A.01.38_PN077779_AMIB_SPECIFICATIONS_RTA_VOL_3.pdf
PDF 1 MB Posted
- Attached to
- Aviation Maintenance Instructional Building, Fort Eustis, VA Federal contract opportunity
- Solicitation number
- W91236-18-B-0018
About this file
Specifications Volume 3
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| B.01.02_Abstract_of_Offers_Continuation_Sheet_Page_2_W91236-18-B-0018_AMIB.pdf | ||
| B.01.02_Abstract_of_Offers_Continuation_Sheet_Page_3_W91236-18-B-0018_AMIB.pdf | ||
| B.01.02_Abstract_of_Offers_Pg._1_W91236-18-B-0018_AMIB.pdf | ||
| AMENDMENT_0002_Attachment.pdf | ||
| W91236-18-B-0018_Amendment_0002.pdf | ||
| W91236-18-B-0018_Amendment_0001.pdf | ||
| Amendment_0001_Attachment.pdf | ||
| Site_Visit_Attendance_Sheet_18-B-0018.pdf | ||
| A.01.13_RTA_AMIB_DWGS_VOL_1.pdf | ||
| A.01.13_RTA_AMIB_DWGS_VOL_2.pdf | ||
| A.01.38_PN077779_AMIB_GEOTECHNICAL_REPORTS_VOL_4.pdf | ||
| Site_Visit_Access_Spreadsheet.xls | XLS spreadsheet | |
| LETTER_OF_COMMITMENT_FOR_SUBCONTRACTOR_sample.docx | DOCX document | |
| A.07.23_W91236-18-B-0018_Aviation_Maintenance_Instruction_Building_FINAL.pdf | ||
| A.01.38_PN077779_AMIB_SPECIFICATIONS_RTA_VOL_1.pdf | ||
| A.01.38_PN077779_AMIB_SPECIFICATIONS_RTA_VOL_2.pdf |
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
AVIATION MAINTENANCE TRAINING FACILITY Specifications – JUNE 2018
Property of the United States Government ‐ FOUO | For Official Use Only AS DIRECTED BY THE DTL Copying, Dissemination, and Distribution to Unauthorized Individuals Prohibited AS DIRECTED BY THE DTL
JUNE 2018
US Army Corps of Engineers
AVIATION MAINTENANCE TRAINING
FACILITY
Aviation Maintenance Instructional Building (AMIB)
General Instructional Building (GIB)
General Storage Building (GSE)
Multipurpose Room (MPR)
JOINT BASE LANGLEY EUSTIS
NEWPORT NEWS, VA
June 2018
Project Number: 077779 Norfolk District U.S. Army Corps of Engineers Engineering and Construction Division
Engineering Branch 803 Front Street Norfolk, VA 23510
SPECIFICATIONS
RTA SUBMITTAL
VOLUME 3
Aircraft Maintenance Instructional Building 793AMIB RTA Submittal
26 00 00.00 20 BASIC ELECTRICAL MATERIALS AND METHODS
26 08 00 APPARATUS INSPECTION AND TESTING
26 20 00 INTERIOR DISTRIBUTION SYSTEM
26 24 13 SWITCHBOARDS
26 28 01.00 10 COORDINATED POWER SYSTEM PROTECTION
26 29 23 VARIABLE FREQUENCY DRIVE SYSTEMS UNDER 600 VOLTS
26 41 00 LIGHTNING PROTECTION SYSTEM
26 51 00 INTERIOR LIGHTING
DIVISION 27 - COMMUNICATIONS
27 05 28.36 40 CABLE TRAYS FOR COMMUNICATIONS SYSTEMS
27 10 00 BUILDING TELECOMMUNICATIONS CABLING SYSTEM
DIVISION 28 - ELECTRONIC SAFETY AND SECURITY
28 31 33.00 10 FIRE ALARM REPORTING SYSTEM, RADIO TYPE
28 31 76 INTERIOR FIRE ALARM AND MASS NOTIFICATION SYSTEM
DIVISION 31 - EARTHWORK
31 00 00 EARTHWORK
31 11 00 CLEARING AND GRUBBING
31 31 16.13 CHEMICAL TERMITE CONTROL
31 62 13.20 PRECAST/PRESTRESSED CONCRETE PILES
DIVISION 32 - EXTERIOR IMPROVEMENTS
32 11 16.16 BASE COURSE FOR SUBBASE COURSE FOR PERVIOUS PAVING
32 11 23 AGGREGATE BASE COURSE
32 11 24 GRADED CRUSHED AGGREGATE BASE COURSE FOR PERVIOUS PAVEMENT
32 12 16 HOT-MIX ASPHALT (HMA) FOR ROADS
32 13 13.06 PORTLAND CEMENT CONCRETE PAVEMENT FOR ROADS AND SITE
FACILITIES
32 16 13 CONCRETE SIDEWALKS AND CURBS AND GUTTERS
32 16 15 CONCRETE BLOCK PAVEMENTS
32 17 24.00 10 PAVEMENT MARKINGS
32 31 13 CHAIN LINK FENCES AND GATES
32 92 19 SEEDING
DIVISION 33 - UTILITIES
33 40 00 STORM DRAINAGE UTILITIES
33 71 02 UNDERGROUND ELECTRICAL DISTRIBUTION
33 82 00 TELECOMMUNICATIONS OUTSIDE PLANT (OSP)
DIVISION 41 - MATERIAL PROCESSING AND HANDLING EQUIPMENT
41 22 13.15 BRIDGE CRANES, OVERHEAD ELECTRIC, UNDER RUNNING
-- End of Project Table of Contents --
PROJECT TABLE OF CONTENTS Page 1
-- PROJECT TABLE OF CONTENTS --
25 05 11 25 10 10
25 50 00
CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS
UTILITY MONITORING AND CONTROL SYSTEM (UMCS) FRONT END
AND INTEGRATION
CYBERSECURITY OF FACILITY-RELATED CONTROL SYSTEMS
DIVISION 26 - ELECTRICAL
DIVISION 25 - INTEGRATED AUTOMATION
SECTION 25 05 11
CYBERSECURITY FOR FACILITY-RELATED CONTROL SYSTEMS
11/17
PART 1 GENERAL
Many subparts in this Section contain text in curly braces ("{" and "}") indicating which cybersecurity control and control correlation identifier (CCI) the requirements of the subpart relate to. The text inside these curly braces is for Government reference only, and enables coordination of the requirements of this Section with the RMF process throughout the design and construction process. Text in curly braces are not contractor requirements.
