatory PACS technical requirements including GSA APL mandate for all components, end-to-end FICAM architecture, PKI-based authentication with real-time certificate validation via OCSP/SCVP, and operator training for up to 5 working days. All tasks must be completed within 14 calendar days of commencement, with total performance period to be specified upon award.

Key requirements include mandatory compliance with COMDTINST 5532.1, UFC 4-021-02, FIPS 201-3, NIST SP 800-116, NIST SP 800-53, and FAR 52.204-25 (Section 889 restrictions). The contractor must provide qualified Key Personnel including a Project Manager with minimum 5 years of federal contract experience and a Lead Certified Technician with 5 years of ESS installation experience and 3 years of FIPS 201-compliant PACS experience for federal agencies. All contractor personnel require background investigations (Tier 2 for facility access, Tier 4 for system administrator privileges) and must complete cybersecurity awareness training prior to access to Government information systems or CUI. The contractor is responsible for all costs including travel, lodging, per diem, equipment procurement, labor, tools, and materials as part of a firm-fixed-price contract. Deliverables include 17 items ranging from the ESS Security Plan and test reports to final documentation packages, accessibility conformance reports (VPATs), and weekly project status reports submitted every Friday. All deliverables are subject to Government review and formal acceptance, with a 10 business day review period and 10 business day correction period as standard. The Government retains unlimited rights to all work products and deliverables first produced under the contract, including the ESS Security Plan, As-Built drawings, configuration files, and training materials.

View the file

Other files for this federal contract opportunity

Other files attached to Electronic Security Systems Upgrades at USCG Station Bodega Bay, newest first.
File Type Posted
Station Bodega Bay ESS Upgrade Additional Answers.pdf PDF
Station Bodega Bay ESS Upgrade Questions and Answers.pdf PDF
Statement of Work Bodega Bay ESS Upgrade - Amended.pdf PDF
BASE ACCESS FORM.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Note: the links and images in this document may point to external sources. Please review them before opening.

STATEMENT OF WORK (SOW)

for Coast Guard Station Bodega Bay Electronic Security Systems (ESS) Modernization

1.0 GENERAL

1.1 BACKGROUND

Electronic Security Systems (ESS) at certain United States Coast Guard (USCG) facilities have become obsolete and no longer meet current operational or security standards. These legacy systems, often comprised of outdated CCTV and proximity card readers, require modernization to enhance facility security and ensure alignment with federal directives.

1.2 SCOPE

This Statement of Work (SOW) defines the requirement for a Contractor to provide a complete, turn-key solution to modernize the Video Surveillance System (VSS) and Physical Access

Control System (PACS) at Coast Guard Station Bodega Bay.

The scope of this project includes all tasks necessary to deliver a complete and fully functional system. This includes conducting a site survey, developing an ESS Security Plan, procuring all required materials, professionally decommissioning and removing legacy equipment, and installing, testing, and commissioning the new VSS and PACS in accordance with the approved plan.

1.3 OBJECTIVE

The primary objective of this project is to replace legacy security systems with modern, fully compliant VSS and PACS. The new systems must meet all applicable National Security

Standards and be designed for future integration into a centralized monitoring architecture. The new PACS must be a complete, end-to-end, FIPS 201-compliant solution, utilizing components listed on the GSA Approved Products List (APL), and be capable of validating PIV credentials from all federal agencies. The final result shall be fully operational, tested, and accepted systems that enhance the security and operational readiness of the facility.

1.4 APPLICABLE DOCUMENTS

1.4.1 Mandatory Compliance Documents

The following documents establish mandatory requirements, standards, and specifications for this project:

Document

Number Title Relevance

COMDTINST

5532.1 Physical Access Control

USCG policy for PACS implementation.

UFC 4-021-02 Electronic Security Systems DoD design and installation standards for ESS.

FIPS 201-3

Personal Identity Verification (PIV) of

Federal Employees and Contractors

Standard for interoperability with

PIV credentials.

36 C.F.R. §

1194.1 Section 508 of the Rehabilitation Act

Accessibility standards for all

ICT.

DHS MD

11042.1

Safeguarding Sensitive But

Unclassified (For Official Use Only)

Information

Requirements for protecting

CUI.

FAR 52.204-25

Prohibition on Contracting for

Certain Telecommunications and

Video Surveillance Services or

Equipment

Prohibits use of equipment from entities covered by Section 889.

NIST SP 800-

116 Rev. 1

The use of PIV Credentials in

Physical Access Control Systems

(PACS)

This document provides the technical recipe for FICAM compliance.

NIST SP 800-53

Rev. 5

Security and Privacy Controls for

Information Systems and

Organizations

Establishes the mandatory baseline of security controls required for all federal information systems.

Document

Number Title Relevance

NIST SP 800-88

Rev. 1 Guidelines for Media Sanitization

Defines the required procedures for securely sanitizing data from legacy equipment prior to disposal.

DHS MD 4300A Sensitive Systems Policy Directive

Provides the foundational DHS policy for the security of all IT systems, including the ESS.

COMDTINST

M5500.13

Series

USCG Information and Technology

Management

Specifies USCG-specific policies for information assurance and cybersecurity.

1.4.2 Reference Documents

The following documents provide supplementary guidance:

Document

Number Title Relevance

NIST SP 800

Series

NIST Special Publications on

Cybersecurity and Privacy Computer Security Resources

ISC/RMP The Risk Management Process Baseline Security Requirements for

Government Facilities

FAR 31.205-46 Travel Costs Federal Travel Regulations

2.0 SPECIFIC REQUIREMENTS/TASKS

The Contractor shall perform the following tasks to complete the ESS modernization at Coast

Guard Station Bodega Bay.

