Revised_Attachment_9_Sample_Task_Order_PWS.pdf

PDF 87 KB Posted

Attached to
Electronic Security Systems (ESS) VI Federal contract opportunity
Solicitation number
W912DY-14-R-0062
Issued by
Department of the Army Corps of Engineers Engineering Support Center Huntsville

About this file

Revised Attachment 9 Sample Task Order PWS

View the file

Other files for this federal contract opportunity

Other files attached to Electronic Security Systems (ESS) VI, newest first.
File Type Posted
Revised_Attachment_3_-_Small_Business_Participation_Plan_Evaluation_Form.pdf PDF
Project1-FloorPlan-BASEMENT.DWG DWG drawing
Project1-FloorPlan-SITE.DWG DWG drawing
Revised_Attachment_7_-_Time_and_Materials_Rates_7-23-15.xls XLS spreadsheet
Revised_Attachment_5_-_Proposal_Data_Sheet.pdf PDF
Project1-AreaPlan(Rentable)-2NDFLOOR.DWG DWG drawing
Revised_Attachment_10_ESS_VI_Drawing.pdf PDF
Revised_Attachment_6_ESS_VI_Firm_Fixed_Rates_7-9-15.xls XLS spreadsheet
W912DY_14_R_0062_0005.pdf PDF
Project1-AreaPlan(Rentable)-1STFLOOR.DWG DWG drawing
Revised_Attachment_8_-_Area_Cost_Factors_-_7-24-15.xls XLS spreadsheet
W912DY_14_R_0062_0004.pdf PDF
W912DY_14_R_0062_0003.pdf PDF
Attachment_9.pdf PDF
Attachment_8.xls XLS spreadsheet
Attachment_5.pdf PDF
W912DY_14_R_0062_0002.pdf PDF
Attachment_1.pdf PDF
Attachment_3.pdf PDF
Attachment_2.pdf PDF
Attachment_12.pdf PDF
Attachment_4.pdf PDF
Attachment_10.pdf PDF
Attachment_11.pdf PDF
Attachment_7.xls XLS spreadsheet
Attachment_6.xls XLS spreadsheet
RFP_W912DY_14_R_0062.pdf PDF
Show all 27

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 9

Sample Task Order Performance Work Statement for

RFP W912DY-14-R-0062

Electronic Security System (ESS) for Federal Office Building101 Anywhere, USA

1.0 SYNOPSIS. The Offeror shall provide a Group I Technical Data Package (TDP) for an ESS at Federal Office Building 101, Anywhere, USA

1.1 Upon completion, the Offeror shall turn over a Group I TDP to provide for the procurement and installation of a complete and functional ESS.

2.0 REVISIONS TO THE PERFORMANCE WORK STATEMENT (PWS).

2.1 Revision 00. Revision 00 to the PWS is for the initial award of this Task Order.

2.2 Revision 01. Revision 01 to the PWS incorporates changes required for Amendment 4.

3.0 DESCRIPTION OF WORK.

3.1 Existing Conditions and ESS Requirements.

3.1.1 Existing Conditions.

Building 101:

The first level Basement (basement) parking garage is for Government USACE and building personnel vehicles only.

Public parking for visitors is located within one block of the building.

There is one vehicle entrance and one vehicle exit gate for the parking facility.

The building has two elevators. Both elevators provide access to the parking garage and all levels of the building The stairwells provide access to all levels floors of the building

The building is occupied by several federal agency tenants. Part of the first floor and the entire second floor is occupied by the USACE District.

Open Storage is located on the second First floor

A Secret Internet protocol Router Network (SIPRNET) room is located on the second first floor Mechanical and Electrical rooms open to the interior of the building only.

Exterior lighting is limited to fixtures mounted on the exterior of the building building and provides adequate lighting for Closed Circuit Television (CCTV) Parking Lot Garage interior lighting is adequate for Closed Circuit Television (CCTV) coverage The building has emergency generator backup adequate to supply the new ESS.

Monitoring Station:

The monitoring station will be located in Security Room #2. at the existing Guard Desk in the Lobby of the building.

The wall between the Guard Desk and the lobby area is a 42” wall with counter and a service window. The service window is a two panel sliding glass window allowing interaction with the guard force

3.1.2 Requirements.

Building 101:

Vehicle access to the parking facility is to be controlled Public Visitor access to the building is required at the main entrance, through the Lobby, during normal working hours (0800 to 1700) Access to USACE District office areas are to be controlled at all times.

Access to the building is to be controlled at all levels during non-working hours areas.

Access to the Command suite located on second floor is to be controlled.

The Command suite shall have duress alarms in Rooms 49 and 71.

and guard desk require duress alarms The guard desk, located in Security Room #2 shall have a duress alarm.