This Section refers to Security Requirements Guide (SRGs) and Security Technical Implementation Guide (STIGs). STIGs and SRGs are are available online at the Information Assurance Support Environment (IASE) website at http://iase.disa.mil/stigs/Pages/index.aspx. Not all control system components have applicable STIGs or SRGs.
1.1 RELATED REQUIREMENTS
All Sections containing facility-related control systems or control system components are related to the requirements of this Section. Review all specification sections to determine related requirements.
1.1.1 FIRE ALARM AND MASS NOTIFICATION SYSTEM
Current base wide Fire Alarm and Mass Notification system possess an Authority to Operate (ATO) under Department of Defense Information Assurance Certification (DIACAP) with the Air Force.
The current ATO is set to expire in 2019 and transition to Risk Management Framework (RMF) in the same year.
Anticipated level of work is to prepare the building level controls in accordance with the active Request for Change Process outlined in the active ATO of the system. The vendor will be responsible for ensuring the controls installed meet or exceed the current systems baseline security configuration as well as meeting the criteria of UFC 4-010-06.
1.1.2 HVAC CONTROLS
Current base wide Energy Monitoring Control System (EMCS) possess an Authority to Operate (ATO) under Department of Defense Information Assurance Certification (DIACAP) with the Air Force.
The current ATO is set to expire in 2019 and transition to Risk Management Framework (RMF) in the same year.
Anticipated level of work is to prepare the building level controls in accordance with the active Request for Change Process outlined in the active ATO of the system. The vendor will be responsible for ensuring the
SECTION 25 05 11 Page 1 controls installed meet or exceed the current systems baseline security configuration as well as meeting the criteria of UFC 4-010-06.
1.2 REFERENCES
The publications listed below form a part of this specification to the extent referenced. The publications are referred to within the text by the basic designation only.
AMERICAN SOCIETY OF HEATING, REFRIGERATING AND AIR-CONDITIONING
ENGINEERS (ASHRAE)
ASHRAE 135 (2016; INT 1 2016; ERTA 1 2016) BACnet—A Data Communication Protocol for Building Automation and Control Networks
INSTITUTE OF ELECTRICAL AND ELECTRONICS ENGINEERS (IEEE)
IEEE 802.1x (2010) Local and Metropolitan Area Networks - Port Based Network Access Control
NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY (NIST)
NIST FIPS 201-2 (2013) Personal Identity Verification (PIV) of Federal Employees and Contractors
U.S. DEPARTMENT OF DEFENSE (DOD)
DODI 8551.01 (2014) Ports, Protocols, and Services Management (PPSM)
DTM 08-060 (2008) Policy on Use of Department of Defense (DoD) Information Systems - Standard Consent Banner and User Agreement
UFC 4-010-06 (2017) Cybersecurity of Facility-Related Control Systems, with Change 1
1.3 DEFINITIONS
1.3.1 Computer
As used in this Section, a computer is one of the following:
a. a device running a non-embedded desktop or server version of Microsoft Windows
b. a device running a non-embedded version of MacOS
c. a device running a non-embedded version of Linux
d. a device running a version or derivative of the Android OS, where Android is considered separate from Linux
e. a device running a version of Apple iOS
SECTION 25 05 11 Page 2
1.3.2 Network Connected
A component is network connected (or "connected to a network") only when the device has a network transceiver which is directly connected to the network and implements the network protocol. A device lacking a network transceiver (and accompanying protocol implementation) can never be considered network connected. Note that a device connected to a non-IP network is still considered network connected (an IP connection or IP address is not required for a device to be network connected).
Any device that supports wireless communication is network connected, regardless of whether the device is communicating using wireless.
1.3.3 User Account Support Levels
The support for user accounts is categorized in this Section as one of three levels:
1.3.3.1 FULLY Supported
Device supports configurable individual accounts. Accounts can be created, deleted, modified, etc. Privileges can be assigned to accounts.
1.3.3.2 MINIMALLY Supported
Device supports a small, fixed number of accounts (perhaps only one).
Accounts cannot be modified. A device with only a "User" and an "Administrator" account would fit this category. Similarly, a device with two PINs for logon - one for restricted and one for unrestricted rights would fit here (in other words, the accounts do not have to be the traditional "user name and password" structure).
1.3.3.3 NOT Supported
Device does not support any Access Enforcement therefore the whole concept of "account" is meaningless.
1.3.4 User Interface
Generally, a user interface is hardware on a device allowing user interaction with that device via input (buttons, switches, sliders, keyboard, touch screen, etc.) and a screen. There are three types of user interfaces defined in this Section: Limited Local User Interface, Full Local User Interface and Remote User Interface. In this Section, when the term "User Interface" is used without specifying which type, it refers only to Full Local User Interface and Remote User Interface (NOT to Limited Local User Interface).
1.3.4.1 Limited Local User Interface
A Limited Local User Interface is a user interface where the interaction is limited, fixed at the factory, and cannot be modified in the field. The user must be physically at the device to interact with it.
Examples of Limited Local User Interface include thermostats (Space Sensor Modules as defined in Section 23 09 13 INSTRUMENTATION AND CONTROL DEVICES
FOR HVAC).
SECTION 25 05 11 Page 3
1.3.4.2 Full Local User Interface
A Full Local User Interface is a user interface where the interaction and displays are field-configurable.
