Statement of Work- Feb2023.pdf
PDF 165 KB Posted
- Attached to
- Access Control System Federal contract opportunity
- Solicitation number
- FA8601-23-R-0006
About this file
This statement of work outlines requirements for an access control system replacement project at Wright Patterson Air Force Base. The existing system controls access to 327 doors across 14 buildings using AccessNsite software run on a Quintron server. The replacement system must support PIV authentication of at least 50,000 users with credentials, control 2000 doors and readers, monitor 500 alarm points and outputs, and integrate with physical security cameras. The contractor will install the new system in compliance with DOD STIG and NIST SP800-53 security controls, providing all required RMF documentation. Maintenance and support is required for five years, including quarterly preventative maintenance inspections. The contractor must be a certified PACS integrator and provide training, installation documentation, and an annual maintenance report. The target award date is February 2023.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| QA 4.pdf | ||
| QA 3.pdf | ||
| AccessNsite 7.9.5 Operator's Manual smaller.pdf | ||
| Statement of Work- Updated.docx | DOCX document | |
| Copy of Access Control System.pdf | ||
| Sub-Controllers.pdf | ||
| White Board Drawing.pdf | ||
| QA 1.pdf | ||
| QA 2.pdf | ||
| Solicitation Amendment FA860123R00060001 SF 30.pdf | ||
| Solicitation - FA860123R0006.pdf | ||
| Solicitation Instructions AMC ACS.pdf |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Work (SoW)
For
Acquisition Management Complex (AMC) Access Control System (ACS)
Title: Acquisition Management Complex (AMC) Access Control System (ACS)
Document Date: 2 Feb 2023
1. Scope: The AMC ACS shall have all the necessary resources to handle access control of 327 access-controlled doors and 79 monitored only doors. These doors are spread across 14 buildings.
1.1. Background: The AMC at Wright Patterson AFB has a requirement to replace the one (1) server/system for monitoring/controlling access to buildings and individual room's while providing the same/enhanced capabilities of the existing system. The existing system is running AccessNsite from a
Quintron Server. All software installations will be performed by the contractor with physical oversight of government personnel. The government staff will follow guidelines provided by contractor to perform day-to-day system support.
2. Applicable Documents:
2.1. [HSPD-12] Homeland Security Presidential Directive 12, August 27, 2004 https://www.dhs.gov/homeland-security-presidential-directive-12
2.2. [FIPS 201] Federal Information Processing Standard 201-3, Personal Identity Verification (PIV) of
Federal Employees and Contractors http://csrc.nist.gov/publications/PubsFIPS.html
2.3. [Common] FPKIPA X.509 Certificate Policy For The U.S. Federal PKI Common Policy Framework, Version 2.2, December 1, 2021 https://www.idmanagement.gov/docs/fpki-x509-cert-policy-common.pdf
2.4. [FBCA] X.509 Certificate Policy For The Federal Bridge Certification Authority (FBCA), Version 2.36, May 6, 2022 https://www.idmanagement.gov/docs/fpki-x509-cert-policy-fbca.pdf
2.5. [APL] GSA Approved Products List https://www.idmanagement.gov/buy/#products
2.6. [E-PACS] FICAM Personal Identity Verification (PIV) in Enterprise Physical Access Control Systems
(E-PACS), Version 3.0, March 26, 2014 https://www.idmanagement.gov/docs/pacs-piv-epacs.pdf
2.7. [FRTC] FIPS 201 Evaluation Program Functional Requirements and Test Cases https://www.idmanagement.gov/fips201/
2.8. [M-05-24] Office of Management and Budget (OMB) Memorandum M-05-24, August 5, 2005 https://georgewbush-whitehouse.archives.gov/omb/memoranda/fy2005/m05-24.pdf
2.9. [M-06-18] OMB Memorandum M-06-18, June 30, 2006 https://georgewbush-whitehouse.archives.gov/omb/memoranda/fy2006/m06-18.pdf
2.10. [M-11-11] OMB Memorandum M-11-11, February 3, 2011 https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf
2.11. [Roadmap] FICAM Roadmap and Implementation Guidance, Version 2.0, December 2, 2011 https://playbooks.idmanagement.gov/docs/roadmap-ficam.pdf
2.12. [SP800-53-4] National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53- 4, April 2013 https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/archive/2015-01-22
2.13. [SP800-116] National Institute of Standards and Technology (NIST) Special Publication (SP) 800-116, June 2018 https://csrc.nist.gov/publications/detail/sp/800-116/rev-1/final
2.14. [RMF Security Controls] https://rmfks.osd.mil/rmf/ControlsandAuthorization/securitycontrols/Pages/BasicControlsExplorer.aspx
2.15. [ICD 705] Intelligence Community Standard (ICD) 705-1 https://www.dni.gov/files/NCSC/documents/Regulations/ICS-705-1.pdf
3. Requirements/Salient Characteristics:
3.1. The proposed ACS solution shall be capable of controlling access and providing live monitoring of access points from at least three operator location manned by authorized AMC security administrators.