2.1 TASK ONE. ELECTRONIC SECURITY SYSTEM (ESS)

SECURITY PLAN

The Contractor shall develop a comprehensive ESS Security Plan for the identified performance location. The plan will detail the design, equipment specifications, and installation layout for a new or updated electronic security system. The purpose of this plan is to ensure the proposed system meets all operational requirements, is compatible with existing infrastructure at Coast

Guard Base Alameda and is fully documented for government review and approval.

2.1.1 The Contractor shall perform the following tasks:

Conduct Site Survey: The Contractor shall perform a physical site survey to assess the current infrastructure, identify security vulnerabilities, and determine optimal locations for all proposed ESS components.

Develop Draft ESS Security Plan: The Contractor shall create a draft ESS Security Plan.

The plan must include, at a minimum:

A detailed Bill of Materials (BOM) listing all required hardware and software.

Manufacturer make and model numbers for all components. For all PACS components, the BOM must include the GSA APL approval number for each item, ensuring they are compatible with the existing ESS at Coast Guard Base Alameda for future integration.

Scaled floor plans and site maps indicating the precise installation location of each component (e.g., cameras, sensors, access control panels).

A network diagram illustrating how all components will be interconnected and integrated into the existing network infrastructure.

Submit for Review & Revision: The Contractor shall submit the draft plan to the designated Government representative(s) for review and feedback. The Contractor shall incorporate all Government-mandated changes and submit a final version for approval.

The Government is not responsible for providing software, hardware, or any other physical materials for the preparation of the ESS security plan.

2.1.2 Deliverables

The Contractor shall provide the following deliverables:

Deliverable # Title Due Date

1 Draft ESS Security Plan (PDF Format) TBD after award

2 Final, Approved ESS Security Plan (PDF Format) TBD after review

2.1.3 Acceptance Criteria

The Final ESS Security Plan shall be considered complete and acceptable when it has been formally approved in writing by the Southwest District Security Manager and a copy has been successfully delivered to the unit command (through the Command Security Officer or CSO).

2.1.4 Government Rights to Standalone Deliverables

The Government shall retain full rights and privileges to the resulting ESS Security Plan as a final product. Consistent with the "Unlimited Rights" provisions defined in Section 4.12, the

Government reserves the right to utilize the approved plan, including all technical specifications, Bill of Materials (BOM), and system designs, as a baseline for future competitive procurements or for implementation by other government or contracted entities.

2.2 TASK TWO. ESS MATERIAL PROCUREMENT AND

VERIFICATION

2.2.1 Scope

The Contractor shall take custody of any provided Government-Furnished Equipment (GFE), conduct functional testing to ensure its operational readiness, and procure any additional materials required to fulfill the Bill of Materials (BOM) in the approved ESS Security Plan. This task ensures a complete and fully functional set of materials is ready for the installation phase.

2.2.2 Government-Furnished Equipment (GFE)

If applicable, the Government will provide the Contractor with a detailed list of all government-furnished equipment intended for this project ("the GFE list"). The physical equipment will be made available to the Contractor for inventory and testing.

2.2.3 Specific Tasks

The Contractor shall perform the following tasks in sequence:

Inventory & Chain of Custody: The Contractor shall conduct a joint inventory with a

Government representative to verify that all items on the GFE list are present. Upon completion, the Contractor and the Government representative shall sign a Chain of

Custody document to formalize the transfer of equipment.

GFE Functional Testing: The Contractor shall test all GFE to ensure it is in good working order and fully operational according to manufacturer specifications. The

Contractor must provide the Government representative an opportunity to be present and visually witness all testing procedures of equipment.

Report Test Findings: The Contractor shall create and submit a GFE Test and

Verification Report to the Coast Guard unit Command Security Officer (CSO). This report shall certify the status of each item as either "Operational" or "Non-Operational." For Non-

Operational items, the report must detail the specific reason for failure.

Deficiency Resolution: The CSO will review the report and verify the findings for any

Non-Operational equipment. Following CSO verification, the Government's Contracting

Officer (or their Representative) will provide the Contractor with a formal decision to either: a) Receive a Government-provided replacement part for the defective GFE; or. b)

Direct the Contractor to procure a replacement part "in kind" as part of the contract.

Procure Remaining Materials: The Contractor shall procure all remaining materials specified in the approved ESS Security Plan that were not provided as operational GFE.

2.2.4 Deliverables

The Contractor shall provide the following deliverables:

Deliverable # Title Due Date

3 Signed Chain of Custody Document Within 2 days of receiving GFE

4 GFE Test and Verification Report Within 7 days of receiving GFE

2.2.5 Completion Date

All activities and deliverables under this task must be completed within fourteen (14) calendar days.

2.3 TASK THREE. DECOMMISSIONING AND DISPOSITION

OF LEGACY EQUIPMENT

2.3.1 Scope

The Contractor shall safely decommission, remove, and dispose of all legacy ESS components being replaced under this Statement of Work. This includes all cameras, exposed wiring, mounting hardware, and associated accessories. Equipment with data storage capabilities requires special handling and must be turned over to Government personnel.

2.3.2 Prerequisite for Commencement

The Contractor shall not begin any removal activities until all required materials from Task 2

(Section 2.2) are physically on-site and accounted for, unless the Contractor receives explicit, written approval from the Coast Guard unit CSO to proceed otherwise.