Examples of a Full Local User Interface include local applications on a computer and user interfaces to Variable Speed Drives.
1.3.4.3 Remote User Interface
A Remote User Interface is a user interface on a Client device allowing user interaction with a different Server device. The user need not be physically at the Server device to interact with it.
Examples of Remote User Interfaces include web browsers and Local Display Panels as defined in Section 23 09 00 INSTRUMENTATION AND CONTROL FOR HVAC.
1.4 ADMINISTRATIVE REQUIREMENTS
1.4.1 Coordination
Coordinate the execution of this Section with the execution of all other Sections related to control systems as indicated in the paragraph RELATED REQUIREMENTS. Items that must be considered when coordinating project efforts include but are not limited to:
a. If requesting permission for wireless communication, the Wireless Communication Request submittal must be approved prior to control system device selection and integration.
b. If requesting permission for alternate account lock permissions, the Device Account Lock Exception Request must be approved prior to control system device selection and integration.
c. If requesting permission for the use of a device with multiple IP connections, the Multiple IP Connection Device Request must be approved prior to control system device selection and integration.
d. Wireless testing may be required as part of the control system testing. See requirements for the Wireless Communication Test Report submittal.
e. If the Device Audit Record Upload Software is to be installed on a computer not being provided as part of the control system, coordination is required to identify the computer on which to install the software.
f. Cybersecurity Interconnection Schedule must be coordinated with other work that will be interconnected to, and interconnections must be approved by the Government before relying on them for system functionality.
g. Cybersecurity testing support must be coordinated across control systems and with the Government cybersecurity testing schedule.
h. Passwords must be coordinated with the indicated contact for the project site.
i. If applicable, HTTP web server certificates must be obtained from the indicated contact for the project site.
SECTION 25 05 11 Page 4
j. Contractor Computer Cybersecurity Compliance Statements for each contractor using contractor owned computers.
1.5 SUBMITTALS
Government approval is required for submittals with a "G" designation;
submittals not having a "G" designation are for information only. When used, a designation following the "G" designation identifies the office that will review the submittal for the Government. Submittals with an "S" are for inclusion in the Sustainability eNotebook, in conformance with Section 01 33 29 SUSTAINABILITY REPORTING. Submit the following in accordance with Section 01 33 00 SUBMITTAL PROCEDURES:
SD-01 Preconstruction Submittals
Device Account Lock Exception Request; G, HNC
Multiple IP Connection Device Request; G, HNC
Contractor Computer Cybersecurity Compliance Statements; G, HNC
Contractor Temporary Network Cybersecurity Compliance Statements; G, HNC
SD-02 Shop Drawings
User Interface Banner Schedule; G, HNC
Network Communication Report; G, HNC
Cybersecurity Riser Diagram; G, HNC
Control System Inventory Report; G, HNC
Cybersecurity Interconnection Schedule; G, HNC
SD-03 Product Data
Control System Cybersecurity Documentation; G, HNC
SD-07 Certificates
Software Licenses; G, HNC
SD-11 Closeout Submittals
Password Summary Report; G, HNC
Software Recovery And Reconstitution Images; G, HNC
Device Audit Record Upload Software; G, HNC
1.6 CYBERSECURITY DOCUMENTATION
1.6.1 Cybersecurity Interconnection Schedule
{For Reference Only: This subpart (and its subparts) relates to CA-3(b), SECTION 25 05 11 Page 5
CCI-00258}
Provide a completed Cybersecurity Interconnection Schedule documenting connections between the installed system and other systems. Provide the following information for each device communicating between systems: Device Identifier, Device Description, Transport layer Protocol, Network Address, Port (if applicable), MAC (Layer 2) address (if applicable), Media, Application Protocol, Service (if applicable), Descriptive Purpose of communication. If other control system Sections used on this project include submittals documenting this information, provide copies of those submittals to meet this requirement.
In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Cybersecurity Interconnection Schedule as an editable Microsoft Excel file (a template Cybersecurity Interconnection Schedule in Excel format is available at http://www.wbdg.org/FFC/NAVGRAPH/graphtoc.pdf.)
1.6.2 Network Communication Report
{For Reference Only: This subpart (and its subparts) relates to CA-9;
CCI-002102, CCI-002103, CCI-002104, CCI-002105 and also the submittal requirements associated with CM-6, CM-7 and SC-41}
Provide a network communication report. For each networked controller, document the communication characteristics of the controller including communication protocols, services used, and a general description of what information is communicated over the network. For each controller using IP, document all TCP and UDP ports used. If other control system Sections used on this project include submittals documenting this information, provide copies of those submittals to meet this requirement.
In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Network Communication Report as an editable Microsoft Excel file.
1.6.3 Control System Inventory Report
{For Reference Only: This subpart (and its subparts) relates to CM-8(a), CP-12, SI-17, IA-3; CCI-000389, CCI-000392, CCI-000398, CCI-002855, CCI-002856, CCI-002857, CCI-002773, CCI-002774, CCI-002775, CCI-000777, CCI-000778, CCI-001958}
Provide a Control System Inventory report using the Inventory Spreadsheet listed under this Section at http://www.wbdg.org/FFC/NAVGRAPH/graphtoc.pdf documenting all networked devices, including network infrastructure devices.
For each device provide all applicable information for which there is a field on the spreadsheet in accordance with the instructions on the spreadsheet.
In addition to the requirements of Section 01 33 00 SUBMITTAL PROCEDURES, provide the Control System Inventory Report as an editable Microsoft Excel file.
1.6.4 Software Recovery and Reconstitution Images
{For Reference Only: This subpart (and its subparts) relates to CP-10;
CCI-000550, CCI-000551, CCI-000552}
SECTION 25 05 11 Page 6
For each computer on which software is installed under this project, provide a recovery image of the final as-built computer. This image must allow for bare-metal restore such that restoration of the image is sufficient to restore system operation to the imaged state without the need for re-installation of software.