3.2. The systems will have the ability to expand without Major IT system modifications, support current doors and be expandable for future doors. Expansion for additional doors derived from government customer request. Ideally, the system would be managed through updates to software only.
3.3. The proposed ACS must be expandable to include compatibility with a camera surveillance system.
https://www.dhs.gov/homeland-security-presidential-directive-12 http://csrc.nist.gov/publications/PubsFIPS.html https://www.idmanagement.gov/docs/fpki-x509-cert-policy-common.pdf https://www.idmanagement.gov/docs/fpki-x509-cert-policy-fbca.pdf https://www.idmanagement.gov/buy/#products https://www.idmanagement.gov/docs/pacs-piv-epacs.pdf https://www.idmanagement.gov/fips201/ https://georgewbush-whitehouse.archives.gov/omb/memoranda/fy2005/m05-24.pdf https://georgewbush-whitehouse.archives.gov/omb/memoranda/fy2006/m06-18.pdf https://georgewbush-whitehouse.archives.gov/omb/memoranda/fy2006/m06-18.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf https://playbooks.idmanagement.gov/docs/roadmap-ficam.pdf https://csrc.nist.gov/publications/detail/sp/800-53/rev-4/archive/2015-01-22 https://csrc.nist.gov/publications/detail/sp/800-116/rev-1/final https://rmfks.osd.mil/rmf/ControlsandAuthorization/securitycontrols/Pages/BasicControlsExplorer.aspx https://www.dni.gov/files/NCSC/documents/Regulations/ICS-705-1.pdf
3.4. The hardware and software installers and maintainers provided by this contract shall have completed the solution vendor’s recommended support training.
3.5. The keypads and door controls shall be a type that are all weather (suitable for geographical location "WPAFB Ohio") and can perform outside of buildings. The keypads will operate in both the contact and contactless modes, support a PIN interface, and will be capable of accepting all versions of the Common Access Cards (CACs) issued to military service members, federal employees, and contractors.
3.6. The access keypads will be LEDs illuminated for nighttime use.
3.7. The AMC ACS shall continue to function without network access to the host or commercial power (Minimum 24 hours).
3.8. Must allow for no degradation of system performance in the event of communication loss to the host (or actual loss of host).
3.9. The access-controlled systems will be segregated from all other networks.
3.10. The service provider would provide equipment, work force, and knowledge required to install, program, and test the software and hardware necessary for proper operation of the system. Then after the systems are installed and tested; the service provider will provide manufacture certification training for at least two (2) personnel and documentation to ensure AMC administrators understand how to use and perform basic troubleshooting of the system.
3.11. Regarding Physical Access Control System (PACS) Integrators or Installers, personnel that are listed on IDManagement.gov as a Certified System Engineer ICAM PACS must perform PACS configuration work performed under the awarded task. The certification must be current. Note: This certification program will provide necessary training and a minimum assurance of ability to implement PKI efficiently and effectively and federal ICAM architectures for Enterprise Physical Access Control Systems (E-PACS) and meet federal requirements.
3.12. The contracted service provider will have at its own discretion the option to use all or part of the existing access control systems. Any reused parts will fall under the new warranty defaulting back to original warranty start date.
3.13. The AMC ACS shall comply with all aspects of Homeland Security Presidential Directive 12 (HSPD-
12) and the Personal Identity Verification publication (PIV).
3.14. The contractor shall have experience maintaining HSPD-12/PIV compliant access control systems. This experience is necessary to ensure continuity for the AMC access control system compliance certification.
3.15. All hardware and software shall be compatible with the existing Base Information Transport Infrastructure (BITI). This infrastructure consists of Wright-Patterson AFB owned and maintained fiber lines between buildings.
3.16. OMB Memorandum M-06-18 [M-06-18] requires all agencies to use the General Services
Administration (GSA) Approved Products List [APL] in all procurements for HSPD-12 and Federal Information Processing Standard 201 [FIPS 201] compliant systems. The GSA FIPS 201 Evaluation Program lists compliant E-PACS solutions on the APL for procurements.
3.17. OMB Memorandum M-11-11 [M-11-11] requires all E-PACS systems at federally owned or leased buildings “be enabled to use PIV credentials” and that “agency processes must accept and electronically verify PIV credentials issued by other federal agencies.” M-11-11 further requires compliance with FICAM Roadmap and Implementation Guidance [Roadmap], which expands the use of PIV to include PIV Interoperable (PIV-I) credentials in FICAM compliant solutions. Both PIV and PIV-I credentials contain PKI digital certificates, fingerprint minutia templates, and a secure Personal Identification Number (PIN).
3.18. The system will support and use 2-Factor authentication as specified in FIPS-201 (PIN submitted to credential).
3.19. The system will provide live status of doors (e.g., locked, unlocked, open, closed etc.) Ability to know how long the doors have been in each status Example: Open door for 28 minutes.
3.20. Central systems will be a Windows based multi-tasking server that provides true 64-bit application with full DOD STIG compliance.
3.21. Access Control software will be based on the Windows-10 or newer SDC format.
3.22. Windows application based Building/Facility Management and Monitoring Systems used to control and monitor access and alarm activity.
3.23. System should have integrated room, area monitoring, and point monitoring. Any/all door statuses (open, locked, PIN enabled, etc.) should be recognized easily by identifiable text, color, or icon.
3.24. Provide controllers that offer various configurations of card reader inputs, relay outputs, and alarm inputs. Controllers must be able to be combined to provide the exact number of inputs and outputs required for each application. The controllers must provide fully distributed database architecture with real-time processing performed at each controller. Shall have the ability to download existing Windows based database and image files.
3.25. Shall have the ability to lock down of all doors by “lockdown mode”. Lockdown mode must be able to be initiated immediately without delay.
3.26. Shall have the ability to track by-pass key use (when a door is opened via a key).
3.27. All information (time, date, valid codes, access levels, etc.) is downloaded to the controllers so that each controller makes its own access control decisions.
3.28. No hierarchical or intermediate processors to make decisions for the controllers.
3.29. The host server is not required to make any decisions for the controllers including any global functions.
3.30. Provides instant response to card reads regardless of system size.
3.31. All time zones, access levels, linking events, holiday schedules, and global functions remain operational without communication to host.
3.32. Compatible with features like elevator control so readers can be used to separate floors via an elevator.
3.33. Controller operating system: Must reside in Flash ROM on each controller. It must be upgradeable through a download from the host server to each of the controllers in the system. Upgrades in controller operating system shall NOT require Programmable Read Only Memory (PROM) changes.
3.34. Controller shall continue to process access requests during information (time, date, valid codes, access levels, etc.) downloads.