2.3.3 Specific Tasks

Disconnect and Segregate: The Contractor shall physically disconnect all legacy ESS equipment from power and network sources. Any device with internal memory or storage

(e.g., servers, recorders, computer-based controllers) must be segregated from general equipment.

Secure Handover of Sensitive Equipment: The Contractor shall physically transfer all segregated equipment with memory/storage capabilities to the Coast Guard unit CSO for final data sanitization and disposal in accordance with NIST SP 800-88, Guidelines for

Media Sanitization. A Sensitive Equipment Handover Form, which shall include the manufacturer, model, and serial number of each item, must be signed by both the

Contractor and the CSO to document the transfer.

Removal and Disposal: The Contractor shall remove all other legacy equipment, including cameras, wiring, conduits, and mounting assemblies. All resulting scrap and debris shall be disposed of legally and properly, in accordance with all applicable federal, state, and local environmental regulations.

2.3.4 Deliverables

The Contractor shall provide the following deliverables:

Deliverable

Title Due Date

Signed Sensitive Equipment Handover

Form (with Serial Numbers)

Upon transfer of legacy equipment to CSO

2.3.5 Completion Date

This task must be completed within fourteen (14) calendar days from the date of commencement.

2.4 TASK FOUR. ESS INSTALLATION, COMMISSIONING,

AND ACCEPTANCE

Install new equipment according to the ESS security plan.

2.4.1 Scope

The Contractor shall furnish all labor, tools, and materials necessary to install, test, and commission the new Electronic Security System (ESS). The installation must strictly adhere to the designs and standards specified in the approved ESS Security Plan. The ultimate goal of this task is to deliver a complete, turn-key system that is fully operational, documented, and accepted by the Government.

2.4.2 Specific Tasks

The Contractor shall perform the following tasks in a logical sequence:

Physical Installation: The Contractor shall install all new equipment, including cameras, sensors, control panels, servers, and workstations. This includes all wiring, conduit, and mounting hardware as detailed in the ESS Security Plan. All work shall be performed in a professional manner consistent with industry best practices and local building codes.

System Configuration & Integration: The Contractor shall power on and configure all hardware and software components. This includes, but is not limited to: setting IP addresses, configuring servers and recording schedules, programming access control rules, and integrating the system with the Government's network as specified in the plan.

System Acceptance Testing (SAT): Following installation and configuration, the

Contractor shall conduct a comprehensive SAT to demonstrate that all aspects of the system function as required. The Contractor must provide a System Acceptance Test Plan for Government review at least 48 hours prior to testing. The Government (including the

CSO) must be given the opportunity to witness the SAT. The SAT shall consist of two distinct phases: Functional Validation and Security Validation.

Functional Validation: The contractor shall demonstrate at a minimum:

Every camera displays a clear image and records properly.

Every sensor detects and reports alarms correctly.

The system correctly logs all events.

FICAM Compliance Validation: The Contractor shall demonstrate, using

Government-provided test PIV cards (including valid, revoked, and expired cards), the successful performance of the following at each access point:

Successful authentication using a valid PIV card in the required authentication mode (e.g., CARD + PIN).

Rejection of an expired PIV card.

Rejection of a revoked PIV card, demonstrating successful real-time certificate validation against a Certificate Authority (CA) using OCSP/SCVP.

Rejection of a non-PIV, legacy proximity card.

Correct and distinct logging of each of the above event types (valid access, denied-expired, denied-revoked, etc.) in the PACS head-end software.

Security Validation: The Contractor shall perform a security assessment of the newly installed system to validate its security posture. This shall include, at a minimum:

Vulnerability Scanning: The Contractor shall conduct authenticated vulnerability scans against all servers, workstations, and network devices that are part of the

ESS. The scans shall use credentials to provide a deep assessment of the system's configuration and patch level.

Remediation: The Contractor shall provide a report of all scan findings. All vulnerabilities categorized as "Critical" or "High" must be remediated by the

Contractor prior to final system acceptance. The Contractor shall perform a follow-on scan to validate that the vulnerabilities have been successfully remediated.

Operator Training: The Contractor shall provide on-site training for up to 5 working days to Government personnel. This training shall cover all day-to-day operational functions of the system, including but not limited to managing PIV certificates and credentials, viewing live and recorded video, managing alarms, and basic troubleshooting.

Documentation and Final Handover: The Contractor shall provide a complete documentation package, including "As-Built" drawings reflecting the final installation, all equipment manuals, admin usernames and passwords, and a final SAT report showing the successful test results. The Contractor shall deliver all system administrative credentials, encryption keys, and master passwords through a secure, out-of-band transfer mechanism. This shall consist of either a password-protected, encrypted digital vault (with the password provided via a separate communication channel) or a witnessed, physical hand-off of a sealed envelope to the Government CSO. Under no circumstances shall credentials be transmitted in clear text via email or included in the written Final

Documentation Package.

2.4.3 Deliverables

The Contractor shall provide the following deliverables:

Deliverable

Title Due Date

6 System Acceptance Test (SAT) Plan 48 hours prior to SAT

7 Vulnerability Scan Reports (Initial and Final) With SAT Report

8 Operator Training Session & Training Materials Prior to Final Acceptance

Final Documentation Package (including As-

Built Drawings and SAT Report)

Upon completion of all work

10 Security Assessment Report (SAR) With Final

Documentation Package

2.4.4 Acceptance Criteria

Final acceptance of this task will be granted only when all of the following conditions have been met:

The physical installation has been visually verified by a Government representative to conform to the ESS Security Plan.