1.6.5 Cybersecurity Riser Diagram
{For Reference Only: This subpart (and its subparts) relates to PL-2(a);
CCI-003051, CCI-003053}
Provide a cybersecurity riser diagram of the complete control system including all network and controller hardware. If the control system specifications require a riser diagram submittal, provide a copy of that submittal as the cybersecurity riser diagram. Otherwise, provide a riser diagram in one-line format overlayed on a facility schematic.
1.6.6 Control System Cybersecurity Documentation
This subpart (and its subparts) relates to SA-5 (a),(b),(c); CCIs:
CCI-003124, CCI-003125, CCI-003126, CCI-003127, CCI-003128, CCI-003129,
CCI-003130, CCI-003131}
Provide a Control System Cybersecurity Documentation submittal containing the indicated information for each device and software application.
1.6.6.1 Software Applications
For all software applications running on computers provide:
a. administrator documentation that describes secure configuration of the software {relates to CCI-003124}
b. administrator documentation that describes secure installation of the software {relates to CCI-003125}
c. administrator documentation that describes secure operation of the software {relates to CCI-003124}
d. administrator documentation that describes effective use and maintenance of security functions or mechanisms for the software {relates to CCI-003127}
e. administrator documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the software {relates to CCI-003128}
f. user documentation that describes user-accessible security functions or mechanisms in the software and how to effectively use those security functions or mechanisms {relates to CCI-003129}
g. user documentation that describes methods for user interaction which enables individuals to use the software in a more secure manner {relates to CCI-003130}
h. user documentation that describes user responsibilities in maintaining the security of the software {relates to CCI-003131}
SECTION 25 05 11 Page 7
1.6.6.2 For HVAC Control System Devices
1.6.6.2.1 HVAC Control System Devices FULLY Supporting User Accounts
For all HVAC Control System Devices which FULLY support user accounts, provide:
a. Documentation that describes secure configuration of the device {for reference only: relates to CCI-003124}
b. Documentation that describes secure operation of the device {for reference only: relates to CCI-003124}
c. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {for reference only: relates to
CCI-003127}
d. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {for reference only: relates to CCI-003128}
e. Documentation that describes user-accessible security functions or mechanisms in the device and how to effectively use those security functions or mechanisms; or a specific indication that there are no user-accessible security functions or mechanisms in the device {for reference only: relates to CCI-003129}
f. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {for reference only: relates to CCI-003130}
1.6.6.2.2 All Other HVAC Control System Devices
For all HVAC Control System Devices which do not FULLY support user accounts, provide:
a. Documentation that describes secure configuration of the device; or a specific indication that there are no secure configuration steps that apply {for reference only: relates to CCI-003124}
b. Documentation that describes effective use and maintenance of security functions or mechanisms for the device; or a specific indication that there are no security functions or mechanisms in the device {for reference only: relates to CCI-003127}
c. For devices which include a user interface, documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {for reference only: relates to
CCI-003130}
1.6.6.3 Default Requirements for Control System Devices
For control system devices where Control System Cybersecurity Documentation requirements are not otherwise indicated in this Section, provide:
a. Documentation that describes secure configuration of the device {for reference only: relates to CCI-003124}
SECTION 25 05 11 Page 8
b. Documentation that describes secure installation of the device {for reference only: relates to CCI-003125}
c. Documentation that describes secure operation of the device {for reference only: relates to CCI-003124}
d. Documentation that describes effective use and maintenance of security functions or mechanisms for the device {for reference only: relates to
CCI-003127}
e. Documentation that describes known vulnerabilities regarding configuration and use of administrative (i.e. privileged) functions for the device {for reference only: relates to CCI-003128}
f. Documentation that describes user-accessible security functions or mechanisms in the device and how to effectively use those security functions or mechanisms {for reference only: relates to CCI-003129}
g. Documentation that describes methods for user interaction which enables individuals to use the device in a more secure manner {for reference only: relates to CCI-003130}
h. Documentation that describes user responsibilities in maintaining the security of the device {for reference only: relates to CCI-003131}
1.7 SOFTWARE UPDATE LICENSING
{For Reference Only: This subpart (and its subparts) relates to SI-2 (a),(c); CCI-001227, CCI-002605}
In addition to all other licensing requirements, all software licensing must include licensing of the following software updates for a period of no less than 5 years:
a. Security and bug-fix patches issued by the software manufacturer.
b. Security patches to address any vulnerability identified in the National Vulnerability Database at http://nvd.nist.gov with a Common Vulnerability Scoring System (CVSS) severity rating of MEDIUM or higher.
Provide a single Software Licenses submittal with documentation of the software licenses for all software provided
1.8 CYBERSECURITY DURING CONSTRUCTION
{For Reference Only: This subpart (and its subparts) relates to AC-18, SA-3, CCI-00258}
In addition to the control system cybersecurity requirements indicated in this section, meet following requirement throughout the construction process.
1.8.1 Contractor Computer Equipment
Contractor owned computers may be used for construction. When used, contractor computers must meet the following requirements:
SECTION 25 05 11 Page 9
1.8.1.1 Operating System
The operating system must be an operating system currently supported by the manufacturer of the operating system. The operating system must be current on security patches and operating system manufacturer required updates.
1.8.1.2 Anti-Malware Software
The computer must run anti-malware software from a reputable software manufacturer. Anti-malware software must be a version currently supported by the software manufacturer, must be current on all patches and updates, and must use the latest definitions file. All computers used on this project must be scanned using the installed software at least once per day.
1.8.1.3 Passwords and Passphrases
The passwords and passphrases for all computers must be changed from their default values. Passwords must be a minimum of eight characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.
