skip to main content

An official website of the United States government

Here’s how you know

Official websites use .mil
A .mil website belongs to an official U.S. Department of Defense organization.

Secure .mil websites use HTTPS
A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .mil website. Share sensitive information only on official, secure websites.

Fed Outside of DoD _ DoD Universities & Private Sector
serdp and estcp logo
  • About Us
  • Projects
    Project Directory Energy & Water Test & Training Lands Chemicals & Materials Natural Hazards PFAS Other Chemicals of Concern UXO
  • News
  • Webinars
  • Resources
  • Work With Us
  • Mailing List Login to SEMS
Mailing List Login to SEMS

For mobile, landscape view is recommended.

Automated Inventory Tools For Facility Related Control Systems (FRCS)

ESTCP, Installation Energy and Water Program Area

Released January 6, 2023

Closed March 9, 2023


FY 2024
  1. Work With Us
  2. ESTCP FY 2024 Solicitation

Objective

Solutions were for automated tools to scan and inventory Facility Related Control Systems (FRCS) in DoD facilities. FRCS related to real property assets include systems such as Fire and Life Safety (FLS), Utility Monitoring and Control Systems (UMCS), Heating, Ventilation and Air Conditioning (HVAC), etc. To enable installation and enterprise level decision making to improve the cybersecurity poster of our FRCS, it is important to have accurate and current inventories of control systems and their components.

Successful tools must be able to meet one or more of the following sub-objectives, and must be able to receive an Authority To Operate (ATO) after undergoing the Risk Management Framework (RMF) process:

  • Active or passive scanning of connected devices at Levels 0-4 (see Figure 1) including IP and non-IP devices. In many cases, this will likely require connecting to multiple separate or segmented enclaves at a given physical location to capture and integrate the total inventory of devices.
  • A full listing of desired protocols is provided in the background section.
  • Scans should not disrupt operation of devices (i.e., brick devices).
  • Generate tabular (and/or graphical) list of all devices with relevant information including:
    • Output into Excel file
    • Dependency mapping
  • Provide the following minimum information about the devices:
    • Device identifier (e.g., Model number, manufacturer, etc.)
    • Address (e.g., IP address, BacNET MS/TP address, Modbus address, etc.), where available
  • Ideally, provide as much addition information as possible, such as:
    • Protocol(s) used by the device
    • Ports in use
    • Firmware version
  • Demonstrate significant labor and cost savings compared to traditional approaches.
  • Mobile (i.e., tablet based) solutions are desired, but not required.

Figure 1: DoD 5-tier FRCS reference architecture

Benefits

Successful technologies and solutions will help the DoD build resilient and efficient installations by having a comprehensive assessment of their FRCS inventory. The demonstrated solutions will inform DoD installations in their installation assessment and resilience planning activities. Any technologies/solutions will significantly reduce the manual nature of the current inventory process and enable for continuous inventory of these systems.

Background

It is critical to maintain operations in the event of grid outage to support mission preparedness and readiness. The National Defense Authorization Act for Fiscal Year 2021 highlighted the importance of on-base energy resources and reduction of the DoD’s dependence on off-base resources. The installation energy priority of the DoD is to ensure mission readiness by pursuing energy resilience. Most of these goals depend on FRCS for successful execution; as systems get increasingly complex, automated tools are needed to inventory them for visibility as well as cybersecurity.

Example protocols in use for communication by the device are:

  • Ethernet:
    • BACnet – Native
    • BACnet over IP
    • C37.118
    • COMTRADE
    • DNP 3.0
    • IEC-61850
    • FTP
    • Modbus
    • MV-90
    • SEL
    • Telnet
  • Serial:
    • BACnet
    • DNP 3.0
    • IEC-61850
    • Lon
    • Modbus
    • N1
    • N2
    • SEL
serdp and estcp logo
 

Strategic Environmental Research and Development Program (SERDP)

Environmental Security Technology Certification Program (ESTCP)

 
 
  • Project Directory
  • Energy & Water Test & Training Lands Chemicals & Materials Natural Hazards PFAS Other Chemicals of Concern UXO
  • NEWS
  • WEBINARS
  • RESOURCES
  • ABOUT US
  • Login to SEMS
  • Mailing List
 

Office of the Deputy Assistant Secretary of Defense (Energy Resilience & Optimization) 
3500 Defense Pentagon, RM 5C646
Washington, DC 20301-3500

Phone (571) 372-6565

Contact | Accessibility | FOIA Requests | Privacy Policy | Copyright Information | Media/Press

About DoD | DoD Information Quality | No Fear Act | Plain Language | Privacy Program | USA.gov

 
  • Project Directory
  • Energy & Water Test & Training Lands Chemicals & Materials Natural Hazards PFAS Other Chemicals of Concern UXO
  • NEWS
  • WEBINARS
  • RESOURCES
  • ABOUT US
Login to SEMS
Mailing List
 

Office of the Deputy Assistant Secretary of Defense (Energy Resilience & Optimization) 
3500 Defense Pentagon, RM 5C646
Washington, DC 20301-3500

Phone (571) 372-6565

Contact | Accessibility | FOIA Requests | Privacy Policy | Copyright Information | Media/Press

About DoD | DoD Information Quality | No Fear Act | Plain Language | Privacy Program | USA.gov