The Government has witnessed a successful System Acceptance Test (SAT) where all components performed without deficiencies.

All required deliverables, including the Final Documentation Package and As-Built drawings, have been received.

The Government provides the Contractor with formal, written acceptance of the system.

2.4.5 Completion Date

This task, including the successful completion of the SAT, must be completed within fourteen

(14) calendar days from the date of commencement.

2.5 TASK FIVE. PHYSICAL ACCESS CONTROL SYSTEM

(PACS) TECHNICAL REQUIREMENTS

2.5.1 Scope

This task defines the mandatory technical requirements the new PACS must meet to be considered FIPS 201 / FICAM compliant. The Contractor shall be responsible for delivering a complete, turn-key solution that meets these specifications.

2.5.2 GSA Approved Products List (APL) Mandate

All components of a proposed PACS solution—including but not limited to controllers, card readers, software, and middleware—must be listed on the GSA FIPS 201 Approved Products

List (APL) under a valid, unexpired certification. The Contractor's ESS Security Plan must provide the APL certification number for each component.

2.5.3 End-to-End System Architecture

The proposed system must be a validated, end-to-end FICAM solution. The Contractor is responsible for ensuring all components function together as a compliant whole. The system architecture must follow the principles of the FICAM End-to-End High Assurance Architecture, ensuring secure communication from the card reader to the validation infrastructure.

2.5.4 Authentication and Certificate Validation

The PACS must be configured to perform identity authentication using PIV credentials in accordance with NIST SP 800-116.

Authentication Modes: The system must support, at a minimum, the CHUID + VIS

(Cardholder Unique Identifier + Visual) and PKI-CAK (Public Key Infrastructure - Card

Authentication Key) authentication mechanisms.

Certificate Validation: The system must be configured to perform real-time certificate validation for every PKI-based authentication. This shall be accomplished by communicating with a Certificate Authority (CA) using either the Online Certificate Status

Protocol (OCSP) or the Server-based Certificate Validation Protocol (SCVP). The ESS

Security Plan must detail the network path and configuration for this validation process.

3.0 CONTRACTOR PERSONNEL

3.1 QUALIFIED PERSONNEL

The Contractor shall provide appropriately qualified and trained personnel to perform all requirements specified in this Statement of Work (SOW). All personnel shall be fluent in English and be legally authorized to work in the United States.

3.2 CONTINUITY OF SUPPORT

The Contractor is responsible for ensuring that all project milestones and deliverable deadlines specified in this SOW are met. In the event any personnel are absent, the Contractor shall manage its workforce to ensure no impact on the project schedule. Any absence of Key

Personnel must be reported in advance to the Contracting Officer's Representative (COR).

3.3 KEY PERSONNEL

The Government considers the following positions to be Key Personnel. The individuals proposed for these roles are considered instrumental to the successful completion of this project. The Contractor shall provide the names, qualifications, and contact information for these individuals in their proposal.

Position Title Minimum Qualifications & Responsibilities

Project Manager (PM) and Alternate Project

Manager (APM)

Responsibilities:

Serve as the single point of contact for the Contracting Officer

(KO) and Contracting Officer's Representative (COR).

Be responsible for the overall management of all work performed under the agreement, including schedule, performance, and personnel.

Be available to the COR via telephone between 0900 and 1700

PST, Monday through Friday.

Respond to any Government request for discussion within twenty-four (24) business hours.

Minimum Qualifications:

A minimum of five (5) years of experience managing federal government contracts or technology installation projects of similar scope and complexity.

Position Title Minimum Qualifications & Responsibilities

Lead Certified

Technician

Responsibilities:

Serves as the primary technical point of contact for assigned projects.

Must be physically on-site during all activities related to equipment testing (Task 2) and installation/commissioning (Task

4).

Responsible for ensuring all installation work conforms to the ESS

Security Plan and manufacturer specifications.

Minimum Qualifications:

Must possess a current, valid certification for the primary ESS product line being installed as a Certified Professional. The specific, valid certification must be identified prior to award.

A minimum of five (5) years of hands-on experience installing and configuring electronic security systems of similar size and scope.

A minimum of three (3) years of demonstrated experience installing and configuring FIPS 201-compliant PACS solutions for

U.S. Federal Government agencies.

3.4 DUAL-HATTING OF KEY PERSONNEL

The roles of Project Manager and Lead Certified Technician may be filled by the same individual, provided that the proposed individual meets all the minimum qualifications and responsibilities for both positions as defined in the table above.

3.5 KEY PERSONNEL REPLACEMENT

The individuals designated as Key Personnel at the time of award shall be assigned for the duration of the agreement. The Contractor shall not replace any Key Personnel without prior written notification to the Contracting Officer (KO). Before replacement, the Contractor must notify the KO no less than fifteen (15) business days in advance and provide the qualifications of the replacement. Any replacement must possess qualifications, experience, and certifications equal or superior to the individual being replaced.

3.6 SECURITY AND IDENTIFICATION

3.6.1 Contractor Vetting and Access Requirements

The Contractor shall submit personnel information to the Government for all individuals requiring access to government facilities to perform work under this SOW.

The work will be conducted at United States government facilities. All personnel accessing

Government Property are subject to all applicable federal, state, and local laws, as well as

Coast Guard regulations, particularly the Coast Guard Physical Security Manual.

Enforcement of these regulations may include random personnel, and vehicle searches to ensure compliance with United States Coast Guard security.