1.8.1.4 Contractor Computer Cybersecurity Compliance Statements
Provide a single submittal containing completed Contractor Computer Cybersecurity Compliance Statements for each company using contractor owned computers. Contractor Computer Cybersecurity Compliance Statements must use the template published at http://www.wbdg.org/FFC/NAVGRAPH/graphtoc.pdf.
Each Statement must be signed by a cybersecurity representative for the relevant company.
1.8.2 Temporary IP Networks
Temporary contractor-installed IP networks may be used during construction.
When used, temporary contractor-installed IP networks must meet the following requirements:
1.8.2.1 Network Boundaries and Connections
The network must not extend outside the project site and must not connect to any IP network other than IP networks provided under this project or Government furnished IP networks provided for this purpose. Any and all network access from outside the project site is prohibited.
1.8.3 Government Access to Network
Government personnel must be allowed to have complete and immediate access to the network at any time in order to verify compliance with this specification
1.8.4 Temporary Wireless IP Networks
In addition to the other requirements on temporary IP networks, temporary wireless IP (WiFi) networks must not interfere with existing wireless network and must use WPA2 security. Network names (SSID) for wireless networks must be changed from their default values.
SECTION 25 05 11 Page 10
1.8.5 Passwords and Passphrases
The passwords and passphrases for all network devices and network access must be changed from their default values. Passwords must be a minimum 8 characters with a minimum of one uppercase letter, one lowercase letter, one number and one special character.
1.8.6 Contractor Temporary Network Cybersecurity Compliance Statements
Provide a single submittal containing completed Contractor Temporary Network Cybersecurity Compliance Statements for each company implementing a temporary IP network. Contractor Temporary Network Cybersecurity Compliance Statements must use the template published at http://www.wbdg.org/FFC/NAVGRAPH/graphtoc.pdf. Each Statement must be signed by a cybersecurity representative for the relevant company. If no temporary IP networks will be used, provide a single copy of the Statement indicating this.
1.9 CYBERSECURITY DURING WARRANTY PERIOD
All work performed on the control system after acceptance must be performed using Government Furnished Equipment or equipment specifically and individually approved by the Government.
PART 2 PRODUCTS
(NOT USED)
PART 3 EXECUTION
3.1 ACCESS CONTROL REQUIREMENTS
3.1.1 User Accounts
{For Reference Only: This subpart (and its subparts) relate to AC-2(a)and
AC-3; CCI-002110, CCI-000213.}
Any device supporting user accounts (either FULLY or MINIMALLY) must limit access to the device according to specified limitations for each account.
Install and configure any device having a STIG or SRG in accordance with that STIG or SRG.
3.1.1.1 Computers
All computers must FULLY support user accounts.
3.1.1.2 For HVAC Control System Devices
Devices with web interfaces must either FULLY support user accounts or have their web interface disabled. Field devices with full local user interfaces allowing modification of data must at least MINIMALLY support user accounts.
3.1.1.3 Default Requirements for Control System Devices
For control system devices where User Account requirements are not otherwise indicated in this Section:
a. Devices with web interfaces must either FULLY support user accounts or
SECTION 25 05 11 Page 11 have their web interface disabled.
b. Field devices with full local user interfaces allowing modification of data must at least MINIMALLY support user accounts.
3.1.2 Unsuccessful Logon Attempts
{For Reference Only: This subpart (and its subparts) relate AC-7 (a), AC-7 (b); CCI-000043, CCI-000044, CCI-001423, CCI-002236, CCI-002237, CCI-002238}
Except for high availability user interfaces indicated as exempt, devices must meet the indicated requirements for handling unsuccessful logon attempts.
3.1.2.1 Devices MINIMALLY Supporting Accounts
Devices which MINIMALLY support accounts are not required to lock based on unsuccessful logon attempts.
3.1.2.2 Devices FULLY Supporting Accounts
Devices which FULLY support accounts must meet the following requirements.
If a device cannot meet these requirements, document device capabilities to protect from subsequent unsuccessful logon attempts and propose alternate protections in a Device Account Lock Exception Request submittal. Do not implement alternate protection measures without explicit permission from the Government.
a. It must lock the user account when three unsuccessful logon attempts occur within a 15 minute interval.
b. Once an account is locked, the account must stay locked until unlocked by an administrator.
c. Once the indicated number of unsuccessful logon attempts occurs, delay further logon prompts by 5 seconds.
3.1.2.3 High Availability Interfaces Exempt from Unsuccessful Logon Attempts Requirements
There are no high availability interfaces which are exempt from unsuccessful logon attempts requirements.
3.1.3 System Use Notification
{For Reference Only: This subpart (and its subparts) relates to AC-8;
CCI-000048, CCI-002247, CCI-002243, CCI-002244, CCI-002245, CCI-002246,
CCI-000050, CCI-002248}
Web interfaces must display a warning banner meeting the requirements of
DTM 08-060.
Devices which are connected to a network and have a user interface must display a warning banner meeting the requirements of DTM 08-060 if capable of doing so. Devices which are connected to a network and have a user interface but are not capable of displaying a banner must have a permanently affixed label displaying an approved banner from DTM 08-060.Labels
SECTION 25 05 11 Page 12 must be machine printed or engraved, plastic or metal, designed for permanent installation, must use a font no smaller than 14 point, and must provide a high contract between font and background colors.
3.1.3.1 User Interface Banner Schedule
Provide a User Interface Schedule using the format indicated showing each user interface provided and how the information banner requirement has been implemented for each user interface.
User Interface Schedule Format (with sample entries)
User Interface Description
User Interface Location
Type of User Interface
Banner Implementation
Sample 1 Room 1 Remote DTM 08-060 Banner "A" Displayed at Logon
Sample 2 Room 2 Limited Local DTM 08-060 Banner "B" on Affixed Label
Sample 3 Room 3 Full Local DTM 08-060 Banner "B" Displayed on Screen
3.1.4 Permitted Actions Without Identification or Authentication
{For Reference Only: This subpart (and its subparts) relates to AC-14;
CCI-000061, CCI-000232}
The control system must require identification and authentication before allowing any actions by a user acting from a user interface which MINIMALLY or FULLY supports accounts.