3.35. Support a minimum 2000 readers and 2000 reader-controlled doors.
3.36. Support legacy 32-bit & 64-bit, transitional contact, and contactless & PIV II CAC card reader formats.
3.37. Support 50,000 cardholder’s total or up to 50,000 access codes/cards per location.
3.38. Support a minimum of 2000 alarm points.
3.39. Support a minimum of 500 programmable outputs.
3.40. Support a minimum of 50 time zones with each time zone having holiday overrides.
3.41. Support a minimum of 1,000 self-purging holidays.
3.42. Support a minimum of 100 user defined date fields.
3.43. Support a minimum of 100 system operators, each with a separate login.
3.44. Support a minimum of 100 operator comments.
3.45. Support a minimum of 500 graphic alarm maps for full input, output, and alarm handling.
3.46. Support a minimum import of .JPG, .GIF, .PNG, and AutoCAD .dxf graphic file types for maps.
3.47. Support a minimum of 100 custom action messages to instruct operator on action required when alarm is received.
3.48. Each controlled entry/exit shall have the ability to be locked (secured) and unlocked (open) or other mode changes through time zone or scheduled programming.
3.49. Each operator console shall have the ability to enable/disable each reader/keypad.
3.50. All cabling will be above the drop ceiling, in walls, or in conduit.
3.51. Each person/CAC shall have the ability to be enabled/disabled, limited times when usable, and be enabled/disabled for one or more devices for multiple time windows.
3.52. The system shall communicate using serial ports for direct connections, and onboard capability of
TCP/IP LAN for connections to the host server and between locations.
3.53. The serial ports used for communications shall be individually configurable for Direct Communications as an ASCII output port.
3.54. Direct serial line or Ethernet TCP/IP connection shall have no difference in monitoring or control of the System.
3.55. For TCP/IP communications, an option to set the Poll Frequency and Message Response Time Out settings shall be available. This will allow tuning for bandwidth and latency issues associated with network communications. For TCP/IP support for static IP, dynamic DNS, and DHCP-enabled networking.
3.56. The communication software on the central server shall actively monitor the controller to server communications link.
3.57. The communications shall be supervised when using either direct serial port connections, or TCP/IP LAN connections.
3.58. Loss of communications to any controller shall result in a communication loss alarm at server running the communications software.
3.59. When communications are restored to the controller all buffered events shall automatically upload to the central server and any database changes shall automatically be sent to the controller.
3.60. Must be operate on a stand-alone VLAN environment and not rely on any external network, internet connections, or cloud-based environment.
3.61. Must be capable of meeting all applicable security controls in NIST SP800-53-4 publication to be Authority to Operate (ATO) ready.
4. Description of Services and Maintenance Agreements.
4.1. The service provider will be solely responsible for the installation of the proposed new systems. The contractor shall provide all labor for corrective maintenance and preventive maintenance necessary to support the AMC ACS. Service shall be provided 24 hours a day and seven (7) days a week, including holidays. In cases where the integrity and security of buildings could be or is compromised, it may be necessary to provide emergency or expedited service on the system. Such emergency service would be initiated with a call to the contractor, and they would be expected to respond and resolve the issue within the allotted amount of time.
Normal response time shall be four (4) working hours following receipt of a service call. Emergency response time shall be within four (4) hours following receipt of a call. This would include nights, weekends, and holidays.
4.2. Access control equipment that is under service coverage shall receive one (1) Preventive Maintenance
(PM) inspection quarterly. Preventative maintenance shall include functional testing and adjusting all key components. All devices (card readers, reader interfaces, micro panels, door contacts and exit devices) shall be tested for proper operation. System power and standby batteries shall be verified and tested. Software updates shall be applied at the time of the PM, unless the software update available addresses security vulnerability and those shall be applied as soon as the update is available and when the customer has agreed.
4.3. The vendor shall be available to conduct functionality training once a quarter, if requested by the Government.
4.4. Included in the contract will be maintenance for the first year that includes everything not included in the equipment’s warranty. Four additional Contract Line Item Numbers (CLINs) covering year’s two through five. The contractor shall be responsible for providing maintenance service for all access control system components located throughout the buildings where the system exists. The overall concept of service maintenance is from the reader to the server (to include the software running the system). Those items/components covered within the SoW shall include:
4.4.1. Power supplies.
4.4.2. Batteries.
4.4.3. Card readers (and their interfaces).
4.4.4. Door contacts.
4.4.5. Request-to-exit devices.
4.4.6. Control panels.
4.4.7. Circuit boards.
4.4.8. Software (updates/version releases, software support (vendor and manufacturer).
4.5. Items having to do directly with the doors themselves are not covered. Those items would include electrified door hardware, non-electrified door hardware, door closers, handicap door operators, doors and door frames, drip shields, door sweeps, weather stripping and seals.