Contract Construction Personnel: The Contractor shall provide a list of all on-site personnel, including sub-contractors (including second and third-tier subcontractors) and suppliers, to the Coast Guard. The contractor shall update this list when changes occur.

Contractor personnel not listed may be denied access to the Coast Guard facility.

Contractor personnel will be restricted to designated working areas. Any personnel violating this policy may lose access to the Coast Guard facility. Contractor personnel shall always have photo identification while working on Coast Guard facilities. Contractor and delivery personnel may be required to present personal photo identification to gain access to a Coast Guard installation. If identification does not indicate United States citizenship, Coast Guard Security may require proof of the legal right to work in the United

States. Contractor and delivery personnel also may be subjected to an immigration status and outstanding criminal warrants check.

The Contractor shall provide the following data for each employee to include sub-contractors (including second and third-tier subcontractors) and suppliers to the designated Government security point of contact (e.g., the unit CSO) no less than ten

(10) business days prior to their required access date.

# Data Element Description

1 Full Name Legal name as it appears on government-issued identification.

2 Date of Birth Month, Day, and Year.

3 Place of Birth City, State, and Country.

4 Citizenship Status e.g., U.S. Citizen, Lawful Permanent Resident.

# Data Element Description

Form I-9 Acceptable

Documents

Proof of legal work status in the United States according to

USCIS

Or

Full Nine Digit Social Security Number

6 Driver's License Info State of Issuance and License Number. This is only required if the contractor will be driving on the Coast Guard property.

3.6.2 On-Site Conduct and Identification

The Contractor shall ensure all its employees and subcontractors adhere to the following conduct and identification standards at all times while at a Government facility:

Accepted forms of identification for Contract Personnel: The Real ID Act of 2005 established minimum security standards for license issuance and production and prohibits

Federal agencies from accepting, for certain purposes, driver's licenses and identification cards from states not meeting the Act's minimum standards. To this purpose there are five states that are not in compliance with the Act, nor have they received an extension to come into compliance with the act. Those states are Maine, Minnesota, Missouri, Montana and Washington State as well as American Samoa. Anyone under this contract, including subcontractors, who holds a driver's license from any of the states without approved licenses and requires access to a military facility will be required to provide identification other than a driver's license to gain access. It is the responsibility of the

Contractor to ensure that they are in accordance with the Real ID Act and any other requirements for base access. For the states of Washington and Minnesota an enhanced driver's license is acceptable to gain access.

Display Identification: Always wear and display the Government-issued identification badge in plain view, above the waist.

Self-Identification: Clearly identify themselves as "Contractor" in all forms of communication, including but not limited to, meetings, answering telephones, and in email signature blocks.

Compliance: Comply with all site-specific security regulations, traffic laws, and escort policies.

3.6.3 Government Responsibilities

The Government, through its designated representative (e.g., unit CSO), will be responsible for the following:

Reviewing the Contractor's submitted personnel information.

Conducting necessary background checks and fitness determinations in accordance with

USCG policy.

Notifying the COR and the Contractor's Project Manager of any individual who is denied access.

Issuing appropriate Government identification badges to approved Contractor personnel.

Properly safeguarding and disposing of all submitted Personally Identifiable Information

(PII) once it is no longer needed.

3.7 CONTRACTOR EMPLOYEE CONDUCT

3.7.1 Professional Conduct

The Contractor shall be responsible for maintaining a high standard of conduct for all its employees and subcontractors. The Contractor shall ensure its personnel conduct themselves in a professional, orderly, and business-like manner at all times while on Government property.

All personnel shall comply with all applicable federal, state, and local laws, as well as all site-specific facility regulations and policies.

3.7.2 Prohibited Activities

While at any Government facility, Contractor employees and subcontractors are strictly prohibited from behaving in a manner that is counter to good order and discipline. Activities that are illegal at the federal, state, and local level are prohibited. The list below highlights some activities that are prohibited. This list is not all-inclusive.

Possession of firearms, explosives, or other dangerous weapons, either openly or concealed.

The use or being under the influence of alcohol or any illegal drugs.

Engaging in any form of harassment, discrimination, disruptive behavior, or fighting.

Unauthorized use or removal of Government property.

Willful damage to Government property.

Accessing or attempting to access areas for which they are not authorized.

3.7.3 Removal of Personnel for Misconduct or Security Concerns

The Contracting Officer (KO) or the Contracting Officer's Representative (COR) reserves the right to direct the immediate removal of any Contractor employee or subcontractor from the work site for any instance of misconduct or for any reason deemed necessary to protect the security and integrity of the facility and its mission. The KO or COR will notify the Contractor's

Project Manager of the removal directive. Upon such notification, the Contractor shall immediately remove the specified employee from Government property. The Contracting

Officer's determination in these matters shall be final.

3.7.4 Duty to Replace Personnel

In the event an employee is removed from the project for reasons of misconduct or security, the

Contractor shall be responsible for providing a fully qualified replacement. The proposed replacement is subject to the security vetting process outlined in Section 3.6. The Contractor shall provide a qualified replacement within five (5) business days of the removal notification, at no additional cost to the Government.

4.0 OTHER APPLICABLE CONDITIONS

4.1 SECURITY REQUIREMENTS

4.1.1 Background Investigation

All Contractor personnel performing work under this SOW shall undergo a background investigation. A Tier 4 (High Risk) investigation is required for any individual granted system administrator privileges. All other contractor employees requiring access to Government facilities or information must receive a favorable adjudication of a Tier 2 (Moderate Risk) investigation.