3.2 CYBERSECURITY AUDITING
3.2.1 Audit Events, Content of Audit Records, and Audit Generation
{For Reference Only: This subpart (and its subparts) relates to AU-2(a),(c),(d), AU-3, AU-12; CCI-000123, CCI-001571, CCI-000125, CCI-001485, CCI-000130, CCI-000131, CCI-000132, CCI-00133, CCI-000134, CCI-001487, CCI-000169, CCI-001459, CCI-000171, CCI-000172, CCI-001910}
For devices that have STIG/SRGs related to audit events, content of audit records or audit generation, comply with the requirements of those STIG/SRGs.
3.2.1.1 Computers
For each computer, provide the capability to select audited events and the content of audit logs. Configure computers to audit the indicated events, and to record the indicated information for each auditable event
3.2.1.1.1 Audited Events
Configure each computer to audit the following events:
SECTION 25 05 11 Page 13
a. Successful and unsuccessful attempts to access, modify, or delete privileges, security objects, security levels, or categories of information (e.g. classification levels)
a. Successful and unsuccessful logon attempts
b. Privileged activities or other system level access
c. Starting and ending time for user access to the system
d. Concurrent logons from different workstations
e. Successful and unsuccessful accesses to objects
f. All program initiations
g. All direct access to the information system
h. All account creations, modifications, disabling, and terminations
i. All kernel module load, unload, and restart
3.2.1.1.2 Audit Event Information To Record
Configure each computer to record, for each auditable event, the following information (where applicable to the event):
a. What type of event occurred
b. When the event occurred
c. Where the event occurred
d. The source of the event
e. The outcome of the event
f. The identity of any individuals or subjects associated with the event
3.2.1.2 For HVAC Control System Devices
3.2.1.2.1 HVAC Control System Devices FULLY Supporting User Accounts
For devices FULLY supporting accounts, provide the capability to select audited events, and the contents of audit logs. Configure devices to audit the following events:
a. Successful and unsuccessful logon attempts to the device
b. Starting and ending time for user access to the device
c. All account creations, modifications, disabling, and terminations
d. All device shutdown and startup
Configure the device to record for each event the following information (as applicable): the type of event, when the event occurred and the identity of any individuals or subjects associated with the event
SECTION 25 05 11 Page 14
3.2.1.2.2 Other HVAC Control System Devices
There are no requirements to perform auditing at HVAC field devices that do not FULLY support accounts.
3.2.1.3 Default Requirements for Control System Devices
For control system devices where Audit Events, Content of Audit Records, and Audit Generation are not otherwise indicated in this Section:
3.2.1.3.1 Devices Which FULLY Support Accounts
For each device which FULLY supports accounts, provide the capability to select audited events and the content of audit logs. Configure devices to audit the indicated events, and to record the indicated information for each auditable event
3.2.1.3.1.1 Audited Events
Configure each device to audit the following events:
a. Successful and unsuccessful attempts to access, modify, or delete privileges, security objects, security levels, or categories of information (e.g. classification levels)
a. Successful and unsuccessful logon attempts
b. Privileged activities or other system level access
c. Starting and ending time for user access to the system
d. Concurrent logons from different workstations
e. All account creations, modifications, disabling, and terminations
f. All kernel module load, unload, and restart
3.2.1.3.1.2 Audit Event Information To Record
Configure each computer to record, for each auditable event, the following information (where applicable to the event):
a. what type of event occurred
b. when the event occurred
c. where the event occurred
d. the source of the event
e. the outcome of the event
f. the identity of any individuals or subjects associated with the event
3.2.1.3.2 Devices Which Do Not FULLY Support Accounts
For each Device which does not FULLY support accounts configure the device to audit all device shutdown and startup events and to record for each
SECTION 25 05 11 Page 15 event the type of event and when the event occurred.
3.2.2 Audit Storage Capacity and Audit Upload
{For Reference Only: This subpart (and its subparts) relates to AU-4;
CCI-001848, CCI-001849}
a. For devices that have STIG/SRGs related to audit storage capacity (CCI-001848 or CCI-001849) comply with the requirements of those STIG/SRGs.
b. For non-computer control system devices capable of generating audit records, provide 60 days worth of secure local storage, assuming 10 auditable events per day.
3.2.2.1 Device Audit Record Upload Software
For each non-computer device required to audit events, provide, and license to the Government, software implementing a secure mechanism of uploading audit records from the device to a computer and of exporting the uploaded audit records as a Microsoft Excel file or comma separated value text file.
Where different devices use different software, provide software of each type required to upload audit logs from all devices.
Submit copies of device audit record upload software. If there are no non-computer devices requiring auditing, provide a document stating this in lieu of this submittal.
3.2.3 Response to Audit Processing Failures
{For Reference Only: This subpart (and its subparts) relates to AU-5;
CCI-000139, CCI-000140, CCI-001490}.
Front end computers associated with auditing must, in the case of a failure in the auditing system, notify NEC personnel via e-mail. In case of an audit failure, if possible, continue to collect audit records by overwriting existing audit records.
3.2.4 Time Stamps
{For Reference Only: This subpart (and its subparts) relates to AU-8;
CCI-000159, CCI-001889, CCI-001890}
3.2.4.1 Computers
Computers generating audit records must have internal clocks capable of providing time with a resolution of 1 second. Clocks must not drift more than 10 seconds per day.
Configure the system so that each computer generating audit records maintains accurate time to within 1 second.
3.2.4.2 For HVAC Control System Devices
Time stamp requirements for HVAC Control Systems are as indicated in the HVAC Control System specifications.
SECTION 25 05 11 Page 16
3.2.4.3 Default Requirements for Control System Devices
For control system devices where Time Stamps requirements are not otherwise indicated in this Section: Devices generating audit records must have internal clocks capable of providing time with a resolution of 1 second. Clocks must not drift more than 10 seconds per day. Configure the system so that each device generating audit records maintains accurate time to within 1 second.