4.6. All work performed shall comply with Government and local laws, regulations, and instructions and be accepted by the customer.
5. Proposed Solution: Security professionals supporting E-PACS within agencies shall work very closely with the vendor community to ensure a solution that is fit for purpose in their unique environment.
Accordingly, an agency may use a vendor PACS solution that meets the agency's needs but is not yet on the APL - but only for a specified period. The vendor shall apply to the FIPS 201 Evaluation Program for evaluation and become listed on the APL within six months of contract award or replace all unapproved components with APL components at contractor expense. In addition, the following process and timeline on item(s) being added to the APL:
5.1. Within 30 days of contract award, the vendor must apply to the FIPS 201 Evaluation Program.
5.2. Within 60 days of contract award, the vendor must receive approval of its application.
5.3. Within 90 days of award, the vendor must be in an approved FIPS 201 Evaluation Program Lab for testing.
5.4. Within 6 months of contract award, the vendor's solution must be listed on the FIPS 201 Evaluation Program APL.
5.5. If after 6 months from contract award, the vendor's solution is not on the APL, then within 1 year of contract award, the vendor must replace the solution with one that is listed on the APL.
6. Deliverables.
6.1. The contractor shall provide all the necessary Risk Management Framework (RMF) documentation to include Ports and Protocol (PPS) on the Defense Information Systems Agency (DISA) current form. VDI
Topology, Hardware and Software lists for the entire VDI. DOD STIG report. ACAS Scan report with no Cat I or II, patch report to the AFLCMC/WB Information Systems Security Officer (ISSM) for approval/completeness. (After install)
6.2. The contractor will provide test results of every major component verifying it performs all the funct ions for Proposed Solution. (After install)
6.3. The contractor will provide Local training provided within 60 days of contract award .
6.4. The contractor shall provide AFLCMC/WB an Annual Preventive Maintenance Report documenting completion of the PACS annual Preventive Maintenance inspect ion.
Delivery Summary:
Performance/Deliverable
Objective
SOW
Paragraph
Performance Threshold
Topology 6.1 Virtual Topology in proposal and a final Topology including physical characteristics within 10 business days of installation completion.
DOD STIG Report 6.1 100% compliant or POAM approved by ISSO in place.
ACAS Scan 6.1 Each component scanned before final addition to network. Not CAT I or II present.
Component Test Results 6.2 Within 30 business days of installation completion.
Training 6.3 Local training provided within 60 days of contract award .
Annual Preventive
Maintenance Report
6.4 The report shall be submitted no later than 30 days prior to the
Option Exercise
7. Summary of Work Report: The contractor shall provide AFLCMC/WB a Summary of Work Report, each time maintenance service is performed. The report shall be submitted the same day of service before leaving the site; no specific format is required, just a simple summary of work performed.
8. Annual Preventative Maintenance Report: The contractor shall provide AFLCMC/WB an Annual Preventive Maintenance Report documenting completion of the PACS annual Preventive Maintenance inspect ion. The report shall contain recommend ations for component replacement in the system and/or system upgrades. The report shall be submitted no later than 30 days prior to the Option Exercise; no specific format is required, just a basic summary of inspection results with any recommendations.
Base Access: For contractor access to the Air Force Installation, the contractor shall obtain Common Access Cards (CACS or identification cards). The vendor will be required to pick-up their visitor’s pass at Pass and
Registration located in Area A, Bldg 286 4185 Logistics Ave, Dayton, Oh 45433 and give Micah Shoaf’s name as the sponsor. Temporary vehicle passes for 30-day periods will be requested for contractor personnel who do not have a CAC at the Wright-Patterson AFB (WPAFB) Gate IB Visitors' Center, as necessary. For those without CAC access to the base, temporary vehicle passes must be requested by the contractor to the government POC within AFLCMC/WB. Only government personnel can request the issuance of vehicle passes to the visitors' center staff.
File details come from the government source that posted it. Updated .