Accordingly, each Contractor employee requiring access to Government facilities or information under this contract must undergo and receive a favorable adjudication of the appropriate level of background investigation (Tier 2 or Tier 4, based on system access role). The Contractor shall ensure that each proposed employee completes and submits the appropriate questionnaire (SF 85P for Tier 2 / SF 85P-S for Tier 4), as directed by the Government's security office. Favorable adjudication of the required investigation is a mandatory prerequisite for any individual to be granted unescorted access to Government facilities, administrative access to systems, or access to the ESS Security Plan. The Government will not be responsible for any project delays caused by a Contractor employee failing to obtain a favorable background investigation determination.

4.1.2 Handling of Sensitive Information

All documentation, plans, and drawings generated or handled under this agreement, including but not limited to the ESS Security Plan and "As-Built" drawings, are designated as Controlled

Unclassified Information (CUI) and must be handled as such. The Contractor is responsible for safeguarding this information at all times. The Contractor shall not disclose, disseminate, or remove any CUI from the designated work site or release it to any party without the express written permission of the Contracting Officer.

4.1.3 Incident Response Procedures

Reporting Timelines: The Contractor shall report all suspected or confirmed security incidents to the Government Contracting Officer's Representative (COR) and the unit's

Command Security Officer (CSO) within one (1) hour of discovery. A formal written incident report must follow within 24 hours.

Reportable Incidents: Incidents that must be reported include, but are not limited to:

Security Incidents: Any actual or suspected data breach, loss of CUI or PII, unauthorized access to systems or facilities, malware detection, or theft of government or contractor property.

Safety Incidents: Any event resulting in injury, accidents, or hazardous conditions.

Compliance Violations: Any breach of contract terms or applicable laws and regulations.

Incident Report Content: Initial and formal incident reports shall be submitted in a format directed by the COR and must include, at a minimum:

Date, time, and location of the incident.

A detailed description of the incident and its known or suspected impact.

Names of any individuals involved or affected.

Immediate actions taken to contain the incident and recommended corrective measures.

Investigation and Follow-Up: The Contractor shall conduct a thorough investigation of all reported incidents, identify the root cause, and implement corrective actions to prevent recurrence. The Contractor shall provide follow-up reports to the COR to confirm the final resolution of the incident.

4.1.4 Cybersecurity Training

The contractor shall ensure that all personnel assigned to this contract, including subcontractors, complete government-approved cybersecurity awareness training prior to being granted access to any government information systems or controlled unclassified information

(CUI). This training shall include, at a minimum, instruction on recognizing and reporting cybersecurity threats, proper handling of sensitive information, and adherence to agency security policies. The contractor shall ensure all personnel complete this training annually.

Records of training completion shall be maintained by the contractor and made available to the government upon request.

4.1.5 Access Control Requirements

Role-Based Access Control (RBAC): The Contractor shall configure the Electronic

Security System (ESS) using the principle of least privilege. The system must support and be configured with Role-Based Access Control (RBAC) to ensure users are only granted the permissions necessary to perform their assigned duties.

Multi-Factor Authentication (MFA): The Contractor shall configure the ESS to require

Multi-Factor Authentication (MFA) for all administrative accounts and any accounts with permissions to alter system configurations, access audit logs, or manage other users.

Access Reviews: The Contractor shall provide the capability for the Government to generate comprehensive user access reports. The Contractor shall assist the Command

Security Officer (CSO) in conducting quarterly access reviews to identify and disable dormant, unauthorized, or inappropriate accounts.

4.1.6 Supply Chain Risk Management (C-SCRM)

Software Bill of Materials (SBOM): The Contractor shall provide a detailed Software Bill of Materials (SBOM) for all software, firmware, and operating systems deployed under this contract. The SBOM must align with NTIA (National Telecommunications and

Information Administration) minimum elements and be provided to the Government prior to system installation.

Hardware Integrity: The Contractor shall verify and document the integrity of all hardware and firmware components prior to installation. The Contractor must ensure that all devices (including cameras, controllers, and servers) are sourced through authorized, OEM-certified distribution channels. Procurement from prohibited sources or vendors listed under federal restriction lists is strictly prohibited.

Firmware Updates: The Contractor shall deliver all system components flashed with the most recent, stable, and vendor-signed firmware version. The Contractor shall document the current firmware version and provide a secure procedure for the Government to pull future security patches.

4.1.7 Government Audits and Compliance Verification

The Government reserves the right to conduct on-site inspections, audits, and security control assessments of the contractor's work, information systems, and security controls used in the performance of this contract to ensure compliance with the specified security requirements.

These assessments may be conducted by Government personnel or a Government-designated third party. The Contractor shall provide access to its facilities, personnel, documentation, and systems at reasonable times and as necessary for the Government to carry out these assessments. Any findings of non-compliance may result in a request for corrective action, and failure to resolve such findings in a timely manner may be considered a breach of contract.

4.1.8 IoT/Edge Device Security

Hardening: The Contractor shall harden all IoT and edge devices (e.g., IP cameras, door controllers, NVRs) in accordance with NIST IR 8259, Foundational Cybersecurity Activities for IoT Device Manufacturers. This includes disabling all unused services, ports, and protocols (e.g., Telnet, FTP, HTTP) that are not required for system operation.

Credential Management: The Contractor shall change all default manufacturer passwords for every device prior to installation. Each device must be configured with a unique, strong password. A master inventory of these credentials shall be maintained and delivered to the Government via the secure handover process defined in Section 2.4.2.5.