3.3 REQUIREMENTS FOR LEAST FUNCTIONALITY
{For Reference Only: This subpart (and its subparts), along with the network communication report submittal specified elsewhere in this section, relates to CM-6 (a), (c), CM-7, CM-7 (1)(b), SC-41; CCI-000363, CCI-000364, CCI-000365, CCI-001588, CCI-001755, CCI-000381, CCI-000380, CCI-00382, CCI-001761, CCI-001762, CCI-002544, CCI-002545, CCI-002546.}
For devices that have a STIG or SRG related to Requirements for Least Functionality (such as configuration settings and port and device I/O access for least functionality), install and configure the device in accordance with that STIG or SRGs.
For HVAC Control Systems: Do not provide devices with user interfaces where one was not required. Do not use a networked sensor or actuator where a non-networked sensor or actuator would suffice.
3.3.1 Non-IP Control Networks
When control system specifications require particular communication protocols, use only those communication protocols and only as specified.
Do not implement any other communication protocol, or use any protocol on ports other than those specified.
When control system specifications do not indicate requirements for communication protocols, use only those protocols required for operation of the system as specified.
3.3.2 IP Control Networks
Do not use nonsecure functions, ports, protocols and services as defined in DODI 8551.01 unless those ports, protocols and services are specifically required by the control system specifications or otherwise specifically authorized by the Government. Do not use ports, protocols and services that are not specified in the control system specifications or required for operation of the control system.
3.4 SAFE MODE AND FAIL SAFE OPERATION
{For Reference Only: This subpart (and its subparts) relates to CP-12, SI-17; CCI-002855, CCI-002856, CCI-002857, CCI-002773, CCI-002774, CCI-002775}
For all control system components with an applicable STIG or SRG, configure the component in accordance with all applicable STIGs and SRGs.
SECTION 25 05 11 Page 17
3.5 IDENTIFICATION AND AUTHENTICATION
3.5.1 User Identification and Authentication
{For Reference Only: This subpart (and its subparts) relates to
IA-2,(1),(12); CCI-000764, CCI-000765, CCI-001953, CCI-001954}
a. Devices that FULLY support accounts must uniquely identify and authenticate organizational users.
b. Devices which allow network access to privileged accounts must implement multifactor authentication for network access to privileged accounts.
3.5.1.1 HVAC Control Systems Devices
Identification and Authentication for network access to privileged accounts must be implemented by either accepting and electronically verify Personal Identity Verification (PIV) credentials or inheriting identification and authentication from the operating system.
3.5.1.2 Default Requirements for Control System Devices
For control system devices where User Identification and Authentication requirements are not otherwise indicated in this Section, User Identification and Authentication for network access to privileged accounts must be implemented by accepting and electronically verify Personal Identity Verification (PIV) credentials or inheriting identification and authentication from the operating system.
3.5.2 Authenticator Management
{For Reference Only: This subpart (and its subparts) relates to IA-5 (b),(c),(e),(g),(1),(11); CCI-000176, CCI-001544, CCI-001989, CCI-000182, CCI-001610, CCI-000192, CCI-000193, CCI-000194, CCI-000205, CCI-001619, CCI-001611, CCI-001612, CCI-001613, CCI-001614, CCI-000195, CCI-001615, CCI-000196, CCI-000197, CCI-000199, CCI-000198, CCI-001616, CCI-001617, CCI-000200, CCI-001618, CCI-002041, CCI-002002, CCI-002003}
3.5.2.1 Authentication Type
3.5.2.1.1 For HVAC Control System Devices
Unless otherwise indicated:
a. Software which FULLY supports accounts and which runs on a computer must use password-based authentication.
b. Other devices which FULLY support accounts must use password-based authentication.
c. Devices MINIMALLY supporting accounts must use password-based authentication.
3.5.2.1.2 Default Requirements for Control System Devices
For control system devices where Authentication Type requirements are not otherwise indicated in this Section:
SECTION 25 05 11 Page 18
a. Software which FULLY supports accounts and which runs on a computer must use password-based authentication.
b. Other devices which FULLY support accounts must use password-based authentication.
c. Devices MINIMALLY supporting accounts must use password-based authentication.
3.5.2.2 Password-Based Authentication Requirements
3.5.2.2.1 Passwords for Computers
All computers supporting password-based authentication must enforce the following requirements:
a. Minimum password length of 12 characters
b. Password must contain at least one uppercase character.
c. Password must contain at least one lowercase character.
d. Password must contain at least one numeric character.
e. Password must contain at least one special character.
f. Password must have a minimum lifetime of 24 hours.
g. Password must have a maximum lifetime of 60 days. When passwords expire, prompt users to change passwords. Do no lock accounts due to expired passwords.
h. Password must differ from previous five passwords, where differ is defined as changing at least 50 percent of the characters.
i. Passwords must be cryptographically protected during storage and transmission.
3.5.2.2.2 Passwords for Non-Computer Devices FULLY Supporting Accounts
All non-computer devices FULLY supporting accounts and supporting password-based authentication must enforce the following requirements:
a. Minimum password length of twelve (12) characters
b. Password must contain at least one uppercase character.
c. Password must contain at least one lowercase character.
d. Password must contain at least one numeric character.
e. Password must contain at least one special character.
f. Password must have a maximum lifetime of sixty (60) days. When passwords expire, prompt users to change passwords. Do no lock accounts due to expired passwords.
g. Password must differ from previous five (5) passwords, where differ is defined as changing at least fifty percent of the characters.
SECTION 25 05 11 Page 19
h. Passwords must be cryptographically protected during storage and transmission.
3.5.2.2.3 Passwords for Web Interfaces
Passwords for connecting to a web interface supporting password-based authentication must enforce the following requirements:
a. Minimum password length of 12 characters
b. Password must contain at least one uppercase character.
c. Password must contain at least one lowercase character.
d. Password must contain at least one numeric character.
e. Password must contain at least one special character.
f. Password must have a maximum lifetime of 60 days. When passwords expire, prompt users to change passwords. Do no lock accounts due to expired passwords.
g. Password must differ from previous five passwords, where differ is defined as changing at least 50 percent of the characters.
h. Passwords must be cryptographically protected during storage and transmission.
3.5.2.2.4 Passwords for Devices Minimally Supporting Accounts
Devices minimally supporting accounts must support passwords with a minimum length of four characters.
3.5.2.2.5 Password Configuration and Reporting
For all devices with a password, change the password from the default password. Coordinate selection of passwords with Fort Eustis CED. Do not use the same password for more than one device unless specifically instructed to do so. Provide a Password Summary Report documenting the password for each device and describing the procedure to change the password for each device.
Do not provide the Password Summary Report in electronic format. Provide two hardcopies of the Password Summary Report, each copy in its own sealed envelope.
3.5.3 Authenticator Feedback
{For Reference Only: This subpart relates to IA-6; CCI-000206}
Devices must never show authentication information, including passwords, on a display. Devices that momentarily display a character as it is entered, and then obscure the character, are acceptable. For devices that have STIGs or SRGs related to obscuring of authenticator feedback (CCI-000206), comply with the requirements of those STIGS/SRGs.
3.5.4 Device Identification and Authentication
{For Reference Only: This subpart (and its subparts) relates to IA-3;
CCI-000777, CCI-000778, CCI-001958}
SECTION 25 05 11 Page 20
All computers must use IEEE 802.1x for authentication to the network. All web servers running on computers must use HTTPS
3.5.4.1 For HVAC Control System Devices
Devices using BACnet must support Network Security as specified in Clause 24 of ASHRAE 135.
3.5.5 Cryptographic Module Authentication
{For Reference Only: This subpart (and its subparts) relates to IA-7;
CCI-000803}
For devices that have STIG/SRGs related to cryptographic module authentication (CCI-000803), comply with the requirements of those STIG/SRGs.
3.6 EMERGENCY POWER
{For Reference Only: This subpart (and its subparts) relates to PE-11,(1);
CCI-02955, CCI-000961}
Emergency power is specified in the control system and equipment specifications.
3.7 DURABILITY TO VULNERABILITY SCANNING
{For Reference Only: This subpart (and its subparts) relates to RA-5 (a),(b),(c),(d); CCI-001054, CCI-001055, CCI-0010156, CCI-001641, CCI-001643, CCI-001057, CCI-001058, CCI-001059}
All IP devices must be scannable, such that the device can be scanned by industry standard IP network scanning utilities without harm to the device, application, or functionality.
For control system devices other than computers:
3.7.1 HVAC Control System Devices Other Than Computers
HVAC control system devices other than computers are not required to respond to scans.
3.7.2 Default Requirements for Control System Devices
Non-computer control system devices where Durability to Vulnerability Scanning requirements are not otherwise indicated in this Section are not required to respond to scans.
3.8 FIPS 201-2 REQUIREMENT
{For Reference Only: This subpart (and its subparts) relates to SA-4 (10);
CCI-003116}
Devices in the following systems which implement PIV must be on the NIST FIPS 201-2 approved product list: NONE.
SECTION 25 05 11 Page 21
3.9 DEVICES WITH CONNECTION TO MULTIPLE IP NETWORKS
Except for Ethernet switches, do not use more than one physical connection to IP networks on the same device unless doing so is both required by the project specifications and the specific application is approved. If a device with multiple IP connections is required, provide a Multiple IP Connection Device Request using the Multiple IP Connection Device Request Schedule at http://www.wbdg.org/FFC/NAVGRAPH/graphtoc.pdf to request approval for each device.
3.10 SYSTEM AND COMMUNICATION PROTECTION
3.10.1 Denial of Service Protection, Process Isolation and Boundary Protection
{For Reference Only: This subpart (and its subparts) relates to SC-5, SC-39, SC-7(a); CCI-001093, CCI-002385, CCI-002386, CCI-002430, CCI-001097}
To the greatest extent practical, implement control logic in non-computer hardware and without reliance on the network.
3.11 SYSTEM AND INTEGRATION INTEGRITY
3.11.1 Malicious Code Protection
{For Reference Only: This subpart (and its subparts) relates to SI-3(c);
CCI-001241, CCI-002623}
For all computers installed under this project, install and configure malware protection software in accordance with the relevant STIGs.
3.12 FIELD QUALITY CONTROL
3.12.1 Tests
In addition to testing and testing support required by other Sections, provide a minimum of 72 hours of technical support for cybersecurity testing of control systems.
-- End of Section --
SECTION 25 05 11 Page 22
SECTION 25 10 10
UTILITY MONITORING AND CONTROL SYSTEM (UMCS) FRONT END AND INTEGRATION
11/15
PART 1 GENERAL
1.1 SUMMARY
Integrate ASHRAE 135 (BACnet) field control systems installed per Section
23 09 23 BACNET DIRECT DIGITAL CONTROL FOR HVAC AND OTHER BUILDING CONTROL
SYSTEMS as specified.
1.1.1 System Requirements
Existing Site-wide UMCS is a Johnson Controls, Inc. Metasys Automation System. Incorporate the field control network(s) installed under this contract into the existing Metasys Automation System UMCS.
1.1.1.1 General System Requirements
a. The system performs supervisory monitoring and control functions including but not limited to Scheduling, Alarm Handling, Trending, Overrides, Report Generation, and Electrical Demand Limiting as specified.
b. The system includes a Graphical User Interface which allows for graphical navigation between systems, graphical representations of systems, access to real-time data for systems, ability to override points in a system, and access to all supervisory monitoring and control functions.
c. All software…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.