Access Control shall accommodate both PIV and proximity cards for building access. The access control authentication level for access to USACE administrative areas is considered low and only requires reading of the CHUID. The SIPRNET and Open Storage are considered high security areas and will require full PKI authentication to gain access.

Monitoring Station:

The monitoring station requires the capability to monitor and control all aspects of the new integrated electronic security system.

The monitoring center requires the capability to see and communicate with visitors at the main entrance to the building.

Access control enrollment and badging will be done in Security Office Room 23 at the Badging Office next to the Guard Desk. Associated data, supplies, and spare credentials will also be stored in this room.

The headend equipment rack for the security system shall be located in the Communications Closet (Room 26) on the main level First floor of the building.

CCTV video retention shall be H.264 resolution, 7 frames per second for a period of 30 days.

Remote monitoring of the ESS is required. Remote monitoring will be performed at a federal government facility. Assume existing infrastructure is provided.

3.2 Group I TDP

Contractor shall submit a Group I TDP. The Offeror shall provide an integrated ESS solution, consisting of intrusion detection, CCTV, access control, duress, intercom, and remote monitoring. As a minimum, the Group I TDP shall include the following:

1. Project Description, including a technical description and data sheets of the primary equipment, materials and software proposed.

2. Operational Concept, to include the capabilities of the system and how the proposed ESS will meet the User requirements. Also provide a brief description of how the proposed ESS complies with the PWS, United Facility Guide Specifications (UFGS), United Facility Criteria (UFC), DoD/Army/other relevant Cybersecurity regulations and directives, and applicable codes, standards and statutes. Highlight any expected limitations of the recommended solution.

3. Offeror’s recommended solution to include the rationale behind the choices madeand how they will provide an efficient and cost effective solution for the Government.

4. Drawings which include:

a. Site layout

b. Functional block diagrams for all major systems

c. Floor plans with the system components location indicated and labeled - (to include headend, field and Data Transmission Media (DTM) equipment).

d. Communications network system equipment and routing

e. Power and lighting support systems.

f. Door and gate schedules detailing door position devices, closers, door hardware, card readers, request to exit sensors, automatic gate operators, vehicle loop detectors, intercom stations and other related devices.

g. Camera and camera pole schedules which detail camera location, enclosure, camera type and other information related to CCTV camera positions.

*See Attachment 10 for supporting drawings.

4.0 REFERENCES. Work performed under this task order shall comply with: Technical criteria for the work described herein shall be as defined in the base contract and any site-specific requirements defined in the PWS. The following criteria (most current version) shall be applied during the execution of all work performed.

a. Unified Facilities Guide Specifications (UFGS) 28 20 01.00 10, Electronic Security System

b. UFGS 27 10 00 Building Telecommunications Cabling System

c. UFGS 28 23 23 00 10 Closed Circuit Television System

d. Army Regulation (AR) 380-5, Department of the Army Information Security Program.

e. AR 190-51, Security of Unclassified Army Property (Sensitive and Non-sensitive).

f. AR 190-13, The Army Physical Security Program

g. Life Safety Code NFPA 101 (latest version)

h. National Electrical Code NFPA 70 (latest version)

i. Federal Information Processing Standards Publication 201 (FIPS PUB 201), Personal Identity Verification (PIV) of Federal Employees and Contractors.

j. DOD O-2000.12-H, DOD Antiterrorism Handbook

k. AR 530-1, Operations Security (OPSEC)

l. DoD 8520.02 Smart Card Technology

m. Directive Type Memorandum (DTM) 08-003, Next Generation Common Access Card (CAC) Implementation Guidance

n. DTM 09-012, Interim Policy Guidance for DoD Physical Access Control

o. AR 380-5, Department of the Army Information Security Program

p. Homeland Security Presidential Directive (HSPD) 12

5.0 Cybersecurity Requirements.

5.1 The Contractor shall design, develop, and integrate Cybersecurity (to include, but not limited to, all hardware, software and/or equipment) IAW the DoD, Department of the Army (DA), US Army Network Enterprise Center (NEC), and other applicable Government Agencies. This work shall be done IAW ALL applicable Cybersecurity Regulations and Directives, as provided in this PWS. All equipment provided shall be listed on the Unified Capabilities Approved Products List (UC APL). The systems (to include, but not limited to, ALL hardware, software and/or equipment) provided by the Contractor shall be able to obtain a favorable Authority to Operate (ATO) to all requisite Government networks. Contractor shall perform all Cybersecurity Activities .

5.2 The Contractor shall provide Cybersecurity that is IAW current policies, procedures, and statutes, to include (but not limited to) the following:

• Army Regulation (AR) 25-1, Army Information Technology;

• Army Regulation (AR) 25-2, Information Assurance;

• The Federal Information Security Management Act (FISMA)

• Committee National Security Systems, Policy No. 11

• Federal Information Processing Standards;

• Defense Information Systems Agency (DISA) Secure Technical Implementation Guides (STIGs)

• DoD Directive 8500.1, Information Assurance;

• DoD Instruction 8500.2, Information Assurance Implementation;

• DoD Instruction 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT)

• DoD 8570.01-M Information Assurance Workforce Improvement Program

5.3 The Contractor shall provide all documentation required to obtain a favorable ATO .,. The IA requirement shall be considered to be complete upon obtaining an ATO and the successful connection to local infrastructure (as required), for purposes of this PWS.

5.4 Completion And Government Acceptance Of The System(S) Security Plan. IAW DoDI 8510.01 Risk Management Framework (RMF) all DoD Information Systems (IS) and Platform Information Technology (PIT) systems are required to obtain an Authority to Operate (ATO) via the RMF process. The DISA Enterprise Mission Assurance Support Service (eMASS) is the tool used for producing and submitting a System Security Plan that meets the requirements of RMF, in order to obtain an ATO.

5.5 Completion And Government Acceptance Of Cybersecurity Artifacts And Other Required Documents.

The Contractor shall develop and upload into eMASS, all required artifacts and supporting documentation. This effort should result in the creation of a System Security Plan (SSP) packet. The required artifacts are determined by the system security classification, system categorization, and Cybersecurity controls. This information may include but is not limited to the list below:

a) System Description Statement

b) Configuration Management Plan

c) Disaster Recovery Plan

d) Continuity of Operations

e) Contingency Plan

f) Incidence Response Plan

g) Risk Assessment Report

h) Plan of Action and Milestones (POAM)

i) System Architecture / Topology / Data Flow

j) Configuration Validation Checklist

k) Security Classification Guide

l) System Configuration Guide

m) Hardware Inventory List (use the CIO/G-6 template)

n) Software Inventory List (use the CIO/G-6 template)

o) Physical Security Plan

p) Personnel Security Plan

q) Information Assurance Vulnerability Management (IAVM) Process

r) Patch Management Process, Connection Approval / System Approval documentation

s) Ports, Protocols, and Services (PPS) List

t) Active Directory (AD) Documentation, (if applicable)

The data representing this information may either be uploaded directly, or cut and pasted, into eMASS for each applicable control. In addition, eMASS will provide a rollup of inherited controls for each system once it has been properly identified and classified within eMASS. It is recommended that the current version of the Department of Homeland Security (DHS) Cyber Security Evaluation Tool (CSET) be used as a development tool for eMASS artifacts.

5.6 Completion Of Scan/Fix/Scan Testing And Analysis. This work is performed before the Security Control Assessor (SCA) assesses the system(s) and provides a certification recommendation to the Authorizing Official (AO). The Contractor shall assess (scan and perform manual checks) it’s own system using approved Cybersecurity scanning tools. When issues are found (High, Medium, Low Impact Levels) the Contractor shall fix those issues and rescan the system to ensure all issues have been fixed and/or properly and acceptably mitigated. High impact level findings that cannot be fixed are to be reported to the Government immediately along with a valid reason the vulnerability cannot be fixed and a mitigation plan to fix the vulnerability in the future. The goal is for the system to have a proper

Cybersecurity posture before the SCA comes in to assess the system. The scan/fix/scan process should find and fix all issues before the SCA’s assessment.

5.0 COMPLETION OF DOCUMENTATION TO CONNECT TO THE GOVERNMENT INSTALLATION’S

NETWORK. This shall be based on the Government Installation Network Enterprise Center’s connection approval process (CAP). The Contractor shall provide required assistance and documentation to the Government to satisfy the CAP. Normally this entails having an approved ATO, but it may vary depending on the installation. If PVT will be performed on the installations network then completion of the Network Enterprise Center’s CAP should be scheduled to occur before PVT. If not then the timeline for this task should be at least forty-five (45) days before connecting to the installation’s network.

56.0 DELIVERABLES. The Contractor shall provide the following deliverables.

56.1 Group I TDP. The Group I TDP shall be submitted in both hardcopy and electronic format.

56.2 Technical Data Packages. The Contractor shall make the following technical data package submittals.

DATA DESCRIPTION REQUIRED

Group I Data Design Package to include: YES Table of Contents Project Description Operational Concept Recommended solution Drawings

Attachment 10 - Support Drawings for Sample Task Order PWS will be attached separately with the RFP

Attachment 11 - Engineering Form 4025-R, Transmittal of Shop Drawings, Equipment, Data, Material Samples or Manufacture’s Certificate Compliance will be attached separately with the RFP

Attachment 12 – DD 254, Department of Defense Contract Security Classification will be attached separately with the RFP

File details come from the government source that posted it. Updated .