Secure Management: All administrative access to IoT/Edge devices must be conducted over encrypted channels (e.g., HTTPS, SSH). Direct internet exposure of these devices is strictly prohibited.

4.1.9 Deliverables

The Contractor shall provide the following deliverables:

Deliverable # Title Due Date

11 Software Bill of Materials (SBOM) Prior to System Installation

4.2 PERIOD OF PERFORMANCE

The period of performance for this contract shall be calendar days from the date of contract award. Cancellation of this contract may be initiated by the government or the contractor at any time during the performance period. Cancellation of the contract must occur no less than 30 days before the desired cancellation date. Cancellation of the contract must be a mutual agreement.

4.3 PLACE OF PERFORMANCE

The primary place of performance shall be Coast Guard Station Bodega Bay.

4.4 HOURS OF OPERATION

Normal Working Hours: The Contractor shall perform all on-site work during normal

Government working hours, defined as 0800 to 1700 PST, Monday through Friday, excluding Federal holidays.

Work Outside Normal Hours: Any work required outside of these hours, including weekends or holidays, must be requested and scheduled with the Contracting Officer's

Representative (COR) at least 48 hours in advance. The Contractor shall not perform work outside of normal hours without prior written approval from the COR.

FEDERAL HOLIDAYS: The Government observes the following federal holidays.

Contractor personnel are not expected to work on these days.

NEW YEAR’S DAY

MARTIN LUTHER KING, JR.’S BIRTHDAY

PRESIDENT’S DAY

MEMORIAL DAY

JUNETEENTH NATIONAL INDEPENDENCE DAY

INDEPENDENCE DAY

LABOR DAY

COLUMBUS DAY

VETERAN’S DAY

THANKSGIVING DAY

T BD

CHRISTMAS DAY

4.5 TRAVEL

This contract shall be inclusive of all costs associated with travel, lodging, and per diem for

Contractor personnel to and from the primary place of performance specified in Section 4.3. No separate travel costs will be reimbursed for work performed at the primary site.

4.5.1 Government-Directed Travel

No travel to locations other than the primary place of performance is anticipated under this contract. In the unlikely event that the Government requires the Contractor to travel to a different location (e.g., for a special meeting or inspection at another facility), the Contractor must obtain advance written authorization from the Contracting Officer (KO) prior to incurring any costs. If authorized, travel will be reimbursed in accordance with Federal Acquisition

Regulation (FAR) 31.205-46, Travel Costs.

4.6 POST AWARD CONFERENCE

The Contractor shall participate in a Post-Award Conference with the Contracting Officer (KO) and the Contracting Officer's Representative (COR). This conference will be held via teleconference no later than ten (10) business days after the date of contract award. The purpose of this meeting is to ensure a shared understanding of all requirements and to establish a clear path for successful project execution. The Contractor's Project Manager and Lead

Certified Technician are required to attend. Topics for discussion will include, at a minimum:

Introductions: Introduction of all Government and Contractor Key Personnel.

SOW Review: A detailed review of the SOW scope, tasks, deliverables, and timelines.

Project Schedule: Establishment and confirmation of the detailed project schedule, including milestone dates for each task.

Communication Plan: Formalizing the primary points of contact, communication methods, and frequency of status updates.

Security & Access: Review of the personnel security submission and facility access procedures.

Invoicing Procedures: Clarification of the process for submitting invoices for completed work.

Questions & Answers: An open forum for the Contractor to ask any clarifying questions about the project.

4.7 PROJECT SCHEDULE

The Contractor shall develop, submit, and maintain a detailed Project Schedule to ensure the timely completion of all work.

Submission and Approval: Upon contract award, the Contractor shall submit a formal, detailed Project Schedule to the COR for review and approval no later than five (5) business days after contract award.

Content and Format: The Project Schedule shall be delivered in a Gantt chart format

(e.g., Microsoft Project or PDF equivalent) and must, at a minimum:

Incorporate all major tasks, sub-tasks, and deliverables defined in the contract.

Clearly define the planned start date and completion date for each task.

Show the logical dependencies between tasks (e.g., Task 3 cannot start until Task 2 is complete).

Identify all major project milestones, including all deliverable due dates and planned

Government review periods.

Updates: The Contractor shall keep the Project Schedule current and provide an updated version to the COR within two (2) business days of any significant change to a milestone date.

4.7.1 Deliverables

The Contractor shall provide the following deliverables:

Deliverable

Title Due Date

Project

Schedule

No later than 5 business days after Post-Award

Conference

4.8 GOVERNMENT/CONTRACTOR COMMUNICATIONS

The Contractor shall provide contact information to ensure clear lines of communication in the event of an issue that impacts project operations. The Contractor shall provide a list of primary and alternate emergency points of contact to the COR for this contract. This list must be updated immediately if any information changes. The list shall include, at a minimum:

Role Name Primary Phone (Mobile) Alternate Phone Email

Project Manager

Alternate PM

Lead Technician

4.8.1 Deliverables

The Contractor shall provide the following deliverables:

Deliverable # Title Due Date

13 Emergency Contact List At Post-Award Conference

4.9 PROGRESS REPORTS

The Contractor's Project Manager shall submit a Weekly Project Status Report for this project to the COR and the KO via email. The report shall be delivered no later than close of business every Friday for the duration of the project, beginning the first week after the Post-Award

Conference.

The report shall be concise and, at a minimum, provide the following information:

Work Completed: A summary of work completed during the reporting period, referenced against the SOW tasks and the approved Project Schedule.

Work Planned: A summary of work planned for the next reporting period.

Schedule Status: An assessment of the project schedule, highlighting milestones achieved and noting any current or anticipated delays.

Risks and Issues: A description of any problems, risks, or issues encountered that could impact cost, schedule, or performance, along with proposed or implemented solutions.

Government Action Items: A list of any decisions, actions, or information required from the Government to prevent delays.

4.9.1 Deliverables

The Contractor shall provide the following deliverables:

Deliverable

Title Due Date

Weekly Project Status

Report

Every Friday, starting the week after Post-Award

Conference

4.10 PROGRESS MEETINGS

The Contractor shall participate in regularly scheduled progress meetings with the Government to ensure clear communication and proactive management of the project.

Frequency: Meetings will be held on a recurring day and time mutually agreed upon by the COR and the Contractor's Project Manager.

Attendees: The Contractor's Project Manager and Lead Certified Technician are required to attend. The Contracting Officer shall be invited to all meetings.

Agenda: The purpose of these meetings is to review project status, address risks, and resolve any issues. The Weekly Project Status Report (from Section 4.9) shall serve as the primary agenda for each meeting.

Format: All meetings will be held via teleconference unless otherwise directed by the

COR.

4.11 GENERAL REPORT AND DELIVERABLE

REQUIREMENTS

All reports, plans, schedules, documentation, and other digital deliverables required under this contract shall be provided by the Contractor in electronic format. These electronic deliverables must meet the following criteria:

Compatibility: Be fully compatible with current versions of Microsoft Office Suite applications (Word, Excel, PowerPoint, Project) used on Coast Guard workstations, ensuring full read/write and editing capabilities.

Format: Unless otherwise specified, deliverables shall be provided in native application formats (e.g., .docx, .xlsx, .pptx, .mpp) and, where appropriate, a corresponding Portable

Document Format (PDF) with searchable text.

Delivery Method: Delivered via email or through a secure file transfer method as directed by the COR.

4.12 INTELLECTUAL PROPERTY – GOVERNMENT RIGHTS

TO DELIVERABLES

Pre-existing Materials and Commercial Software: The Government’s rights to any commercial computer software, including Commercial-Off-The-Shelf (COTS) items and any other pre-existing materials or data not first produced in the performance of this contract, shall be the standard commercial license rights governing the use of such items.

The Contractor shall not incorporate any COTS or pre-existing materials into a deliverable without the Government's prior written approval.

Rights to Deliverables: The Government shall have unlimited rights to all data, documentation, and materials first produced and delivered in the performance of this contract. This includes, but is not limited to:

The ESS Security Plan.

All "As-Built" drawings and diagrams.

All system configuration files.

All reports, plans, and schedules.

All custom-developed training materials.

"Unlimited rights" means the right of the Government to use, disclose, reproduce, prepare derivative works, and distribute copies of the data in any manner and for any purpose, and to have or permit others to do so. The Contractor shall not use or assert any copyright or other proprietary rights in these materials that would restrict the Government's use.

4.13 PROTECTION OF INFORMATION

In the performance of this contract, the Contractor will be required to access and generate

Controlled Unclassified Information (CUI). This information is considered sensitive and is critical to the security of the facility. The Contractor is responsible for ensuring its strict protection from unauthorized disclosure or dissemination.

Definition of CUI: CUI is sensitive information that does not meet the criteria for classification but must still be protected. It is Government-created or owned UNCLASSIFIED information that allows for, or requires, safeguarding and dissemination controls in accordance with laws, regulations, or Government-wide policies. For the purposes of this SOW, CUI includes but is not limited to: the ESS Security Plan, network diagrams, system configuration data, "As-Built" drawings, IP addresses, and any information that reveals site-specific security measures or potential vulnerabilities.

Governing Directives: The Contractor shall handle, store, and transmit all CUI in strict accordance with all applicable laws and regulations, including but not limited to Department of

Homeland Security (DHS) Management Directive (MD) 11042.1, "Safeguarding Sensitive But

Unclassified (For Official Use Only) Information."

Mandatory Non-Disclosure Agreement: The Contractor shall ensure that every employee and subcontractor requiring access to CUI under this contract signs a Non-Disclosure Agreement

(DHS Form 11000-6). An executed copy of this form for each individual must be provided to the

COR prior to that individual being granted access to any CUI.

End of Agreement Procedures: Upon completion or termination of the contract, the Contractor shall, as directed by the COR, either return all CUI to the Government or destroy it in an approved manner. The Contractor shall provide a written certification to the KO that all CUI has been returned or destroyed.

4.13.1 Deliverables

The Contractor shall provide the following deliverables:

Deliverable

Title Due Date

15 Signed Non-Disclosure Agreements Prior to individual's access to CUI

Certificate of FOUO/CUI

Destruction/Return

No later than 15 days after contract completion

4.14 SECTION 508 ACCESSIBILITY REQUIREMENTS

4.14.1 General Requirement

All Information and Communications Technology (ICT) procured, developed, maintained, or used under this Statement of Work must conform to the Revised 508 Standards, as specified in

36 C.F.R. § 1194.1 and its appendices. This applies to all components of the solution, including but not limited to the servers, Video Surveillance System (VSS) software and hardware, Physical

Access Control System (PACS) software and hardware, and any associated user interfaces or documentation.

4.14.2 Applicable Standards

The following standards apply…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .