Loading...
HomeMy WebLinkAbout2023-653-E-AMS-CTCH Security Business Consulting-Facility AssessmentRevised 04/23 1 [Departmental Use Only] TITLE Facility Assessment FY 2023/2024 NORTH CAROLINA SERVICES AGREEMENT RFP/RFQ ORANGE COUNTY This Services Agreement (hereinafter “Agreement”), made and entered into this 1st day of November, 2023, (“Effective Date”) by and between Orange County, North Carolina a political subdivision of the State of North Carolina (hereinafter, the "County") and Collaborative, Technical and Comprehensive Security Business Consulting, LLC, (hereinafter, the "Provider"). WITNESSETH: That the County and Provider, for the consideration herein named, do hereby agree as follows: 1. Services a. Scope of Work. i) This Services Agreement (“Agreement”) is for services to be rendered by Provider to County with respect to (insert type of project): A comprehensive security assessment to be conducted on its decentralized public owned and operated sites. In an effort to reach all goals associated with the project, the team will implement CTCH’s SRAMF-CPTED model to evaluate all levels of OC’s existing security posture at each decentralized site.In an effort to identify the security risk levels associated with each site, physical security vulnerabilities and site security flaws, the team will evaluate each site using the following SRAMF methodology. ii) By executing this Agreement, the Provider represents and agrees that Provider is qualified to perform and fully capable of performing and providing the services required or necessary under this Agreement in a fully competent, professional and timely manner. iii) Time is of the essence with respect to this Agreement. iv) The services to be performed under this Agreement consist of Basic Services, as described and designated in Section 3 hereof. Compensation to the Provider for Basic Services under this Agreement shall be as set forth herein. 2. Responsibilities of the Provider a. Services to be provided. The Provider shall provide the County with all services required in Section 3 to satisfactorily complete the Project within the time limitations set forth herein and in accordance with the highest professional standards. b. Standard of Care. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Revised 04/23 2 i) The Provider shall exercise reasonable care and diligence in performing services under this Agreement in accordance with the highest generally accepted standards of this type of Provider practice throughout the United States and in accordance with applicable federal, state and local laws and regulations applicable to the performance of these services. Provider is solely responsible for the professional quality, accuracy and timely completion and submission of all work related to the Basic Services. ii) Provider shall be responsible for all errors or omissions of its agents, contractors, employees, or assigns in the performance of the Agreement. Provider shall correct any and all errors, omissions, discrepancies, ambiguities, mistakes or conflicts at no additional cost to the County. iii) The Provider shall not, except as otherwise provided for in this Agreement, subcontract the performance of any work under this Agreement without prior written permission of the County. No permission for subcontracting shall create, between the County and the subcontractor, any contract or any other relationship. iv) Provider is an independent contractor of County. Any and all employees of the Provider engaged by the Provider in the performance of any work or services required of the Provider under this Agreement, shall be considered employees or agents of the Provider only and not of the County, and any and all claims that may or might arise under any workers compensation or other law or contract on behalf of said employees while so engaged shall be the sole obligation and responsibility of the Provider. v) If activities related to the performance of this Agreement require specific licenses, certifications, or related credentials Provider represents that it or its employees, agents and subcontractors engaged in such activities possess such licenses, certifications, or credentials and that such licenses certifications, or credentials are current, active, and not in a state of suspension or revocation. vi) Should this Agreement involve project designs, the construction or creation of which is to be bid out or fulfilled by other contractors, and bidding or negotiation with contractors produce prices which, when added to the other elements of the approved total project cost, produce a cost that is in excess of the approved total project cost, the Provider shall participate with the County in negotiation and design adjustments to the extent such are necessary to obtain prices within the approved total project cost. All activity of the Provider with respect to these matters shall constitute Basic Services and shall be performed by the Provider without additional compensation. If negotiation and design adjustments fail to bring costs within the total project cost the County may reject all bids and Provider will redesign or reduce portions of the project in an effort to reduce the bid prices to within the total project cost and rebid the project. One such redesign is included within Basic Services. If this second letting for bids does not produce bids that are within the approved total project cost initially or after negotiations with the contractor the cost is not reduced to an amount within the total project cost, the Provider is not obligated to engage in further redesign. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Revised 04/23 3 3. Basic Services a. Basic Services. i) The Provider shall perform as Basic Services the work and services described herein and as specified in the County’s Request for Proposals or Request for Qualifications (the “RFP”) “RFP Number 367-OC5403 for “Request For Proposals to Provide Facilities Security Assessment” issued October 23, 2023, and the Provider’s proposal, which are fully incorporated and integrated herein by reference together with Attachments (designate all attachments). In the event a term or condition in any referenced document or attachment conflicts with a term or condition of this Agreement the term or condition in this Agreement shall control. Should such conflict arise the priority of documents shall be as follows: This Agreement, the County’s RFP together with attachments, Provider’s Proposal together with attachments. ii) The Basic Services will be performed by the Provider in accordance with the following schedule: (Insert milestones task list, dates and fees. If milestones are not established mark N/A under Milestone Task 1.) Milestone Task Milestone Date Milestone Fee 1. N/A 2. 3. 4. 5. 6. 7. 8. 9. 10. iii) Should County reasonably determine that Provider has not met the Milestone Dates established in Section 3(a)(ii), County shall notify Provider of the failure to meet the Milestone Date. The County, at its discretion may provide the Provider seven (7) days to cure the breach. County may withhold the accompanying payment without penalty until such time as Provider cures the breach. In the alternative, upon Provider’s failure to meet any Milestone Date the County may modify the Milestone Date schedule. Should Provider or its representatives fail to cure the breach within seven (7) days, or fail to reasonably agree to such modified schedule, County may immediately terminate this Agreement in writing, without penalty or incurring further obligation to Provider. This section shall not be interpreted to limit the definition of breach to the failure to meet Milestone Dates. 4. Duration of Services a. Term. The term of this Agreement shall be from 11/1/2023 to 3/31/2024. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Revised 04/23 4 b. Scheduling of Services i) The Provider shall schedule and perform its activities in a timely manner so as to meet the Milestone Dates listed in Section 3. ii) Should the County determine that the Provider is behind schedule, it may require the Provider to expedite and accelerate its efforts, including providing additional resources and working overtime, as necessary, to perform its services in accordance with the approved project schedule at no additional cost to the County. iii) The Commencement Date for the Provider's Basic Services shall be . 5. Compensation a. Compensation for Basic Services. Compensation for Basic Services shall include all compensation due the Provider from the County for all services satisfactorily (as determined by the County) performed pursuant to this Agreement. The maximum amount payable for Basic Services is Thirty Thousand Eight Hundred Thirty Two Dollars ($30832.00). In the event the amount stated on an invoice is disputed by the County, the County may withhold payment of all or a portion of the amount stated on an invoice until the parties resolve the dispute. Payment for Basic Services shall become due and payable in direct proportion to satisfactory services performed and work accomplished. Payments will be made as Project milestones as set out in Section 3(a)(ii) are achieved up to the corresponding milestone fee. (For example, Provider may invoice for the amount listed as the milestone fee corresponding to the first milestone task upon County’s acknowledgement of the satisfactory completion of Task one. Upon the County’s acknowledgement that the second Task has been satisfactorily completed Provider may invoice for that corresponding milestone fee.) Milestone fees shall be the maximum amount payable for its corresponding milestone task which shall not be altered except by written amendment. b. Additional Services. County shall not be responsible for costs related to any services in addition to the Basic Services performed by Provider unless County requests such additional services in writing and such additional services are evidenced by a written amendment to this Agreement. 6. Responsibilities of the County a. Cooperation and Coordination. The County has designated (Alan Dorman) to act as the County's representative with respect to the Project who shall have the authority to render decisions within guidelines established by the County Manager or the County Board of Commissioners and who shall be available during working hours as often as may be reasonably required to render decisions and to furnish information. 7. Insurance a. General Requirements. Provider shall obtain, at its sole expense, Commercial General Liability Insurance, Automobile Insurance, Workers’ Compensation Insurance, and any DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Revised 04/23 5 additional insurance as may be required by County’s Risk Manager as such insurance requirements are described in the Orange County Risk Transfer Policy and Orange County Minimum Insurance Coverage Requirements (each document is incorporated herein by reference and may be viewed at http://www.orangecountync.gov/departments/purchasing_division/contracts.php.) If County’s Risk Manager determines additional insurance coverage is required such additional insurance shall consist of NA (if no additional insurance required mark N/A as being not applicable). Provider shall not commence work until such insurance is in effect and certification thereof has been received by the County's Risk Manager. 8. Indemnity a. Indemnity. To the extent authorized by North Carolina law the Provider agrees, without limitation, to defend, indemnify and hold harmless the County from all loss, liability, claims or expense, including attorney's fees, arising out of or related to the Project and arising from property damage or bodily injury including death to any person or persons caused in whole or in part by the negligence or misconduct of the Provider except to the extent same are caused by the negligence or willful misconduct of the County. It is the intent of this provision to require the Provider to indemnify the County to the fullest extent permitted under North Carolina law. 9. Amendments to the Agreement a. Changes in Basic Services. Changes in the Basic Services and entitlement to additional compensation or a change in duration of this Agreement shall be made by a written Amendment to this Agreement executed by the County and the Provider. The Provider shall proceed to perform the Services required by the Amendment only after receiving a fully executed Amendment from the County. 10. Termination a. Termination for Convenience of the County. This Agreement may be terminated without cause by the County and for its convenience upon seven (7) days prior written notice to the Provider. b. Other Termination. The Provider may terminate this Agreement based upon the County's material breach of this Agreement; provided, the County has not taken all reasonable actions to remedy the breach. The Provider shall give the County seven (7) days' prior written notice of its intent to terminate this Agreement for cause. Either party may terminate this Agreement upon notice to the other party that obligations pursuant to this Agreement are made impractical due to declarations of emergency by Orange County or by North Carolina due to events directly impacting Orange County. Both parties shall remain responsible for all payment and performance due up to the receipt of such notice, but shall have no further obligation or responsibility beyond that date provided the terminating party has taken all reasonable steps to complete the performance of its obligations. c. Compensation After Termination. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Revised 04/23 6 i) In the event of termination, the Provider shall be paid that portion of the fees and expenses that it has earned to the date of termination, less any costs or expenses incurred or anticipated to be incurred by the County due to errors or omissions of the Provider. Upon request of the County, the Provider shall submit to County all relevant documentation, including but not limited to, job cost records, to support its claims for final compensation. ii) Should this Agreement be terminated, the Provider shall deliver to the County within seven (7) days, at no additional cost, all deliverables including any electronic data or files relating to the Project. d. Waiver. The payment of any sums by the County under this Agreement or the failure of the County to require compliance by the Provider with any provisions of this Agreement or the waiver by the County of any breach of this Agreement shall not constitute a waiver of any claim for damages by the County for any breach of this Agreement or a waiver of any other required compliance with this Agreement. e. Suspension. County may suspend the Basic Services and this Agreement at any time for County’s convenience and without penalty to County upon three (3) days’ notice to Provider. Upon any suspension by County, Provider shall discontinue the Basic Services and shall not resume the Basic Services until notified to proceed by County. 11. Additional Provisions a. Limitation and Assignment. The County and the Provider each bind themselves, their successors, assigns and legal representatives to the terms of this Agreement. Neither the County nor the Provider shall assign or transfer its interest in this Agreement without the written consent of the other. b. Governing Law. This Agreement and the duties, responsibilities, obligations and rights of respective parties hereunder shall be governed by the laws of the State of North Carolina. c. Compliance with Laws. Provider shall at all times remain in compliance with all applicable local, state, and federal laws, rules, and regulations including but not limited to all state and federal anti-discrimination laws, policies, rules, and regulations and the Orange County Non-Discrimination Policy and Orange County Living Wage Policy (each policy is incorporated herein by reference and may be viewed at http://www.orangecountync.gov/departments/purchasing_division/contracts.php.) Any violation of this requirement is a breach of this Agreement and County may immediately terminate this Agreement without further obligation on the part of the County. This paragraph is not intended to limit and does not limit the definition of breach to discrimination. By executing this Agreement Provider affirms that Provider and any subcontractors of Provider are and shall remain in compliance with Article 2 of Chapter 64 of the North Carolina General Statutes. By executing this Agreement Provider certifies that Provider has not been identified, and has not utilized the services of any agent or subcontractor identified, on the list created by the State Treasurer pursuant to G.S. 147-86.58. By executing this Agreement Provider certifies that Provider has not DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Revised 04/23 7 been identified, and has not utilized the services of any agent or subcontractor identified, on the list created by the State Treasurer pursuant to G.S. 147-86.81. d. Dispute Resolution. Any and all suits or actions to enforce, interpret or seek damages with respect to any provision of, or the performance or non-performance of, this Agreement shall be brought in the General Court of Justice of North Carolina sitting in Orange County, North Carolina. It is agreed by the parties that no other court shall have jurisdiction or venue with respect to such suits or actions. Binding arbitration may not be initiated by either Party, however, the Parties may agree to nonbinding mediation of any dispute prior to the bringing of a suit or action. e. Entire Agreement. This Agreement, together with the RFP and its attachments and the Proposal and its attachments, represents the entire and integrated agreement between the County and the Provider and supersedes all prior negotiations, representations or agreements, either written or oral. This Agreement may be amended only by written instrument signed by both parties. Modifications may be evidenced by facsimile signatures. f. Severability. If any provision of this Agreement is held as a matter of law to be unenforceable, the remainder of this Agreement shall be valid and binding upon the Parties. g. Ownership of Work Product. Should Provider’s performance of this Agreement generate documents, items or things that are specific to this Project such documents, items or things shall become the property of the County and may be used on any other project without additional compensation to the Provider. The use of the documents, items or things by the County or by any person or entity for any purpose other than the Project as set forth in this Agreement shall be at the full risk of the County. h. Non-Appropriation and Government Action. Provider acknowledges that County is a governmental entity, and the validity of this Agreement is based upon the availability of public funding under the authority of its statutory mandate. In the event that public funds are unavailable or not appropriated for the performance of County’s obligations under this Agreement, then this Agreement shall automatically expire without penalty to County immediately upon written notice to Provider of the unavailability or non-appropriation of public funds. It is expressly agreed that County shall not activate this non-appropriation provision for its convenience or to circumvent the requirements of this Agreement. In the event of a change in the County’s statutory authority, mandate or mandated functions, by state or federal legislative or regulatory action, which adversely affects County’s authority to continue its obligations under this Agreement, then this Agreement shall automatically terminate without penalty to County upon written notice to Provider of such limitation or change in County’s legal authority. i. Signatures. This Agreement together with any amendments or modifications may be executed electronically. All electronic signatures affixed hereto evidence the consent of the Parties to utilize electronic signatures and the intent of the Parties to comply with DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Revised 04/23 8 Article 11A and Article 40 of North Carolina General Statute Chapter 66. j. Notices. Any notice required by this Agreement shall be in writing and delivered by certified or registered mail, return receipt requested to the following: Orange County Provider’s Name & Address Attention: Bonnie Hammersley CTCH Security Business P.O. Box 8181 416 W N Avenue #56 Hillsborough, NC 27278 Lompoc, CA 93436 IN WITNESS WHEREOF, the Parties, by and through their authorized agents, have hereunder set their hands and seal, all as of the day and year first above written. ORANGE COUNTY: PROVIDER: By: _________________________________ Bonnie Hammersley By: __________________________________ Calvin James Daniels, CEO Printed Name and Title DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB 11/8/202311/12/2023 Revised 04/23 9 ORANGE COUNTY—INTERNAL USE ONLY ______________________________________________________________________________ Finance Information Vendor Name: CTCH Security Business Consulting Vendor Contact Person: Calvin Daniels Phone: 757-439- 2280 Address: 416 W North Avenue #56 City Lompoc State: CA Zip: 93436 Department: AMS Amount: $30832.00 Purpose: Facility Assessment Budget Code(s): 10700030-875000 Vendor # Vendor Status with NCSOS: Vendor is a BOCC consultant: Yes No Contract Details Contract Type: New Amendment (Original Contract: ) (Most Recent Amendment ) Effective Date End Date Notice Date (Notice Purpose ) Award Approved by Board (Agenda Date: ); Made or Administered by Signature Authority - BOCC Express Delegation (Agenda Date: ) - Policy 9.4: Under $5,000; Service Under $90,000; Construction Under $250,000 - Budget Policy Section XV (Capital Improvement Project: ) Bidding Informal Bidding ($30k-$90k); Formal RFP ($90k+); Other (<$30k); Exception(# ) Department Affirmation This agreement is approved as to technical form and content and I as Department Director affirmatively state work on this project has not been initiated prior to execution of the agreement. Services related to this agreement have already begun or been completed. Description of the nature of the emergency condition that was addressed: Department Director’s Signature ________________________________________ Date: ________ Information Technologies This agreement has been reviewed and is approved as to information technology content and specifications: Office of the Chief Information Officer___________________________________ Date: ________ Inapplicable because no hardware/software purchases or related services Risk Management This agreement is approved for sufficiency of insurance standards, specifications, and requirements: Office of the Risk Management Officer___________________________________ Date: _________ Financial Services This instrument has been pre-audited in the manner required by the Local Government Budget and Fiscal Control Act: Office of the Chief Financial Officer ____________________________________ Date: _________ Legal Services This agreement is approved as to legal form and sufficiency: Office of the County Attorney __________________________________________Date: ________ Clerk to the Board All Docusign contracts must be copied to the Clerk upon completion: occlerkdocs@orangecountync.gov The following signature block is for hard copies only and is not required for Docusign contracts: Received for record retention: Office of the Clerk to the Board __________________________________________Date:_________ DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB 11/7/2023 11/8/2023 11/10/2023 11/11/2023 Revised 04/23 10 DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB FIRM NAME TOTAL COST Good Harbor Techmark, LLC 24,849.00$ Federal Dynamics Corporation 26,965.47$ CTCH Security Business Consulting, LLC 30,832.00$ Crime Prevention Center for Training and Services, 47,220.00$ Preparedness 360 Solutions, LLC 55,000.00$ Force Protect Security Consultants 61,680.00$ Group Nine Risk Consulting 69,800.00$ Affiliated Engineers, Inc.69,875.00$ TRC Environmental Corporation 70,942.00$ Thornton Tomasetti, Inc.73,500.00$ IXP Corporation 75,000.00$ Emerging Technology Support, LLC 75,000.00$ Global Traveler LLC 398,411.00$ Purchasing Agent: Jovana Amaro Jovana Amaro Date: 10/12/2023 TABULATIONS RFP#: 367-OC 5403: To Provide Facilities Security Assessment DUE DATE: October 12 , 2023 at 2:00 pm DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Protecting Our Local Governments “Security Consulting, Engineering, Integration and Design at its Best!” www.ctchconsulting.com October 6, 2023 To: Orange County (OC), North Carolina (Attn: Jovana Amaro, Purchasing Agent) Dear Sir or Madam, Collaborative, Technical and CompreHensive (CTCH) Security Business Consulting, LLC is very grateful for the opportunity to provide its response to Orange County, North Carolina’s, Request for Proposal (RFP), for Facilities Security Assessment (RFP# 367-OC 5403). CTCH has evaluated the RFP and has determined that its Security Risk Assessment Management Framework (SRAMF) – Crime Prevention Through Environmental Design (CPTED) security assessment models would help OC identify critical site assets, identify site vulnerabilities, identify tactical and inherent threats, calculate the probability of security incidents, formulate the existing security risk level(s), create policy and procedures that help manage security programs and would help identify the cost-benefits associated with security improvements. CTCH’s scope of services fall directly in line with the RFP’s scope of work, project deliverables and OC’s project mission goals. I, representing CTCH Security Business Consulting, am designated as the binding authority and project manager for the project team. Please do not hesitate to contact me if you have any questions on any aspect of this proposal. The following information is provided as CTCH’s contact information: Firm: Collaborative, Technical and CompreHensive (CTCH) Security Business Consulting Address: 416 West North Avenue #56, Lompoc, CA 93436 Phone#: (757) 439-2280 Email: info@ctchconsulting.com Website: www.ctchconsulting.com During this project CTCH will partner with Force Protect Security Consultants (FPSC); its sub-contractor and Industry Goals Partner. The following information is provided as contact information: Cover Letter Page 1 DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Protecting Our Local Governments “Security Consulting, Engineering, Integration and Design at its Best!” www.ctchconsulting.com Firm: Force Protect Security Consultants (FPSC) Point of Contact: Frank Finley, II Mailing Address: 10901 Front Beach Road, Suite 1415, Panama City Beach, Florida 332407 Phone: (502) 836-4232 Email: frank@force-protect.com Website: www.force-protect.com Attachments 1 through 7 are forwarded in accordance with RFP requirements. All information published within this proposal is true and correct as of the day of the proposal’s submission. This proposal will remain active up to 60 days after the closing date of this RFP. Again, we appreciate the opportunity to respond to this RFP. Sincerely, Calvin James Daniels Founder, CEO CSC, PSP, ICCP-Practitioner Binding Authority, Project Manager Attachments: 1: Title Page: Include the company name and Federal ID number 2: Acknowledgement of receipt of any Addenda 3: Living Wage Contractor Policy Form 4: E-verify Form 5: Orange County Non-Discrimination Certification 6: Supplemental Vendor Information: Historically Underutilized Businesses Form 7: CTCH’s Proposal Cover Letter Page 2 DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB 811652071 Collaborative Technical and Comprehensive Security Business Consulting DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Calvin James Daniels Collaborative Technical and Comprehensive Security Business Consulting October 5, 2023 DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Calvin James Daniels, Founder - CEO Collaborative Technical and Comprehensive Security Business Consulting DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB X X DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB Protecting Our Local Governments Orange County, North Carolina Facilities Security Assessment Response to Request for Proposal# 367-OC 5403 October 6, 2023 DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 1 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Table of Contents 1. Project Organization .......................................................................................................................................... 2 Background and Services ........................................................................................................................ 2 Industry Goals Partner .............................................................................................................................. 4 Approach and Methodology ................................................................................................................. 4 Initial Project Evaluation ........................................................................................................................ 10 Security Risk Assessment Management Framework (SRAMF) .......................................... 11 2. Technical Approach ........................................................................................................................................... 14 Phased and Tiered SRAMF – CPTED Approach ......................................................................... 14 Phase I (Initial Site Assessments) ...................................................................................................... 15 Phase II (Draft Security Plan Development) ................................................................................ 32 Related Experience and References ................................................................................................. 33 3. Cost Proposal and Schedule ........................................................................................................................ 44 4. Follow-On Services ............................................................................................................................................ 47 Appendices Appendix A: Professional Certifications ........................................................................................ 64 Appendix B: Resumes .............................................................................................................................. 70 DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 2 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com 1. Project Organization Background and Services: CTCH is a Certified Veteran, Small Business, Disadvantaged Business Enterprise and Minority-Owned Security Consulting firm that operates as a Limited Liability Corporation; founded by Calvin James Daniels in 2016 with offices located in El Segundo and Lompoc, California. CTCH began as an idea in the mind of Calvin in 2015, based on the ideas that he wanted to improve the quality of services provided within the security industry after 28-years as a Security Specialist within the Public Sector identifying unique stakeholder Crime Prevention Through Environmental Design (CPTED) needs; identifying systemic security industry vulnerabilities/oversight issues during physical security design evaluations and security risk assessments; wanting to help evolve modern CPTED models; and wanting to help the security industry evolve towards the convergence of Management, Physical and Technical Security services into the IoT and AI. Appendix A, Professional Certifications, are provided for each team member. CTCH offers Security Consulting services within the CPTED, Risk Management, Physical Security, Technical Security and Information Security fields. CTCH’s CPTED services are centered on blending 1st and 2nd Generation CPTED practices during site evaluations, site retrofit projects and new construction projects. The applied 1st Generation CPTED practices enable CTCH to identify existing physical security design flaws associated with site security postures. CTCH’s 2nd Generation CPTED practices enables CTCH to blend physical security with property planning; while at the same time promoting social cohesion and area usage. CTCH’s risk management services are centered on helping organizations refine/develop their security management practices. This is accomplished by CTCH evaluating existing organizational polices, evaluating current procedures, evaluating management practices, evaluating security manpower and measuring how they each support asset protection efforts. The firm’s technical security services are centered on identifying potential physical/electronic security vulnerabilities and helping stakeholders obtain a Return on Security Investment (ROSI) from Electronic Security Systems (ESS) when performing system integrations/site retrofits/new construction. CTCH’s physical security design approach is centered on balanced protection and protection in-depth; which helps stakeholders implement physical security measures that are tailored for their operating environments (taking into consideration CPTED guidelines). The firm’s information security consulting services help organizations protect intellectual property, critical DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 3 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com information and logical access that are used to develop business relationships with stakeholders/clients. By blending its security consulting services, CTCH has created Security Risk Assessment Management Framework (SRAMF)-CPTED models that ensure people and assets are protected using the appropriate levels of security. The SRAMF-CPTED implemented by CTCH enables the firm to conduct Security Risk Assessments/Site Surveys in a tiered format; evaluating the entire Physical Protection System (People, Procedures and Components) and the elements of CPTED that have been built into individual sites/properties. CTCH’s SRAMF-CPTED methodology will enable OC to: • Identify critical assets that are critical to each site • Identify threats (internal and external) that plague site environments • Determine the probability of security threats becoming a reality • Identify CPTED vulnerabilities (procedural, physical and technical) • Identify the current security risks at the decentralized sites • Design/Implement CPTED models that reduce security risks • Evaluate Security Manpower Requirements (Security Staff and Guards/Officers) • Identify Board Member, Staff, Vendor and Security Officer security needs/concerns The SRAMF-Security Management Review Methodology (SMRM) implemented by CTCH will evaluate OC’s current Security Management Practices, Security Training Plans, Comprehensive Emergency Management Plans (Emergency Response, Crisis Management and Business Recovery) and CPTED guidelines currently in use that create the baseline security practices implemented at each of its decentralized sites. This SRAMF-SMRM will enable OC to: • Solidify current security goals • Identify how security policy and procedures are implemented • Determine if the current security training is effective • Help OC publish security policies that are unified • Evaluate the context of Security Response/Recovery - Plans/Practices • Identify the levels of security competence needed by OC stakeholders • Identify the level of Board Member, Staff, Vendor and Security Officer security awareness DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 4 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Industry Goals Partners During this project CTCH will manage and work with its ‘Industry Goals Partner’ (sub-contractors) to complete all deliverables associated with this project. CTCH selects its ‘Industry Goals Partners’ based on merit, performance, security industry contributions and project experience. CTCH’s merit matrix is based on evaluating security industry certifications. CTCH’s performance evaluations are centered on contacting past project references and identifying how satisfied the references were with the overall performance of the industry partner. CTCH’s security industry contribution evaluations are based on identifying how partner activities are helping advance the security industry (management, technical, physical and/or training). CTCH’s experience evaluation model is based on identifying how partner skill sets match with efforts associated with project deliverables. Below is a background summary of the ‘Industry Goals Partner’ associated with this project, Project Organizational Chart and a qualification outline associated with each key project team member: Force Protect Security Consultants (FPSC) is a Certified Disabled Veteran Business Enterprise (DVBE) founded by Frank Finley II in 2013 as a Limited Liability Corporation. The firm was formed as a spin off company from Franks Architectural, Engineering and Construction firm, Paradigm Engineers and Constructors, as a strategic vision. That vision was to provide security consulting services in the Security Risk Assessment, Physical Security, Technical Security, Management Security, Anti-Terrorism and IT Communications fields that would help improve the services provided within the security industry; after identifying preexisting issues during previous site assessments. The firm has a Certified Protection Professional (CPP), Certified Physical Security Professional (PSP), Certified Information Systems Security Professional (CISSP) and a Blast Specialist/Structural Engineer on staff. FPSC staff members are also considered experts in Force Protection, Anti-Terrorism and Physical Security. During this project FPSC will help CTCH conduct the Security Risk Assessments and help create the final project deliverables (SRAMF - CPTED Reports and CPTED Security Master Plan). Approach and Methodology Our team is comprised of highly-qualified professionals with exceptional experience performing Security Risk Assessments and Site Surveys; Identifying CPTED Issues; Creating Comprehensive Emergency Management Plans; Designing Physical and Electronic Security Systems; and evaluating public owned areas that have high throughput rates due to the human services (administrations, outreach, governance, DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 5 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com etc.) that they provide. The following organization chart depicts the reporting order and information sharing process associated with this project: Project Manager/Lead Assessor Calvin James Daniels, CSC, PSP, ICCP-Practitioner Security Consultant/ Assessor Frank Finely II, PSP Security Consultant/ Assessor Steve Wilbanks Security Consultant/ Assessor Trey Finley III Key Personnel: DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 6 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Calvin Daniels is the Founder and CEO of CTCH. He has managed and participated in over 500 Security Risk Assessments and 300 Security Construction Site Surveys in his 28-year career. Calvin possesses a Master’s Degree in Business Administrations, a Bachelor’s of Science Degree in Business Administrations and has been a Board-Certified Physical Security Professional (PSP) since 2011. He is 1 of 29 personnel internationally to be board-certified as a Certified Security Consultant (CSC). Calvin also holds the International Crime Prevention through Environmental Design Association (ICA), Certification Program (ICCP), Practitioner Certification. He has built CTCH into a national provider of security consulting services that consist of Security Risk Assessments, CPTED, Security Engineering, Management Security Reviews, ESS Designs and IT Network Enterprise Designs. ➢ Versed in multiple Security Risk Assessment Models ➢ Developed Division 26, 27, 28 and 32 Specifications and Drawings ➢ Project Managed Minor and Major retrofit/new construction efforts ➢ Program Managed Complex Security Programs ➢ Designed Physical and Electronic Security Systems ➢ Authored and Published Security Awareness Articles Industry Affiliations International Association of Professional Security Consultants (IAPSC) American Society for Industrial Security International (ASIS International) International Crime Prevention through Environmental Design Association (ICA) Project Duties ➢ Spearhead all project activities ➢ Lead the ‘Think Tank’ review of all key findings and recommendations produced by the project team ➢ Develop open lines of communications with OC stakeholders and project team members ➢ Lead the creation of the final CPTED Security Risk Assessment Reports, CPTED Security Master Plans and Preliminary Designs Calvin James Daniels, CSC, PSP, ICCP-Practitioner Project Manager – Lead Assessor Location: CTCH Home Office, Lompoc, California DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 7 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Frank Finley, II, is the Founder and Principal of FPSC. He has participated in over 250 construction site surveys and has successfully completed 110 security retrofit projects within the public sector in the last 8 years. He possesses a Master degree in Manufacturing Technology, a Bachelor’s of Science Degree in Mechanical Engineering and has been a Board-Certified Physical Security Professional (PSP) since 2015. Frank has also owned and operated his own Architecture, Engineering and Consulting Firm (Paradigm Engineers and Constructors) in the past. He has built FPSC into a national provider of security consulting services that consists of Security Risk Assessments, CPTED, Anti-Terrorism Blast Designs, IT Communication-Technology Engineering, Cyber Security, Physical Security Designs and Management Security Reviews. ➢ Fluent in Security Risk Assessment Models ➢ Versed in Physical Security Design Models ➢ Project Managed Electronic Security System upgrades ➢ Team leader during complex projects ➢ Works with A&E firms during large construction projects ➢ Fluent in diverse Facility Design Criteria Industry Affiliations American Society for Industrial Security (ASIS) International Society of American Military Engineers (SAME) International Association of Professional Security Consultants (IAPSC) Project Duties ➢ Provide Senior Security Consultant guidance throughout the project ➢ Conduct Site Assessments (Physical, Technical and Management) ➢ Document Gap Analysis findings ➢ Contribute to ‘Think Tank’ project progression team ➢ Monitor project deliverables schedules ➢ Contribute to the creation of the Final CPTED Security Risk Assessment Reports, CPTED Security Master Plans and Preliminary Designs Frank A. Finley, II, PSP Security Consultant – Physical Security/Anti-Terrorism Location: FPSC Home Office, Panama City, Florida DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 8 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Steve Wilbanks has been a member of the FPSC team since 2020. He has conducted over 100 Security Risk Assessments and has worked with Architectural and Engineering Firms to develop security requirements and design specifications. Steve possesses a Bachelor’s of Science Degree in Criminal Justice. Steve has acted as a quality assurance agent during project management efforts associated with FPSC construction and retrofit projects. In the past he has held the position of Director of Operations, managing 150 security officers. ➢ Fluent in Physical Security Reviews ➢ Fluent in Security Risk Assessment Models ➢ Conducted Security Manpower Reviews ➢ Specialize in Response Plan Objective and Response Time Objective Evaluations ➢ Developed Division 28 Design Specifications ➢ QA Agent during security construction and retrofit projects Industry Affiliations American Society for Industrial Security (ASIS) International Project Duties ➢ Conduct Site Assessments (Physical, Technical and Management) ➢ Conduct interviews with OC stakeholders ➢ Produce Security Gap Analysis findings ➢ Contribute to ‘Think Tank’ project progression team ➢ Monitor project deliverables schedules ➢ Contribute to the creation of the final CPTED Security Risk Assessment Reports, CPTED Security Master Plans and Preliminary Designs Steven Wilbanks Security Consultant – Risk Assessor Location: FPSC Home Office, Panama City, Florida DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 9 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Frank Finley, III has been a member of the FPSC team since 2019. He has conducted over 80 Security Risk Assessments Design Reviews and has worked with Architectural and Engineering Firms to develop security requirements and design specifications. Frank has acted as a quality assurance agent during the project management efforts associated with FPSC construction and retrofit projects. In the past, he has managed 60 security officers that provided security services in decentralized locations. ➢ Fluent in Comprehensive Emergency Management Plan Reviews ➢ Specialize in Response Plan Objective and Response Time Objective Evaluations ➢ Developed Division 28 Design Specifications ➢ QA Agent during security construction and retrofit projects Industry Affiliations American Society for Industrial Security (ASIS) International Project Duties ➢ Conduct Site Assessments (Physical, Technical and Management) ➢ Conduct interviews with OC stakeholders ➢ Produce Security Gap Analysis findings ➢ Contribute to ‘Think Tank’ project progression team ➢ Monitor project deliverables schedules ➢ Contribute to the creation of the final CPTED Security Risk Assessment Reports, CPTED Security Master Plans and Preliminary Designs Personnel outlined as key personnel will be directly affiliated with this project from beginning to end. Any augmentee personnel assigned to this project will be employees of CTCH or FPSC. Personnel augmentee’s will be approved by OC prior to personnel changes. Appendix B, Resumes, are provided for each team member. Frank A. Finley, III Security Consultant – Risk Assessor Location: FPSC Home Office, Panama City, Florida DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 10 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Initial Project Evaluation The project team has evaluated the RFP and has determined that OC is requesting Comprehensive Security Assessments to be conducted on its decentralized public owned and operated sites. In an effort to reach all goals associated with the project, the team will implement CTCH’s SRAMF-CPTED model to evaluate all levels of OC’s existing security posture at each decentralized site. The project team recognizes that OC has unique security requirements due to the nature of business that its individual sites conduct (Board Meetings, Operations, Public Services, Safety, Public Outreach, Administrative Support, Logistical Operations, Judicial Operations and Parking). Based on an initial evaluation of the RFP, the team has identified that the areas outlined with the RFP would be classified as Mixed Spaces (Customer Services Areas, Administrative Areas, Logistical Areas, Utility Areas and Parking Areas) and Restricted/Controlled Areas (Administrative Offices, Mechanical Areas, Recycle/Hazardous Material Storage Areas, Meeting Areas, Security Management Areas and Judicial Processing Areas). The team will evaluate each of these decentralized operating environments in accordance with industry specific security risk assessment guidelines, industry security best practices and CPTED guidelines. Some of the guidelines and best practices that will apply to OC project efforts are the: American Lighting Association Guidelines; ASIS International General Risk Assessment Guideline; Homeland Security’s CCTV Technology Handbook; Homeland Security - Integrated Security Committee Standards; Integrated Security Committee – Minimum Standards for Armed Contract Security Officers; International Crime Prevention Through Environmental Design (CPTED) Association Guidelines; Life Cycle Management Center Standardized Electronic Security Equipment Siting and Design Guidance for Permanent Installations; Major Cities Chief, Police Association 1, Campus Security Guidelines, Recommended Operational Policies for Local and Campus Law Enforcement Agencies; PDHengineer Complete Parking Lot Design; Staffing Benchmark: A Model for Determining how many Security Officers are Enough ; and Underwriters Laboratory 2050 National Industrial Security Systems which each are relevant to a project of this scope. The team has implemented the SRAMF – CPTED and Security Site Survey models within similar project settings at Colleges, Counties, Offices of Education, Water Processing Areas, Department of Defense National Critical Infrastructures, Healthcare Centers and Industrial Sites (Public Owned and at Privately Owned). DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 11 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Security Risk Assessment Management Framework (SRAMF) In an effort to identify the security risk levels associated with each site, physical security vulnerabilities and site security flaws, the team will evaluate each site using the following SRAMF methodology: The first step in the SRAMF Model would be to identify security policies, procedures and supporting documents that are in place throughout OC. The documented policies and procedures will outline the existing security protocols, what areas of security are currently covered under the policies/procedures and how security is managed (through governance and response). All identified supporting documents will help add context to the existing policy and procedures, will help identify documented agreements and will help identify individual site infrastructures. The next step in the SRAMF Model would be to identify what are the critical assets areas associated with each site. Assets fall into two categories: tangible and intangible assets. Tangible assets are those assets that stakeholders can label with a dollar value (equipment, building areas, vehicles, etc.). Intangible assets are assets that stakeholders cannot label with a dollar value (loss of life, business model, public reputation, etc.). By ranking assets and conducting a Security Business Impact Analysis, the team can begin to formulate the final Mitigation Matrix. The team will rank critical DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 12 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com assets by identifying OC’s existing security needs, through the use of industry best practices and through the identification of logic diagrams associated with OC operations. After critical assets are ranked, the team will then begin to conduct threat assessments. The threat assessments will identify tactical and inherent threats that are associated with each site based on their locations and past incidents. Tactical threats are those threats that exist within each site’s current operating environment. Inherent threats are those threats that are created due to the location of each site. The threat evaluation models will be centered on crime analytics that are performed by collecting data from OC stakeholders and by evaluating incident reports that OC has collected for each site. Once the threat assessments are conducted, the team will conduct probability assessments. The probability assessments will be based on qualitative and quantitative evaluations. The qualitive evaluations will be based on benchmarks associated with like public and private settings. The quantitative evaluations will be based on all measurable data that is gained throughout the SRAMF evaluations. The probability assessments will ensure that security recommendations that the team develops are true risk based and not based on speculative risk, which ensures stakeholders obtain a cost-benefit when implementing recommended risk mitigation measures. When the probability of all threats has been identified, the team can then begin to evaluate the vulnerabilities associated with the sites based on the threats that are more likely than not to occur using CPTED evaluation models. _________________________________ CPTED Model DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 13 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com The foundation of 1st Generation CPTED consists of Natural Surveillance, Social Management, Maintenance, Territorial Reinforcement and Natural Access Control. Natural Surveillance is the concept of providing clear lines of sight to site stakeholders via natural/predesigned means. Social Management is centered on creating a security culture within working/operating areas. CPTED Maintenance consists of reviewing CPTED measures through site security reviews (planned and responsive). Territorial Reinforcement outlines site boundaries for stakeholders. Natural Access Control consists of implementing foot/vehicle patterns that reduce crime. As crime and design elements have evolved, CPTED has expanded into new areas of security incident prevention that is centered on Social Cohesion, Community Culture, Connectivity and Threshold Capacity - known as Second Generation CPTED. CPTED Social Cohesion merges site management efforts, stakeholder awareness and space usage into uniform security practices. The cohesion of site management and stakeholder cultures help identify space usage culture and gets all OC stakeholders on the same page when it comes to crime prevention. CPTED Community Culture promotes safe working environments and promotes stakeholders helping create safe working environment (free from workplace violence and criminal activities). Identifying security culture shortfalls will help identify security posture shortfalls that exist between security management efforts and stakeholder security practices. CPTED Connectivity is centered on stakeholders communicating with security managers to discuss issues; sites that are designed in a way that promotes approved area usage; and decentralized sites sharing security incident information; which helps reduce site crime rates. CPTED Threshold Capacity is centered on placing gathering/usage areas within designated locations and OC stakeholders having the ability to properly monitor DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 14 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com activities. Through monitoring, stakeholders of OC can prevent trespassing, loitering and unauthorized gatherings which normally is the flash point for criminal activities. Due to national concerns related to the Workplace Violence that affect some of our nation’s public agencies (active shooter, assaults and protests), the team will pay close attention when evaluating existing lockdown efforts, security incident response, security incident reporting, response time objectives, response plan objectives, surveillance, throughput designs and emergency interior compartmentalization; taking into account customer service needs and departmental cultures. The team’s tiered project approach consists of Project Programming, On-Site Assessments and the creation of project Deliverables. The team would execute its SRAMF-CPTED Criteria Matrixes that evaluate 103 CPTED key security points that are centered on protecting people, property and infrastructure. During past assessments the team has identified that the vulnerabilities most often associated with projects involving the public sector are normally related to Site Management, CPTED, Access Control, Visitor Management, Security Incident Response Procedures, Area/Site Monitoring and design flaws (physical and ESS). Once the vulnerabilities have been identified, the team can then formulate the individual risks levels for each site. The final overall risk levels for each site will be calculated from qualitative and quantitative sources. During this project the team will also implement the Homeland Security, Integrated Security Committee (ISC), Facility Security Level (FSL) rating guidelines. The ISC-FSL guidelines will help the team evaluate OC site security settings using Homeland Security Standards. 2. Technical Approach Phased and Tiered SRAMF – CPTED Approach In an effort to thoroughly evaluate the OC’s existing security posture, create the security assessment reports and the draft security plan, the team will segment its project efforts into two phases: Phase I and Phase II, as illustrated below: Phase I – Security Assessments Phase II – Draft Security Plan Development Tier I – Project Programming (11/8-10/23) Tier I – Phase II Artifacts Evaluation (1/8/24) Tier II - Site Assessments/Surveys (11/13-18/23) Tier II – Deliverable Creation (Dates) (1/9-22/24) Tier III – Deliverables (11/27-12/1/23) This phased approached has been developed based on the assessments required for each site and the final deliverables associated with the project. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 15 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Phase I – Initial Site Assessments: During Phase I of the project a Tiered SRAMF- CPTED approach will be used to evaluate OC’s existing security postures, security operations, assets, threats, vulnerabilities and current risk levels; which will help develop the final SRAMF-CPTED Reports (to include final risk calculations, recommendations and cost estimates) and the CPTED-Security Master Plan. The tiered SRAMF-CPTED approach consists of three key tiers: Tier I: Project Programming | Tier II: On-Site Assessments | Tier III: Final Deliverables This approach will enable the team to identify OC stakeholder’s concerns, identify CPTED vulnerabilities, identify true security risk, identify existing site conditions, identify true security requirements and help identify the current Physical Protection System (People, Procedures and Components) that protects OC’s stakeholders and identify critical site assets. The team estimates that it will take 112 hours to complete Phase I. _________________________________ Tier I: Project Programming: This Tier will enable the team to host the initial kickoff meeting; review incident reports; evaluate security policy and security procedures; evaluate existing security training plans and security operations; evaluate artifacts associated with the Electronic Security Systems (ESS) and site layouts; create the ISC -FSL ratings; gather OC data through use of interviews and questionnaires; and confirm the on-site assessment dates. Initial Kickoff Meeting: Once selected for the project, the team will conduct the initial kickoff meeting with stakeholder personnel. During the initial meeting, the stakeholders and the team will evaluate important contractual requirements. The stakeholders will be able to share their expectations and will be able to outline any mission operations that could affect project efforts. The initial kick-off meeting with stakeholder personnel will help the team gain an understanding of daily operations and unique challenges that affect the security postures associated with DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 16 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com the decentralized sites. The kickoff meetings would occur through the use of tele/video conferencing with OC stakeholders. Incident Report Evaluations: In preparation for the on-site assessments, the team will gather tactical threat data, inherent threat data and security incident reports in order to create a preliminary threat assessment for each site. The threat assessment will identify tactical and inherent threats that are associated with each site based on services, locality and past incidents; which will be used to support the cost-benefit evaluations for recommended security measures. Tactical threats that will be evaluated are those threats that exist within a one-mile radius of each site. Inherent threats are those threats that are based on the nature of business associated with each site. Threat/Crime/Incident Report data will be obtained by working with OC stakeholders to obtain data that spans over the last three-years. The team would request copies of all incident reports (and supporting documents) that are related to each site under review in an effort to identify site specific security issues. The team will be able to use this data to identify any vulnerabilities that may exist within current policies and procedures, to identify existing vulnerabilities within the stakeholder’s security postures during the on-site assessments and to evaluate the infrequent/seasonal affects that site services have on each site. Most importantly, this data will immediately identify sites that are plagued with higher security risks/threats. Security Policy, Procedure, Training and Operations Review: In an effort to gain an initial understanding of the current CPTED posture, the team will request electronic copies of OC current Security Management Plans, Comprehensive Emergency Management (CEM) Plans and Security Standard Operating Procedures/Quick Reaction Checklists. By evaluating these documents, the team will be able to identify the policies and procedures that are in place and how these policies and procedures support/hinder the security operations at each site. CEM plans are an integral part of organizational training goals. If CEM plans are non-existent or out of date OC could be exposed to high level of security risks due to its operating environments/nature of business. By evaluating the CEM plans, the team will be able to identify how security incidents are addressed and how frequently these CEM plans should be tested/updated; based on each sites risk exposure. To identify OC’s current Security Training Goals, the team would request copies of the current Security Training Plans. By evaluating the current Security Training Plans, the team will be able to measure the personnel competency levels required under the DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 17 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com plans and will enable the team to identify how the current plans reduce security risk/threats. Once the team has evaluated the security training elements, it will be able to compare current policy vs procedures; and will be able to identify if these policy/procedures meet the minimal industry standards. The overall evaluation will enable the team to recommend possible training resources that address security risks and that would enable OC stakeholders to tailor existing security plans to meet its operational security goals. By outlining administrative vulnerabilities during this tier, the team will also begin to draft parts of the SRAMF-CPTED Reports and CPTED-Security Master Plan, associated with Tier III. Electronic Security System (ESS) and Site Artifacts Review: In an effort to evaluate each areas architectural layout, the team would request electronic copies of ‘As Builts’ that are related to the existing physical makeup of each site: that outline entry/exit points and site structures; that outline Electronic Security System (Access Control Systems, Intrusion Detection Systems, CCTV and Duress) components; that outline the physical infrastructure that is used to support the Electronic Security Systems; and that outline the existing Electronic Security System Network Enterprise (field components to local Premise Control Unit (security panels), Premise Control Unit(s) (security panels) to Switch/Server and Switch/Server to the Monitoring Stations). By evaluating these ‘As Builts’ the team will be able to determine if there are any vulnerabilities associated with existing physical and technical security postures; and will help the team evaluate existing components in their operating environments during Tier II. The team will also request data in relation to security system(s) hardware and software that support Electronic Security Systems (Electronic Access Control Systems, Intrusion Detection Systems, CCTV Systems and Duress Systems) be provided in an effort to identify any Standalone/Local Area Network (LAN)/Wide Area Network (WAN) vulnerabilities. The team will also request electronic copies of the Electronic Security System (ESS – CCTV, Intrusion Detection, Access Control and Duress) maintenance logs, alarm annunciation activity reports and installed equipment lists. These documents will be evaluated in an effort to identify design or operational flaws associated with the ESS, parts of the ESS that may be at its ‘end of life and parts of the ESS that may need to be adjusted. FSL Ratings: Once baseline information is collected, the team will then begin to create the Preliminary Facility Security Level (FSL) rating for OC sites in accordance with Homeland Security, Integrated Security Committee (ISC) standards. The FSL rating will consist of an evaluation of the Mission Criticality, Symbolism, Facility Population, Facility DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 18 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Size and the Threats to Tenant Agencies of each site; as outlined in the below rating chart: The Mission Criticality will be identified by working with OC to determine where within the county’s Business Impact Analysis/OC’s Logistical Logic Diagram is each site located. Each sites Symbolism will be determined by identifying what is the level of importance of each site within the local operating environment. Facility Population and Facility Size information would be gathered by working with OC’s facility department. Threat to Tenant Agencies information will be determined by evaluating past security incidents that have occurred at the sites and/or based on security incidents that have occurred at like sites within specific OC departments. The final scores assigned to Mission Criticality, Symbolism, Facility Population, Facility Size and Threat to Tenant Agencies will drive each site’s FSL rating; which in turn would outline the baseline security requirements for the sites based on the Homeland Security ISC standards. The initial rating can be adjusted (+ or -) depending on OC justifications. OC could use the ISC-FSL rating format to develop baseline levels of security protection for ‘all’ of its administrative/logistical facility sites throughout the county; which would help with future security planning, security procurement and security resource allocation efforts. Counties and Townships around the country are implementing the Homeland Security, ISC standards in an effort to establish minimum security requirements and in an effort to better allocate security resources. The team would request that site managers, site stakeholders and/or OC security personnel help the team formulate the initial FSL rating. Interviews and Questionnaires: During Tier I the team will conduct its initial interviews with OC stakeholders. The interviews would be used to capture opinionated data from OC stakeholders from each OC department through the use of pin-pointed questions. The team has learned that by making stakeholders part of the SRAMF-CPTED evaluation and development process they are more than likely to accept changes associated with security adjustments and upgrades. The interviews with stakeholder DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 19 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com personnel will help the team gain an understanding of daily operations and unique challenges that affect the security posture associated with individual OC departments. The team would request that Board Members, the Director of Facilities, Security Personnel and at least two staff members from each OC department be interviewed to gain an understanding of the security requirements of each department and how OC’s security posture affects their operating environments. The interviews will be conducted in person, via tele-conferences and/or within online meeting forums. Proposed On-Site Schedule: Once the team has gathered and evaluated initial data it will formalize dates to conduct the on-site assessments. The schedule will be put together in a way that enables the team to maximize resources and efforts while evaluating each decentralized site. Once the schedule is officially approved, team would then perform the on-site assessments during Tier II. _________________________________ Tier II: On-Site Assessments: The on-site assessments will be centered on logistics; the team being able to evaluate the existing physical security and CPTED settings at each site (during normal hours and after hours); evaluating previously implemented security measures; evaluating all Operational Procedures (Policy and Procedures); identifying opportunities to implement security leverage and phased mitigation practices; and on the team being able to effectively apply it’s SRAMF – CPTED Model. The team would request elevated visitor access while conducting the on-site assessments; and would request that OC departmental points of contact be designated during the on-site assessments. Site Evaluations: The team will identify how affective the existing security postures is for each site through observations, evaluations, industry best DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 20 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com practices/guidelines evaluations and by identifying the threats that may plague each individual site. The protection of OC’s Mixed Spaces and Restricted/Controlled Areas is centered on CPTED, Access Control, Site Security Management, Internal/Exterior Lighting, Surveillance (Natural and Electronic), Key Control, Stakeholder Awareness, Comprehensive Emergency Management (Emergency Response, Crisis Management and Business Recovery), Physical Security, Signage, Incident Reporting, Visitor Monitoring, Crime and Violence Prevention, Intrusion Detection, Duress Procedures, CCTV (Surveillance and Assessment) and Command and Control practices. The team has developed SRAMF-CPTED Criteria Matrixes that evaluate 103 key security points that are parallel to the Homeland Security Integrated Security Committee Standards which are centered on protecting people, assets and infrastructure. The key security points that will help OC achieve its project goals fall within the following CPTED Criteria’s: The team recognizes that OC sites each will have public settings, customer service settings and unique staff/visitor requirements that must be taken into consideration. _________________________________ The following is an example of an OC site and how the CPTED key security points would be applied throughout the project: DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 21 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com The Justice Center and District Attorney’s Office: Typical Highrise Multi-Floor Building and 1st Floor Markup Example: (1) (2) (3) (4) (4) (4) (4) (4) (4) (4) (1) (1) (2) (2) (3) (3) (1) (1) (1) (1) (1) (1) (1) (1) (2) (3) (3) (3) (3) (3) (3) (3) (4) (4) DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 22 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Site Security (1), Structure Security (2) and Facility Entrance Security (3): The team will begin evaluating each site at its outer most boundary and proceed to interior areas. By starting at the outermost boundary, the team will be able to evaluate vehicular and pedestrian routes; environmental designs; lighting schemes; parking; existing vegetation; the current placement of security components; physical security barriers (natural and man-made); and any previously implemented CPTED strategies. As the team advances towards interior areas, it will also be able to identify the existing access control methods and architectural features of each site (buildings/structures). By evaluating the local access control methods, the team will be able to identify entry/exit points, egress doors, employee convenience areas, locking bodies (mechanical key systems) associated with exterior areas, existing physical/electronic access control systems and any vulnerabilities that could be exploited by crime/threats that have not been identified. The team will also be able to identify any structural design flaws that are associated with barriers and building architectures that would hinder stakeholder CPTED efforts (damaged masonry, inadequate windows and incorrect door installations). The team will also conduct afterhours assessments to evaluate current CCTV coverage and identify afterhours access control vulnerabilities and unauthorized loitering/trespassing. Site Security Criteria (1): The following SRAMF-CPTED Criteria’s will be evaluated – Landscaping, Pedestrian Access to Sites, Vehicle Access Points, Site Lighting, Exterior Restricted and Controlled Areas or Significant Areas and Assets, Exterior Signage, Blast Zones, Control of Parking, Authorized Parking, Vehicle Access to Parking Areas (to include Controlled Parking), Barriers (to include fencing), Vehicle Screening, Pedestrian Access to Controlled Parking Areas, Duress Stations, Hazardous Materials Storage, Areas of Loitering/Trespassing, Trash/Dumpster Locations and Pedestrian Access to Site; which helps identify how visitors, tenant and staff member transit to/from each site; identifies exterior gathering areas; identifies how local landscaping hinders basic CPTED practices; and identifies the level of CPTED that has been implemented during exterior site design. (4) (4) (4) (4) (3) (3) (3) (3) DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 23 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com - The OC has outlined within Addendum 1 that it would like the transportation route between the Detention Center and the Justice Center to be evaluated. The project team will work with OC stakeholders to identify transportation and transit routes between each site to conduct a throughput study which would identify any risks that could obstruct the transportation of people or that puts staff member at risk while conducting official business. Structure Security Criteria (2): The following SRAMF-CPTED Criteria’s will be evaluated – Progressive Collapse, Burglary Resistance of Windows, Security of Walls and Non-Window Openings, Windows in Critical Areas, Protection of Air Intakes, Isolated Ventilation Systems, HVAC Control, HVAC Filtration, Security of Ventilation Equipment and Controls, Location of Utilities and Feeders, Separation of Emergency and Normal Power Distribution, Emergency Generator Protection, Protection of Water Supply, Protection of Building Systems and Roof Access; which would identify any design flaws that may exist within the architecture of each site that could be exploited to gain entry into site areas/systems or that could disrupt site operations. Facility Entry Security Criteria (3): The following SRAMF-CPTED Criteria’s will be evaluated – Badge/Fob Identification Systems, Regulatory Signage, Access Control (Doors, Lock and Electronic), Visitor Access Control, Convenience Doors, Building Entry Points, Perimeter Doors and Door Frame Construction, Building Entrance Co-Locations, Visitor Screening, Occupant Screening, Lobby Queuing, Emergency Exit Doors, After-hours Access Control, Control of Mechanical Keys/Access Cards/Pin Numbers, Delayed Egress and Mail/Stores/Freight-Handling/Screening; which helps identify traffic patterns and how access is gained onto each site/into buildings; and how access is gained through logistical areas. Interior Security (4), Security Systems (4), Security Operations and Administrative (4) and Cyber Security (4): Once the team has conducted an external evaluation of each site, it will then proceed to interior spaces. During the interior evaluation, the team will evaluate interior door/windows assemblies; traffic patterns; physical control measures (to include key control); locking devices; Electronic Security Systems (Access Control Systems, Intrusion Detection Systems, CCTV, Duress System and Mass Notification Components); traffic/lobby queuing; elevator; stairwell and floor security. If an Electronic Security System (Access Control, Intrusion Detection, CCTV, Duress, etc.) is in place, the team will perform functional tests, evaluate all utilities that are used to support the systems and evaluate command and control features (policy and electronics). The team will identify if these security measures protect asset areas and personnel. To gain an understanding of each sites operating environment, the team DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 24 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com will evaluate CCTV footage (to include subsystems) and access control system temporal/spatial patterns. These assessments will enable the team to evaluate light schemes (in place afterhours), evaluate the field of views of any existing cameras, identify traffic patterns, and identify any vulnerabilities that are associated with Electronic Security Systems/Command and Control Operations. Interior Security Criteria (4): The following SRAMF-CPTED Criteria’s will be evaluated – Space Planning, Interior Walls, Interior Doors and Door Locks, Interior Traffic Patterns, Lobby Queuing, Elevator Control, Stairwell Patterns and Access, Access to Mix Space, Duress Stations, Security of Critical Areas (to include Hazardous Material Storage Areas), Building System and Roof Access, Public Accessible Restrooms, Interior Windows and Access to Non-Public Areas; which helps identify how foot traffic is controlled within interior areas (to include waiting, transit and egress areas), building/structure layouts and site specific interior vulnerabilities. Security Systems Criteria (4): The following SRAMF-CPTED Criteria’s will be evaluated – CCTV Coverage, CCTV (Monitoring and Recording), Monitoring Stations/Security Operations Centers, CCTV Surveillance Signage, Intrusion Detection, Electronic Access Control, Duress Alarms, Security System Integrity, Security Communications, Building Mass Communication Systems, Emergency Power, Security System Testing, Security System Maintenance, Physical and Electronic Security and Security Infrastructure (management/design); which evaluates Electronic Security System management practices, system vulnerabilities and system infrastructure. - OC has identified within Addendum 1 that it has CCTV, Access Control and Duress systems in place; and an alarm system being added at the Justice Center. During the on-site assessments the team will perform sample-functional tests on each of the existing systems using its Electronic Security System (ESS) Test Plans that have been developed to evaluate ESS. The ESS Test Plans that would be potentially applied during this project consist of a: Badge/Fob Enrollment Station Test Plan, Camera Coverage Test Plan, Digital Video Recorder/Network Video Recorder Test Plan, Duress Alarm Test Plan, Equipment Enclosure Tamper Switch Test Plan, Line Supervision Test Plan, Network User Access Control Test Plan, Power Failure Battery Backup Test Plan, Vehicle Gate Test Plan and a Monitoring Station/Personnel Viewer Test Plan. The team would request that OC coordinate with the system stakeholders to provide support during each scheduled functional test. The team would also review the design drawings associated with the new system associated with the Justice Center to see if any vulnerabilities exist within the system as designed. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 25 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com The team has evaluated, tested and certified exterior and interior Electronic Security System platforms that consisted of Fence mounted Fiber-Optic Intelligence and Detection Systems, Passive Infrared Systems, CCTV Systems, Access Control systems, Badging Stations, Buried Line Sensors, Ground Radar Systems, Taut-Wire Systems, Infrared Perimeter Intrusion Detection Systems, Microwave Systems and Balanced Magnetic Switch/High Security Switch Systems for some of the nation’s most critical resource areas; which operated off of the Command and Control Systems (Intrusion Detection and Access Control and Duress) – Honeywell Vindicator, Honeywell Pro- Watch, Software House C-Cure, LenelS2 OnGuard, Door King, Gentec, Johnson Controls, DCS PowerSeries, PC4020 Household Burglary and Access Control; CCTV – Milestone, Axis, Video Image Control and Display System (VICADS), Digital Watchdog, Bosch, K- Guard and Eclipse Security; and Electronic Security Systems IT Network Enterprises – CISCO, Starlink Universal and Juniper. Security Operations and Administrative Criteria (4): The following SRAMF – CPTED Criteria’s will be evaluated – Security Operations Management (to include manpower), Security Awareness Training, Security Personnel, Response Time Objectives, Response Plan Objectives, Security Standard Operating Procedures, Security Quick Reaction Checklist, Security Event Communications, Comprehensive Emergency Management (CEM) Plans (Emergency Response, Crisis Management and Business Recovery), Guard/Security Officer contracts/agreements, O&M Contracts, Memorandum of Agreements/Memorandum of Understanding/Security Service Agreements with Vendors/Organizations, Security Incident Reporting, Organizational Security Plans, Facility Security Plans, Security During Construction and Renovations; which measures the effectiveness of the current security management processes (polices vs procedures), situational emergency response procedures and support services. Cyber Security Criteria (4): The following SRAMF-CPTED Criteria’s will be evaluated – ESS Network Identification (Standalone, LAN, WAN, Cloud, etc.), ESS Infrastructure (Copper/Fiber; Analog/IP), ESS Devices, ESS Cyber Security Policy, ESS Physical and Logical Access Control, ESS Configuration Management, ESS Integrity and Availability, ESS Network Enterprise Access Points and ESS Incident Response (failures and breeches); which identifies the cyber security framework that is used to protect the ESS and Identifies ESS vulnerabilities. Follow-On Interviews: As the team conducts its on-site assessments new questions in regards to the existing security postures will be developed based on site evaluations and information that was previously provided. In order to gain clarity, as a result of the on-site assessments, the team will conduct follow-on interviews with OC DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 26 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com stakeholders. The information gathered from these follow-on interviews will help the team complete the on-site assessments and will help it develop the SRAMF-CPTED Reports and CPTED-Security Master Plan. Identifying key personnel early on, that can provide information on the existing OC security posture, will enable the team to stay on schedule and meet project goals. The SRAMF-CPTED will enable OC to holistically evaluate the current security postures at all the sites associated with this project. At the conclusion of each day of the on-site assessments the team will conduct a hot wash (status meeting) with stakeholders to outline project progress. The team will also conduct bi-weekly status meetings throughout the project. If the team identifies any life-threatening vulnerabilities during the on-site assessments, it will immediately present the issue(s) to the designated stakeholder project manager. _________________________________ Tier III: Final Deliverables: This Tier will be a culmination of all information gathered during Tiers I and II. It will be used to create the SRAMF-CPTED Reports and will be used to create the CPTED-Security Master Plan. Final Reports: The team would create a comprehensive SRAMF-CPTED Report for each site assessed during the project. Years of Physical Security, Operations Security and Technical Security experience has enabled the team to create a report format that outlines the current levels of protection that are in place at the time of the assessment; in a true independent fashion. The SRAMF-CPTED Reports will consist of four sections: Executive Summary, Site Overview, Assessment Details and Threat Assessment. Executive Summary: The Executive Summary section of the reports, which is detachable, will outline an overall summary of the current security risk level for each site, the mitigation matrix recommendations listed in order of priority (that would be used to DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 27 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com mitigate security vulnerabilities) and cost estimates associated with recommendations. The team has found that C Suite/Senior Level Management are able to gain a comprehensive understanding of potential issues through this format and are able to share this information at the senior level. Site Overview: The Site Overview section of the report is used to publish site specific information which consists of area layouts, assets that were identified and information about the key stakeholders who supported the on-site assessments. The site overview section also publishes information about site neighbors and documents site activities/incidents that increase threat levels; which may have been previously unidentified/properly published. Assessment Details: The Assessment Details section of the report publishes the Levels of CPTED that were identified during the assessments, site observations and the security recommendations that could be used to mitigate the security vulnerabilities identified. This section of the report will publish information related to the key 103 security points that were evaluated during the on-site assessments; Site Security (19 CPTED Points), Structure Security (14 CPTED Points), Facility Security (17 CPTED Points), Interior Security (14 CPTED Points), System Security (15 CPTED Points), Operations and Administrative Security (16 CPTED Points) and Cyber Security for ESS (8 CPTED Points). The findings within this section of the report enables stakeholders to gain a snapshot of the current security posture. This section of the report will outline, in detail, CPTED observations, recommended CPTED improvements and cost estimates associated with the recommendations. All recommendations will be created based on identified industry best practices, threats/vulnerabilities that may be site specific and Homeland Security standards. Cost estimates associated with recommendations will be created through the use of the teams cost estimate formula. The below is an example of an Observation, Recommendation and Cost Estimate from an Assessment Detail Section statement: DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 28 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Risk Calculations: The Risk Calculations section of the report publishes all qualitative and quantitative threat data that was identified and evaluated to produce the final SRAMF-CPTED Risk Rating for each site. Threat data that will be published for each site will be based on the related site-specific threats. The following SRAMF-CPTED Risk Rating Chart is provided as an example of the Final Risk Ratings that will be published within the Risk Calculations section of the reports: DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 29 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com _________________________________ Security Master Plan: The Security Master Plan would be centered on publishing feedback on the existing CPTED postures; publishing the final FSL ratings for each site; raking all Administrative Vulnerabilities; ranking all Physical Security Vulnerabilities; publishing a proposed 36-month implementation schedule (CPTED Security Master Plan – Mitigation Priority Matrix); publishing security interview data; and publishing ESS functional test results. Feedback on the Existing Security Posture: Once the team has begun to compile data related to the overall assessments, it will be able to identify how effectively the existing CPTED measures protect OC sites. The team will take into account existing site conditions, the nature of recommendations that are proposed and the current crime/security/adverse events that plague each site location. Based off of these evaluations, the team will be able to determine if the existing CPTED measures are effective, if improvements need to be made or if new CPTED mitigation methods need to be introduced to OC’s existing security posture; outlining the overall CPTED Gap Analysis within this section of the Security Master Plan. Security Risk Levels and Final FSL Ratings: There are six sites associated with this project which could drive multiple threat model evaluations due to the nature of DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 30 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com business that each site conducts and based on temporal and spatial analysis of foot traffic associated with each site. By publishing and comparing these security risk levels, the team can help OC prioritize security mitigation efforts in order to correct security vulnerabilities in the form of a mitigation matrix (Critical, High Priority, Moderate Priority, Low Priority or Administrative in Nature). A chart ranking all sites by Final FSL ratings and security risk ratings will be published within this section of the Master Plan in an effort to enable OC to prioritize security funding and create a future assessment schedule. Administrative Vulnerabilities: Based on past assessments, the team understands that each site could have different security requirements and that administrative polices/procedures are the back bone of all security programs. These policies/procedures help publish security roles, security role competencies, security response procedures, incident reporting processes and outline administrative review processes. Within this section, the team will publish administrative vulnerabilities based on priority and will publish mitigative recommendations (to include cost) that will help reduce security risk associated with administrative vulnerabilities. The team will recommend administrative plans and training that would be applied through the use of ‘Leverage’ in an effort to reduce security administrative risks across each areas operating environment; and will then focus on ‘Phased Mitigation’ strategies (to include cost) which would reduce security risks to even lower levels. Physical Security Vulnerabilities: The team realizes that as it completes the on- site assessments different physical security vulnerabilities will be identified. These physical security vulnerabilities will more than likely be the result of original site design flaws, changing industry CPTED guidelines, changing site requirements, the identification of new threats and/or due to degradation of physical/electronic security components. The team would publish a physical security mitigation priority matrix that would be based on the overall security risks ratings. Physical/Electronic Security recommendations would be addressed through ‘Leverage’ methods and through the use ‘Phased Mitigation’ practices; and would also outline cost estimations associated with recommendations. 3 Year (36 Month) Schedule: The 3 Year (36 Month) Schedule would be used to implement and monitor security vulnerability mitigation efforts. The first 1 to 3 months of the schedule would outline all ‘no cost’ Administrative Recommendations that should be implemented. Within a parallel timeline of 1 – 6 months all Administrative Recommendations that have a cost association that should be DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 31 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com implemented, based on security risk levels and priority, would be outlined. In another parallel time line, the team will outline all physical security related recommendations that should be implemented within 1 – 36 months which includes: all critical security vulnerabilities that should be addressed within 1 – 6 months; high priority security vulnerabilities that should be addressed within 7 – 18 months; and moderate security priorities that should be addressed within an 18 – 36-month period. A repeated 3- month review event item would be used within the schedule to monitor security mitigation efforts throughout the 36-month period. Recommendations for improvements will be based on the criticality of assets, vulnerabilities, threats and current risk levels identified during on-site assessments and would be based on quantitative incidents that are Low-Frequency – High Impact or High-Frequency – Low Impact events that could cause major security incidents at each site. Below is an example of the final CPTED Security Master Plan – Mitigation Priority Matrix Excel File that would be provided to track security improvement efforts: Interview Data: Within this section, the team will also publish interview data that was provided by OC stakeholders during the project. ESS Functional Test Data: Within this section the team will publish the ESS components that were tested during the Tier II on-site assessments and how these ESS components performed (Pass, Failed and/or Observed Issues). Official Out-Brief: The official Out-Brief would be hosted in person at the completion of Tier III of Phase I. The out-brief would be used to officially publish the final Security Risk Levels, SRAMF-CPTED Reports, to publish the CPTED-Security Master Plan, to publish a summary of all findings and to obtain feedback from OC stakeholders. The team will provide ‘read ahead’ (draft documents) of the final reports and the master plan so that OC stakeholders can digest the findings and present questions during the DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 32 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com out-brief. The ‘read ahead’ (draft documents) would be provided 10 days prior to the official out-brief. _________________________________ Phase II – Draft Security Plan Development: Once Phase I is completed the team can then begin to identify which form of security plans would be most advantageous to OC security goals. The team would develop the plan(s) using the following two tiers: Tier I: Artifacts Evaluations | Tier II: Deliverable Creation _________________________________ Tier I – Artifacts Evaluation: The team will take into account existing security plans that may be in place, how effective these existing plans are, what plan context needs to be added (based on industry best practices and guidelines), which existing plan context needs to be omitted and will identify which security plan recommendations were accepted, rejected or tabled by OC based on the Phase I Observations and Recommendations. The team will focus on developing security plans that address existing threats associated with OC sites and plans that address the normal hazards associated public owned assets and plans that address security system management guidelines. Tier II – Final Deliverables: The team would draft the plan in a way that outlines the hierarchy of OC, publishes security roles and responsibilities, outlines everyday security policy/procedures, identifies how security information is communicated between staff members and that publishes incident response guides. Elements of the plan will be based on security industry best practices that have help other public organizations create security plans that improve security oversight efforts. Official Out-Brief: The official Out-Brief for the Draft Security Plan would be hosted at the completion of Phase II - Tier II. The out-brief would be used to officially DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 33 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com publish the Draft Security Plan. The team will provide a ‘read ahead’ document so that OC stakeholders can evaluate the draft plan and provide input on the draft plan. The ‘read ahead’ documents would be provided 10 days prior to the official out-brief. The team estimates that it will take 88 hours to complete Phase II of the project. The teams ‘Living’ Project Master Schedules will be used to manage all aspects of the Phase I and Phase II of the project. The Project Master Schedule publishes project tasks by months, weekly task objectives and daily executed tasks. The daily executed task schedule entries are updated every 3 hours in an attempt to identify any bottlenecks that could hinder weekly project goals; which would ultimately affect monthly project tasks. The Project Master Schedule also publishes the team member that is assigned to tasks and outlines team member progress reports. _________________________________ Related Experience and References: “What makes this consultant team any different from other firms?” This question comes to mind because of all the information that has been provided to OC in response to this RFP. One of the first differences you will notice is that the team is made up of true independent security consultant firms; not associated with the sale of any components or recommendation-profit based work. This is very important because the team will not make any security recommendations or propose any security designs that are profit driven and will act in the best interest of OC. The second difference that will be identified about the team is that the firms ‘are not corporations’ that apply the same security evaluation models during every project; never realizing that cookie-cutter security practices often leave stakeholders more vulnerable than they were before. The team will apply a threat and vulnerability driven SRAMF-CPTED model during this project in an effort to address ‘unique’ security issues and will provide OC with a fresh perspective on industry driven security practices. The third, and most important difference between the team and other responding firms is that its members are considered Risk Assessment, Management Security, Physical Security, CPTED and Electronic Security System Experts that possesses additional security expertise within different security niche markets. The team’s past performance has been centered on Management Security Improvement, Security Training, Security Plan Development, Security Risk Assessments, CPTED Evaluations, Physical Security Designs, Electronic Security Designs and Electronic Security System (ESS) IT Network Enterprise Designs. The Management Security DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 34 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com experience of the team will enable OC stakeholders to identify policy and procedures vulnerabilities that exists within its current security posture and identify management practices that are being applied to daily security operations to combat these vulnerabilities. The teams Security Risk Assessment experience will help OC identify the overall risks associated with each site and outline all factors that contributed to overall risk ratings; which will help OC justify the cost – benefits associated with security upgrades. The CPTED, Physical Security and Technical Security experience of the team will enable OC stakeholders to identify all vulnerabilities that may exist within the current security designs associated with each decentralized site. The expertise possessed by the team has helped raise past stakeholder risk awareness and has outlined key CPTED vulnerabilities that were often overlooked. The security industry exposure that the team has gained over multiple years of field work, multiple projects and experience evaluating decentralized programs are very applicable to a project of this scope. CTCH’s lead consultant has conducted over 500 Security Risk Assessments. Conducted 300 site surveys and has designed Electronic Security Systems (Intrusion Detection, Access Control, Duress and CCTV) in 26 states for the: National Weather Service Centers - Lincoln, IL; West Paducah, KY; Yorktown, VA; Charleston, SC; Dousman, WI; Calera, AL; Mobile, AL; Grand Rapids, MI; Flowood, MS; West Columbia, SC; Old Hickory, TN; Ashwaubenon, WI; Jackson, KY; Taunton, MA; Baltimore, MD; Wilmington, OH; Jacksonville, FL, Miami, FL; Caribou, ME; Calera, AL; North Charleston, SC; Gray, ME; Huntsville, AL; Melbourne, FL; Memphis, TN; Tallahassee, FL); National Marine Fisheries Service – Labs and Science Centers - Pascagoula, MS; St. Petersburg, FL; Miami, FL; Ann Arbor, MI; North Charleston, SC; Scituate, MA; Charleston, SC; Portland, ME; Savannah, GA; Stennis Space Center; MS; Pascagoula, MS; Fernandina Beach, FL; Fairhaven, MA; East Falmouth, MA; Oxford, MD; Indianola, MS; Pascagoula, MS; Ft. Lauderdale, FL; Davie, FL; Hollywood, FL; Highlands, NJ; Woods Hole, MA; Milford, CT; Norfolk, VA; Narragansett, RI; Charleston, SC; North Kingstown, RI; Panama City, FL; Port Orange, FL; Sunrise, FL; Woods Hole, MA; Toms River, NJ; Cape May, NJ; Highlands, NJ; Berlin, MD; Oakbrook Terrace, IL; Chatman, MA; International Trade Administration Centers - Jackson, MS; Chicago, IL; Lexington, KY; Grand Rapids, MI; and U.S. Export Assistance Centers - Birmingham, AL; Portland, ME, Atlanta, GA; Middletown, CT; U.S. Air Force Restricted and Controlled Areas – Vandenberg Space Force Base, California – Missile Defense Launch Facilities (LFs), Satellite Launch Complexes (SLCs), Industrial Chemical Storage Areas, Satellite Tracking Stations, Communication Hubs and Sensitive DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 35 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Compartmented Information Facilities (SCIFs); and Charlotte County - Water Utility Sites, Bridges, Cemeteries, Communication Towers, Event and Major Recreation Areas, Fire Stations, Parks, Support Buildings, Human Services, Justice Center, Family Service, Libraries, Logistic Sites, Multi-Tenant Sites, Satellite Sheriffs Offices, Sheriff Offices, Storage Yards, Waste Processing Stations, Sports Parks, Historical Centers, Civic Centers, Natural Resource Centers, Beach Complexes, Youth and Recreation Centers, County Administrator, Building-Land Development-Zoning, Human Resources, Purchasing Department, Planning Department, Clerk of Courts, Property Appraiser, Supervisor of Election, County Tax Collector, Division of Motor Vehicles, Facilities Management, Real Estate Services Division, Project Management, Guardian Ad Litem Program, Conference Rooms, County Commissioners Offices and County Commissioners Meeting Chambers. CTCH’s lead consultant has also conducted Security Risk Vulnerability Assessments at the following Universities: Grand Valley State University: CTCH’s lead consultant conducted a Security Risk Assessment that calculated campus asset risk exposure through Threat and Vulnerability analysis. By evaluating operational and physical vulnerabilities he was able to developed security recommendations that included cost estimates and that formulated FSL Ratings. Jackson State University (Jackson): CTCH’s lead consultant worked with the campus security office to conduct a Security Risk Assessment (SRA) on campus asset areas. The SRA enabled the consultant to affirm security issues associated with visitor control and response policies. The consultant was able to create a mitigation matrix that helped address security issues. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 36 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com University of Alabama (at Huntsville): CTCH” s lead consultant conducted a Security Risk Assessment at campus property areas in an effort to identify asset protection issues and to justify security improvement costs. The consultant calculated the overall security risk associated with the university based on existing threats and asset vulnerabilities. The University of Rhode Island: In response to a security incident CTCH’s lead consultant was asked to conduct a Security Risk Assessment on asset areas associated with the university. The data collected during the assessment enabled the consultant to identify physical security design flaws, issues related to incident response efforts and visitor control. Florida International University (at Miami): CTCH’s lead consultant conducted a Security Risk Assessment in an effort to identify campus security risk levels and the threats related to public owned asset areas. The assessments identified security vulnerabilities associated with physical security, visitor control, access control and security incident response procedures. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 37 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Florida State University (Tallahassee): CTCH’s lead consultant conducted a Security Risk Assessment on asset areas in an effort to identify existing security risk levels associated with public asset hosted by the university. By gathering threat data and evaluating asset areas the consultant was able to identify issues related to security operations and asset protection. Force Protect Security Consultants (FPSC): FPSC has performed over 250 Security Risk Assessments and has created security design packages and master plans for over 110 security projects. Over the course of the past ten years of consulting, FPSC’s clients include the Department of Veterans Affairs, Department of the Interior, Department of the Army, US Army Corp of Engineers, Department of the Air Force, University of Kentucky, University of Louisville, and numerous local and state governments, as well as commercial companies. In supporting the Department of Veterans Affairs, FPSC has performed campuswide risk assessments, created security master plans, and performed security design consulting for 98 VA Medical Centers and 153 clinics nationwide some of which are: Physical Security Risk Assessment - Parkland Health District, Dallas, TX; John J Pershing VAMC, Poplar Bluff, MO; Dwight D Eisenhower VAMC, Leavenworth, KS; George E. Wahlen VAMC, Salt Lake City, UT; Harry S Truman VAMC, Columbia, MO; Robert Dole VAMC, Wichita, KS; St Louis VA Healthcare System, St Louis, MO; Crossbridge Church, Madeira Beach FL; Robley Rex VAMC & Six CBOCs, Kentucky; VISN 2 (NEI) – VA New Jersey Health Care System (East Orange & Lyons); VISN 17 (Paradigm) – Texas VA Healthcare System; Shreveport LA VAMC; Waco TX VAMC; Wichita KS VAMC; Jesse Brown Chicago VAMC; Maryland VA Healthcare System; Lexington KY VAMC; Florida & Puerto Rico; Physical Security Risk Mitigation Design - Omaha, NE VA; Reno NV VAMC; Wichita, KS VAMC; Wichita, KS VAMC; Tucson AZ/OCAMES; Salt Lake City, UT VAMC; Bentonville, AR; OK City OK VAMC; EHRM Infrastructure (Spur) – Twelve VAMCs nationwide; Lovell Chicago IL VAMC; Wichita KS VAMC; Leavenworth, KS VAMC; West Roxbury MA VAMC; Wichita KS VAMC; Providence RI VAMC; West Roxbury VAMC; Augusta GA VAMC; Marion IL VAMC; Ozarks VAMC; Towbin AR VAMC; Little Rock AR JLM VAMC; Charleston, SC VAMC; Shreveport LA VAMC; Seismic Study Book - Albuquerque NM VAMC, White City OR VAMC; Palo Alto CA VAMC; Security Mental Health Clinic Study Book - Dallas, TX VAMC. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 38 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com References The following references are provided to outline the consultant teams most recent projects: CTCH References Charlotte County Water Utilities Department -– Security Risk and CPTED Assessments CTCH conducted Security Risk Assessments and CPTED evaluations on decentralized Water Reclamation Facilities (West Port, Rotunda, Burnt Store and East Port), Reclaimed Booster Station (Eagle Street), Water Booster Stations (Gulf Course, Rotunda, Walenda, and Gulf Cove) and a Water Treatment Facility (Burnt Store) within Charlotte County Florida. During the assessments CTCH conducted criticality, threat and vulnerability assessments which helped calculate the Utilities Departments current risk exposure (through the evaluation of threat data, by conducting interviews and by conducting site assessments). The final deliverables associated with this project was a multi-site CPTED Security Risk Assessment Report which outlined the findings and recommendations associated with all sites under the scope of the project; and a Security Master Plan that categorized (rack and stacked) recommendations based on implementation priority level. Point of Contact: Bryan Hatfield Operations Project Manager Address: 25550 Harbor View RD, Port Charlotte, FL 33980 Phone#/Email: (941) 764-4385 Bryan.hatfield@charlottecounty.gov Charlotte County Florida – Mechanical Lock Assessments CTCH partnered with FPSC (as a sub-contractor) to conducted door and mechanical gate lock assessments on 85 county buildings/sites that Identified 1,628 locking devices that were associated with 54 different lock manufactures. During the door and gate mechanical lock assessments, the project team was able to identify the levels of key control in place and the methodology used within the different county departments to install mechanical locks and replace keys. As a result of the door and gate mechanical assessments, the project team was able to make recommendations towards door assembles, gate, mechanical lock and electronic access control; presenting these recommendations through the use of two cost estimates that would help the county Point of Contact: Anthony Pribble Security Manager Address: 18500 Murdock Circle, Port Charlotte, FL 33948 Phone#/Email: (941) 764-4923 anthony.pribble@charlottecounty.gov DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 39 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com establish a Grand Master Key System; and that would help set a baseline CPTED key control policy. The project team was also able to developed Grand Master - Master Key waterfalls for all 85 county buildings/sites associated with the project. Charlotte County Florida - Access Control and Lock Schedule Evaluations CTCH conducted Lock Schedule and Access Control Evaluations on decentralized county Fire Stations, Water Treatment Plants, Booster Stations, Storage Yards, Lift Stations, Public Works, Libraries, Courthouses, Public Annexes and Sheriff Offices that identified CPTED vulnerabilities. During the evaluations, CTCH evaluated the existing levels of CPTED control measures in place at each facility, identified the locking bodies (lock methods) used to secure all exterior and interior assets, the electronic access control systems in place and window security practices. The evaluations enabled CTCH to identified design flaws associated with electronic strike locks, electronic maglocks, ciper locks, electronic requests for exits, intrusion detection systems, key lock devices, key control, door designs and window designs. The final deliverable associated with this project was a Lock Schedule Report that outlined all Door Hardware associated with each site evaluated, flaws associated with electronic access control systems, mechanical door/lock flaws and CPTED vulnerabilities Point of Contact: Anthony Pribble Security Manager Address: 18500 Murdock Circle, Port Charlotte, FL 33948 Phone#/Email: (941) 764-4923 anthony.pribble@charlottecounty.gov Charlotte County Florida - Security Requirements and CPTED Site Surveys CTCH conducted Security Requirement Site Surveys on decentralized county Bridges, Cemeteries, Communication Towers, Event and Major Recreation Areas, Fire Stations, Parks, Support Buildings, Human Services, Justice Center, Family Service, Libraries, Logistic Sites, Multi-Tenant Sites, Satellite Sheriffs Offices, Sheriff Offices, Storage Yards, Waste Processing Stations, Sports Parks, Historical Centers, Civic Centers, Natural Resource Centers, Beach Complexes, Water Utility Sites and Youth and Recreation Centers. The Site Surveys enabled CTCH to create baseline security and CPTED requirements for: Perimeter Security, Building Boundary Security, Interior Security, Asset Area Security, and Site Support Security. Point of Contact: Anthony Pribble Security Manager Address: 18500 Murdock Circle, Port Charlotte, FL 33948 Phone#/Email: (941) 764-4923 anthony.pribble@charlottecounty.gov DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 40 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com The final deliverables associated with this project were Security-CPTED Requirement Matrixes that outlined the baseline security requirements for 113 sites throughout Charlotte County. Charlotte County Florida - Security Risk and CPTED Assessments CTCH conducted Security Risk Assessments and CPTED evaluations at the Charlotte County Headquarter Complex located at Murdock Circle. Complex tenants consist of County Administrator, Building-Land Development-Zoning, Human Resources, Purchasing Department, Planning Department, Clerk of Courts, Property Appraiser, Supervisor of Election, County Tax Collector, Division of Motor Vehicles, Facilities Management, Real Estate Services Division, Project Management, Guardian Ad Litem Program, Conference Rooms, County Commissioners Offices and County Commissioners Meeting Chambers. During the assessments CTCH conducted criticality, threat and vulnerability assessments which help calculate the County Headquarters Complex current risk exposure (through the evaluation of threat data, by conducting interviews and by conducting site assessments). The final deliverables associated with this project was a multi-building CPTED Security Risk Assessment Report which outlined the findings and recommendations associated with all sites under the scope of the project; and a Security Master Plan that categorized (rack and stacked) recommendations based on an implementation priority level. Point of Contact: Anthony Pribble Security Manager Address: 18500 Murdock Circle, Port Charlotte, FL 33948 Phone#/Email: (941) 764-4923 anthony.pribble@charlottecounty.gov Los Angeles County Office of Education (LACOE) - Security Risk and CPTED Assessments CTCH partnered with NextStep Solutions and conducted Security Risk Assessments and CPTED evaluations at the LACOE's Headquarters Educations Center, Education Center East and Education Center West in Downey; and at the LACOE Head Start Headquarters in Santa Fe Springs. The Risk Assessments enabled the consultant team to identify CPTED vulnerabilities that were associated with site barriers, lighting, parking lots, vegetation, exterior asset areas, site buildings, security guards’ operations and security operational procedures. Point of Contact: Richard Cepeda Emergency Preparedness and Security Officer Address: 9300 Imperial Hwy, Downey, CA 90242 Phone#/Email: (562) 922-6220 DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 41 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com The final deliverables associated with this project was a multi-site CPTED Security Risk Assessment Report which outlined the findings and recommendations associated with all sites under the scope of the project; and a Security Master Plan that categorized (rack and stacked) recommendations based on an implementation priority level. FPSC References Nebraska-Western Iowa VA Health Care System, Feasibility Study – Security Surveillance Infrastructure Upgrades Conducted a feasibility study for upgrade of the Security Surveillance Television (SSTV) system for the Nebraska – Western Iowa Health Care System. Scope involved the Omaha, Lincoln, and Grand Island VA campuses and all subordinate CBOCS to meet the requirements of the VA Physical Security and Resiliency Design Manual (PSRDM) and VA Security Audits. Cost Order of Magnitude averaged $4.5 million per campus. Point of Contact: Brian Hovey COR, Engineer Address: 4101 Woodworth Ave Suite 4199, Omaha, NE 68105 Phone#/Email: 800-451-5796 brian.hovey@va.gov George O’Brien VAMC, Big Spring, Texas Security System Upgrade (519-18-5000) $5 million project consisted of replacing and upgrading components of the existing campus security system, including the campus interconnecting fiber optic network that links the buildings. Additionally, the scope included the establishment of the Security Equipment Room (SER) of the Police Security Control Center (SCC), complete with a new PSIM, SSTV VMS, PACS SMS, and IDS SMS. Physical Access Control (PACS)- specific scope: Integrated PSIM and SSTV into a unified system and install up to date PACS devices throughout all buildings. Point of Contact: Joshua Junkin, COR Gene Lavastida, Prime Address: 300 W. Veterans Blvd, Big Spring, TX 79720 Phone#/Email: (432) 263-7361 joshua.junkin@va.gov gene@prime-arch.com Veterans Integrated Service Network (VISN 17), Texas, Physical Security Risk Assessments Conducted Physical Security Risk Assessments on State of Texas Veterans Affairs system (VISN 17) consisting of ten VA Medical Centers and forty clinics. Risk assessment incorporated threat, vulnerability, and gap analysis. The risk assessments identified $298 million+ worth of campuswide projects, including perimeter hardening fence/walls & Point of Contact: Paul Miller Asset Engineer Address: 1201 East 9th Street, Bonham, TX 74418 Phone#/Email: 800-924-8387 DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 42 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com automated gates, facility blast protection, CPTED Vulnerabilities, facial recognition and trespass analytic Security Surveillance Television (SSTV), mail/package screening, enhancement of Electronic Security Systems (ESS), security lighting, signage, critical utility resiliency and redundancy, conversion of loading docks to secure service yards, and improved Security Control Centers SCC. paul.miller@va.gov George Whalen Veterans Affairs Medical Center Salt Lake City, Utah, Physical Security Risk Assessment Study Completed a Physical Security Risk Assessment study that incorporated threat, criticality, vulnerability, and gap analysis. Asset criticality, coupled with threat vs vulnerability, were assessed to support a gap analysis of PSDM measures in effort to validate mitigation recommendations, as well as variances. Both physical and cyber penetration tests were conducted on each campus. Replace existing fencing; Implement four levels of perimeter and building security measures; Implement an as-FPCON-dictated vehicle screening checkpoint; Rerouted select roadways, enclose loading docks within service yards, and adjust curbing and parking in order to preserve/enforce building standoff requirements; Redesigned parking areas; Enhance CPTED measures to include territorial definition, lighting, wayfinding & signage, anti-ram barriers, and traffic control; Enhance protection and redundancy of campus utilities with updated technology layers of protection, including tighter control of all utilities and utility buildings; and Complete upgrade of all Electronic Security Systems (ESS) across the campus to include VASS/SSTV, PACS, IDS, DSPI. Point of Contact: Travis Payne, COR Address: 500 Foothill Dr, Sal Lake City, UT 84148 Phone#/Email: (801) 582-1565 travis.payne@va.gov Robert Dole VA Medical Center, Wichita, KS, Physical Security Assessments Completed Physical Security Risk Assessment study on the entire Robert Dole VA Medical Center and nine CBOCs in cities throughout Kansas. Risk assessment incorporated threat, criticality, vulnerability, and gap analysis. Asset criticality, coupled with threat vs vulnerability, were assessed to support a gap analysis of PSDM measures in effort to validate mitigation recommendations, as well as Variances. Both physical and cyber penetration tests were conducted on each campus, based on asset criticality vs suspected vulnerability. Prioritized facility solution plans were proposed (in report form) for the Robert Dole VAMC system regarding Point of Contact: Conrad Pierce, COR Address: 5500 E. Kellogg Ave, Wichita, KS 67218 Phone#/Email: (316) 210-5361 DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 43 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Architectural Security, CPTED, Perimeter Security, Electronic Security, Cyber Information Security, Policy & Procedures, Security Force staffing, Utility Redundancy and Protection, Solutions Cost Estimation, Cost Feasibility Analysis and Variance Requests. Saint Louis VA Healthcare System, Saint Louis, MO, Physical Security Assessments Completed a Physical Security Risk Assessment study on the entire VA St Louis Healthcare System (VASLHCS) consisting of the John Cochran VAMC, the Jefferson Barracks VAMC and thirteen CBOCs in cities throughout St Louis proper (MO & IL). Risk assessment incorporated threat, criticality, vulnerability, and gap analysis. Asset criticality, coupled with threat vs vulnerability, were assessed to support a gap analysis of PSDM measures in effort to validate mitigation recommendations, as well as Variances. Both physical and cyber penetration tests were conducted on each campus, based on asset criticality vs suspected vulnerability. Prioritized facility solution plans were proposed (in report form) for the VASLHCS regarding Architectural Security, CPTED, Perimeter Security, Electronic Security, Cyber Information Security, Policy & Procedures, Security Force staffing, Utility Redundancy and Protection, Solutions Cost Estimation, Cost Feasibility Analysis and Variance Requests. Point of Contact: Leslie Kasprzyk, COR Mike Beitenman, COR Address: 915 N. Grand Blvd, St . Louis, MO 63103 Phone#/Email: (314) 652-4100 x 58723 (314) 652-4100 x 58729 Project team members have been able to meet all goals associated with past projects due to the detailed ‘Living’ Project Master Schedules the team creates for each project. This enables CTCH’s project teams to manage project workloads, stay on schedule and forecast potential project bottlenecks. The project team possesses the ability to increase its project workforce if any of the requirements related to this project increase, if there is a change in project scope or if another procurement effort is established. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 44 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 45 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 46 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 47 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com 4. Follow-On Services Follow-On Services: CTCH can provide follow-on services in parallel to this original RFP or can provide follow-on services after the RFP deliverables are completed (under another procurement effort). These follow-on services consist of Security Project Oversite, Testing and Certification Services, Security Training, CPTED Requirements Matrix Development and Security Requirements; which would each add value to OC’s security improvement efforts. Security Training: CTCH has developed Workplace Violence and Physical Security seminars that have been developed from benchmarks within the security industry. CTCH has hosted Workplace Violence and Physical Security seminars within the cities of Santa Barbara, San Louis Obispo, Santa Maria and Lompoc. The Workplace Violence seminar is centered on identifying the types of Workplace Violence, Acts of Workplace Violence, Stressors, Indicators – Threatening Behavior, Intervention, Prevention, Impacts, Active Shooter and Lockdown. The main purpose of the Workplace Violence seminar is to raise awareness and to have organizational personnel develop an open dialog about Workplace Violence (issues and prevention). The Physical Security seminar is centered on Physical Security Development, Industry Trends, Industry Pitfalls, Risk Management, Cost Benefits, Network Enterprises Designs, Shelter-in-Place, Electronic Security System Convergence/Design and Security Risk Assessments. The physical security training helps stakeholders gain an understanding on physical security principals and logical security frameworks. CTCH can also conduct security plan functional exercises with OC and its stakeholders to measure security response plan objectives and security response time objectives. The exercises would also be used to test the cohesiveness of Security Professionals, Incident Commanders and Incident Response teams; and would measure the effectiveness of the reporting processes between Senior Managers, Public Affairs, Security Professionals, Incident Commanders and Incident Response teams. Prior to the exercises beginning CTCH would identify the scenario-based exercises that would be conducted. CTCH would utilize OC’s current/new Emergency Response Procedures to conduct exercises: Suspicious Package Incident(s) Active Shooter Incident(s) Workplace Violence Incident(s) Site Security Incident(s) Building Evacuation Incident(s) Specific Security Incident(s) DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 48 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Once the exercise scenarios are approved by OC, CTCH will work with the project manager to identify the stakeholders who would participate in the exercises. When the exercise stakeholders have been identified, CTCH would then publish the exercise schedule. As a caveat to this schedule, CTCH will recommend that the exercises be conducted during working hours and after working hours. This will enable OC to measure response efforts using a 360-degree spectrum model. Once the exercises have been completed CTCH will conduct hot-wash meetings with OC stakeholders and make recommendations on security plan improvements via a scenario test report. CPTED Requirements Matrixes: In an effort to help OC create a baseline CPTED- Security policy for its existing and future assets, CTCH could develop CPTED Requirement Matrixes that could be injected into construction/retrofit/integration acquisition documents. The CPTED Requirements Matrixes could be used to set the baseline CPTED-Security requirements for ‘like’ sites/properties/buildings in between recurring CPTED Assessments. The tailored CPTED Matrixes would publish baseline Perimeter Security, Building Boundary Security, Interior Security and Site Support CPTED requirements. The Perimeter Security Matrix would outline requirements related to Landscaping, Pedestrian Access to Sites, Vehicle Access Points, Site Lighting, Exterior Restricted and Controlled Areas or Significant Areas and Assets, Exterior Signage, Control of Parking, Authorized Parking, Vehicle Access to Parking Areas (to include Controlled Parking), Barriers (to include fencing), Vehicle Screening, Pedestrian Access to Controlled Parking Areas, Duress Stations, Hazardous Materials Storage, Areas of Loitering/Trespassing, Trash/Dumpster Locations, Exterior Parking Lots and Pedestrian Access to Site. The Building Boundary Matrix would outline requirements related to Burglary Resistance of Windows, Security of Walls and Non-Window Openings, Windows in Critical Areas, Protection of Air Intakes, Isolated Ventilation Systems, HVAC Control, HVAC Filtration, Security of Ventilation Equipment and Controls, Location of Utilities and Feeders, Separation of Emergency and Normal Power Distribution, Emergency Generator Protection, Protection of Water Supply, Protection of Building Systems and Roof Access. The Interior Security Matrix would outline requirements related to Badge Identification System, Regulatory Signage, Access Control (Doors, Lock and Electronic), Visitor Access Control, Convenience Doors, Building Entry Points, Perimeter Doors and Door Frame Construction, Building Entrance Co-Locations, Visitor Screening, Occupant Screening, Lobby Queuing, Emergency Exit Doors, After-hours Access Control, Control of Mechanical Keys/Access Cards/Pin Numbers, Delayed Egress, Mail/Stores/Freight- Handling/Screening, Space Planning, Interior Walls, Interior Doors and Door Locks, DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 49 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Interior Traffic Patterns, Lobby Queuing, Elevator Control, Stairwell Patterns and Access, High-Rise Floor Security, Access to Mix Space, Duress Stations, Security of Critical Areas (to include Hazardous Material Storage Areas), Building Systems, Public Accessible Restrooms, Interior Windows and Access to Non-Public Areas. The Site Support Security Matrix would outline requirements related to CCTV Coverage, CCTV (Monitoring and Recording), Monitoring Stations/Security Operations Centers, CCTV Surveillance Signage, Intrusion Detection, Electronic Access Control, Duress Alarms, Security System Integrity, Security Communications, Building Mass Communication Systems, Emergency Power, Security System Testing, Security System Maintenance, Physical and Electronic Security, Guard/Security Officer Management, Security Infrastructure (management/design), Security Operations Management (to include manpower), Security Awareness Training, Security Personnel, Response Time Objectives, Response Plan Objectives, Security Standard Operating Procedures, Security Quick Reaction Checklist, Security Event Communications, Comprehensive Emergency Management (CEM) Plans (Emergency Response, Crisis Management and Business Recovery), Security Contracts, O&M Contracts, Memorandum of Agreements/Memorandum of Understanding/Security Service Agreements with Vendors/Organizations, Security Incident Reporting, Organizational Security Plans, Facility Security Plans, Security During Construction and Renovations, Electronic Security Systems Network Identification (Standalone, LAN, WAN, Cloud, etc.), Electronic Security Systems Infrastructure (Copper/Fiber; Analog/IP), Electronic Security Systems Devices, Electronic Security Systems Cyber Security Policy, Electronic Security Systems Physical and Logical Access Control, Electronic Security Systems Configuration Management, Electronic Security Systems Integrity and Availability, Electronic Security Systems Network Enterprise Access Points and Electronic Security Systems Incident Response. Security Requirements and Design: CTCH could provide support to OC as it moves forward with implementing security improvements as a result of the initial assessments. CTCH could provide services that help OC during future Physical Security and Electronic Security System procurement efforts. As an additional task order, CTCH could conduct security requirement assessments. These site/property security requirements assessments will enable CTCH to validate property infrastructure conditions that would influence new security installs/retrofits. CTCH would also validate any physical/electronic security requirements that were identified previously. By validating property conditions, CTCH could then identify requirements associated with future security RFP/RFQ/RFI procurement documents. The requirements documents created by CTCH would be centered on Construction: Division DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 50 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com 8 (Doors), Division 10 (Signage), Division 23 (HVAC), Division 26 (Electrical), Division 27 (Communications), Division 28 (Electrical Safety and Security), Division 32 (External Improvements Fencing – Signage) and Division 33 (Underground Distributions); if required. Each of these construction divisions are very often related to Electronic Security System and Physical Security projects. Other Construction Divisions could be identified during the requirements assessments. Once all construction division requirements are identified, CTCH could then begin to create the install/retrofit drawings associated with security upgrades. The drawings created by CTCH would publish floor plan/site layouts that depict the areas that are associated with new install/retrofits; would publish riser drawings of components that would need to be installed; and would publish line drawings that depict component installations and communication pathways. If the CTCH were to identify any civil construction requirements that are out of scope it would present this information to OC for further review. CTCH would also publish cost estimates with the design concepts. The cost estimates will be based on prospective components and labor costs associated with new installs/retrofits. Security System Specifications and CPTED Design Experience: The following security design examples are provided in an effort to outline CTCH’s level of experience Creating Security System Specifications and Designing Electronic Security Systems (Intrusion Detection Systems, Access Control Systems, CCTV Systems and Duress Systems) and creating CPTED drawings for properties: (examples have been sanitized and shortened due to sensitivity) Specifications (Example) - System Description: “Modify existing Electronic Security Systems (ESS), including associated equipment and appurtenances. The design of the ESS shall include devices and equipment used to detect intrusion, control access to restricted and controlled areas, detect and deny unauthorized entries within specific areas, generate reports, produce Photo Identification badges, provide surveillance and annunciate alarms. The ESS shall be designed to provide operational flexibility and reliable performance. The ESS shall be modular, allowing for future incremental expansion or modification of inputs, outputs, and remote-control stations. Integrated system capabilities shall include but not be limited to Intrusion Detection, Automated Access Control Intercommunications, and Photo Badge Identification. Each system shall be complete and ready for operation (turn-key) and provide for a fully integrated central station solution.” DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 51 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Specifications (Example) - ESS Components: “Submit drawings that clearly and completely indicate the function of each ESS component. Indicate termination points of devices, and interconnections required for system operation. Indicate interconnection between modules and devices. In addition, submit a layout drawing showing spacing of components, location, mounting and positioning details.” Specifications (Example) - Overall System Schematics: “Indicate the relationship of integrated components on one diagram and show power source, system controls, impedance matches; plus number, size, identification, and maximum lengths of interconnecting wires. Drawings shall be not less than 11 by 17 inches.” Specifications (Example) - Installer's Qualifications: “Prior to installation, submit data of the installer's experience and certified qualifications. Show that the installer who will perform the work has a minimum of 5 years’ experience successfully installing ESS, be certified to install proposed equipment by manufacturer and design as specified herein. Include the names, locations, and points of contact of at least three installations of the same type and design as specified herein where the installer has installed such systems. Indicate the type of each system and certify that each system has performed satisfactorily in the manner intended for a period of not less than 12 months.” System Design Examples: Electronic Security System Network Diagram (Wide Area Network (WAN)): DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 52 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 53 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 54 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Interior Distribution Box - Premise Control Unit and Sub Components DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 55 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Intrusion Detection System – Balance Magnetic Switch (BMS) Wiring Diagram Drawing Access Control System – Badging Station Network Diagram DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 56 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Door Designs (Access Control System and Intrusion Detection System): Route conduit, concealed in the wall, provide 1 ½ inch EMT with pull String DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 57 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Egress Only Door(s) – If Double Doors – Infrastructure Details DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 58 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Electronic Access Control Door with Intrustion Detection Infrastructure Details Loading Dock Door(s) – Infrastructure Details (ACS and IDS) DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 59 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Camera Details Intrusion Detection System – Passive Infrared (PIR Ceiling Mount) Details DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 60 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Interior and Exterior CPTED Designs DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 61 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Security Design Cost Estimates: CTCH develops its security cost estimates based on market research that is related to physical security components (doors, building materials, infrastructure and electronic components); labor hour estimates; and miscellaneous items (overhead, logistics, etc.) that are often related to security projects. In an effort to obtain fair market estimates related to security components, CTCH will conduct market research via the internet; identifying at least 5 vendors who sell the same products; and then averages the costs associated with like components. This enables CTCH to identify the average market value of a particular product. In some cases, depending on the type of component required, CTCH will work with local area vendors to gain market value data due to some security components manufacturers only selling their products to authorized vendors or to direct sellers. Once the CTCH has completed its fair market analysis on Physical Security Components, it then identifies the labor rates associated with the area(s) where the work will be performed. CTCH will utilize the U.S. Department of Labor rates associated with job titles within the state or local area; evaluate the local union labor rates associated with job titles; evaluate bid results for similar projects to identify the labor rates associated with certain job titles; and utilize the known labor rates that have been applied to similar projects within the state or local area. Once CTCH has identified the Physical Security Component Costs and Labor Rates, it will then calculate the estimated labor/working hours that would be needed to complete project tasks. CTCH’s cost estimates are also centered on evaluating the labor costs, component costs and overhead costs associated with past projects (new construction, retrofit, integrations, etc.); on research performed on similar projects; and on RFI data that is gained from local labor pools. For truly large-scale projects, CTCH works with professional project estimators who have experience within the security project estimating fields. Once CTCH has identified the physical security components costs, labor rates and estimated overhead costs it will then use the below formula to calculate recommendation costs: x = Component Cost a = Labor Rate b = Labor Hours m = 15% Industry Markup (overhead, logistics, market inflation, etc.) z = Component Cost + Direct Labor Cost DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 62 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com z x m = c z + c = Final Estimate Cost Example: x + (a x b) = z z (m) = c z + c = (Final Estimated Costs) $200 + ($15 per hr x 20 hrs) = $500 $500 (15%) = 75 $500 + 75 = $575 (Final Estimated Costs) Security Project Oversight: As OC moves forward with the creation of 3rd Party procurement packages, CTCH could provide administrative support (bid reviews, selection board assistance, quality assurance inspections, project steering and master schedule tracking). Once OC has finalized its 3rd Party selection efforts, CTCH could oversee the integration and installation efforts associated with sub-projects. CTCH would accomplish this by working with 3rd Party vendors to develop a Master Schedule and a change review process. The Master Schedule would be centered on all deliverables associated with new installations and retrofits, project milestones, progress reporting periods and quality assurance efforts. The implemented change review process would be centered on tracking changes and out of scope items. In an effort to maintain control of all 3rd Party project efforts, CTCH would identify ‘Critical Milestones’ within the Master Schedule. During the new construction/retrofit efforts CTCH could also conduct quality assurance inspections as individual project efforts mature. Once all project milestones have been completed for a follow-on project, CTCH could gain permission from OC to Test and Certify newly installed/ retrofitted/integrated - Physical/Electronic Security System components. Testing and Certification: At the conclusion of third-party security installations efforts, CTCH could begin the system testing and certification process. The testing and certification process would begin by obtaining all artifacts associated with installs which include electronic configurations and red line ‘As Builts’. CTCH has created testing plans that evaluates all logical and physical components associated with Electronic Security Systems. The testing plans are centered on 8 key Testing Criteria’s that are centered on: Infrastructure (3 Areas), Power (2 Areas), Programming and Configuration (6 Areas), Electronic Sensors (6 Areas), CCTV (4 Areas), Badging/Physical Access Control (2 Areas), DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 63 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Mechanical Gates/Electronic Doors (3 Areas), and Logical Access: Switch/Router – Access and Configuration (5 Areas). Once OC has accepted the Electronic Security System(s) CTCH would conduct a final artifacts turnover with OC Stakeholders and 3rd Party Vendors. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 64 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Certified Security Consultant (CSC) To be eligible and be considered by The International Association of Professional Security Consultants (IAPSC) as a Certified Security Consultant (CSC), a candidate must have at least 3 years of documented previous security consulting experience prior to being eligible for the certification. CTCH’s Senior Consultant achieved certification (1 of 26 Consultants World Wide) in 2015 and is certified to provide consulting services in the areas of: Physical Security Risk Assessment Consulting Security Operations Consulting Security Surveys Consulting Security Training Consulting Security Management Consulting Security Plans Consulting Security Services Consulting Security Technology Design and Support Consulting Security Polocies and Procedures Consulting Security Technology Standards Consulting Appendix A DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 65 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Physical Security Professional (PSP) To be eligible and be considered by American Society for Industrial Security (ASIS) International as a Certified Physical Security Professional (PSP) candidates must have at least 6 years of previous experience in the Physical Security Field prior to being eligible for the certification. CTCH’s Senior Consultant achieved certification in 2011 and is certified to provide Physical Security Consulting services in the following areas of security: Physical Security Assessment - Develop physical security assessment plan; Identify assets to determine their value, criticality, and loss impact; Assess the nature of the threats so that the scope of the problem can be determined; Conduct assessments to identify and quantify security vulnerabilities of the organization; and perform a risk analysis so that appropriate countermeasures can be developed. Application, Design, and Integration of Physical Security Systems - Establish security program performance; Determine appropriate physical security measures; Design Physical/Electronic System; and Prepare construction and procurement documentation. Implementation of Physical Security Measures - Outline criteria for pre-bid meeting to ensure comprehensiveness and appropriateness of implementation; Procure system and implement recommended solutions to solve problems identified; Conduct final acceptance testing and implement/provide procedures for ongoing monitoring and evaluation of the measures; Implement procedures for ongoing monitoring and evaluation throughout the system life cycle; and Develop requirements for personnel involved in support of the security program. DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 66 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 67 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com ICA CPTED Certified Program – Practitioner (ICCP-Practitioner) The ICA CPTED Certification Program - called the ICCP - is a competency-based certification program. It is intended for individuals experienced in crime prevention with a focus on CPTED who would like to have their competencies recognized and certified by the only internationally represented professional CPTED organization - the ICA. In brief, the overarching goal of the ICCP is both to "test" the applicant and also to "educate" the applicant by mentoring through the certification process and providing feed back to applicants. ICCP Certified CPTED Practitioner (ICCP-Practitioner) - Intended for CPTED practitioners with demonstrated mastery in 8 Competency Units applying best CPTED research and practice outlined below: • Define the Scope of Security Project Tasks • Support Multidisciplinary Property Development/Architectural/Construction Project Management Teams • Research and Identify land usage Topography and Site Work requirements • Evaluate and Create Construction Design Drawings • Identify and Apply Security and Regulatory Processes • Conduct Site Assessments • Create CPTED and Security Risk Assessment Reports • Identify and Execute CPTED Principals DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 68 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 69 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 70 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com Appendix B DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 71 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 72 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 73 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 74 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB P a g e 75 Orange County Facilities Security Assessment RFP#: 367-OC 5403 CTCH Security Business Consulting – www.ctchconsulting.com DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB ANY PROPRIETOR/PARTNER/EXECUTIVE OFFICER/MEMBER EXCLUDED? INSR ADDL SUBR LTR INSD WVD PRODUCER CONTACT NAME: FAXPHONE (A/C, No):(A/C, No, Ext): E-MAIL ADDRESS: INSURER A : INSURED INSURER B : INSURER C : INSURER D : INSURER E : INSURER F : POLICY NUMBER POLICY EFF POLICY EXPTYPE OF INSURANCE LIMITS(MM/DD/YYYY) (MM/DD/YYYY) AUTOMOBILE LIABILITY UMBRELLA LIAB EXCESS LIAB WORKERS COMPENSATION AND EMPLOYERS' LIABILITY DESCRIPTION OF OPERATIONS / LOCATIONS / VEHICLES (ACORD 101, Additional Remarks Schedule, may be attached if more space is required) AUTHORIZED REPRESENTATIVE EACH OCCURRENCE $ DAMAGE TO RENTEDCLAIMS-MADE OCCUR $PREMISES (Ea occurrence) MED EXP (Any one person) $ PERSONAL & ADV INJURY $ GEN'L AGGREGATE LIMIT APPLIES PER:GENERAL AGGREGATE $ PRO-POLICY LOC PRODUCTS - COMP/OP AGGJECT OTHER:$ COMBINED SINGLE LIMIT $(Ea accident) ANY AUTO BODILY INJURY (Per person) $ OWNED SCHEDULED BODILY INJURY (Per accident) $AUTOS ONLY AUTOS HIRED NON-OWNED PROPERTY DAMAGE $AUTOS ONLY AUTOS ONLY (Per accident) $ OCCUR EACH OCCURRENCE CLAIMS-MADE AGGREGATE $ DED RETENTION $ PER OTH- STATUTE ER E.L. EACH ACCIDENT E.L. DISEASE - EA EMPLOYEE $ If yes, describe under E.L. DISEASE - POLICY LIMITDESCRIPTION OF OPERATIONS below INSURER(S) AFFORDING COVERAGE NAIC # COMMERCIAL GENERAL LIABILITY Y / N N / A (Mandatory in NH) SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE THE EXPIRATION DATE THEREOF, NOTICE WILL BE DELIVERED IN ACCORDANCE WITH THE POLICY PROVISIONS. THIS IS TO CERTIFY THAT THE POLICIES OF INSURANCE LISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR THE POLICY PERIOD INDICATED. NOTWITHSTANDING ANY REQUIREMENT, TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPECT TO WHICH THIS CERTIFICATE MAY BE ISSUED OR MAY PERTAIN, THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED HEREIN IS SUBJECT TO ALL THE TERMS, EXCLUSIONS AND CONDITIONS OF SUCH POLICIES. LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS. THIS CERTIFICATE IS ISSUED AS A MATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER. THIS CERTIFICATE DOES NOT AFFIRMATIVELY OR NEGATIVELY AMEND, EXTEND OR ALTER THE COVERAGE AFFORDED BY THE POLICIES BELOW. THIS CERTIFICATE OF INSURANCE DOES NOT CONSTITUTE A CONTRACT BETWEEN THE ISSUING INSURER(S), AUTHORIZED REPRESENTATIVE OR PRODUCER, AND THE CERTIFICATE HOLDER. IMPORTANT: If the certificate holder is an ADDITIONAL INSURED, the policy(ies) must have ADDITIONAL INSURED provisions or be endorsed. If SUBROGATION IS WAIVED, subject to the terms and conditions of the policy, certain policies may require an endorsement. A statement on this certificate does not confer rights to the certificate holder in lieu of such endorsement(s). COVERAGES CERTIFICATE NUMBER:REVISION NUMBER: CERTIFICATE HOLDER CANCELLATION © 1988-2015 ACORD CORPORATION. All rights reserved.ACORD 25 (2016/03) CERTIFICATE OF LIABILITY INSURANCE DATE (MM/DD/YYYY) $ $ $ $ $ The ACORD name and logo are registered marks of ACORD 10/31/2023 (805) 523-8600 (805) 523-8611 085202 Collaborative, Technical & Comprehensive, Security Business Consulting, LLC 113 South U St. #46 Lompoc, CA 93436 A 1,000,000 X PSL0339598441 1/25/2023 1/25/2024 100,000 5,000 1,000,000 2,000,000 2,000,000 1,000,000A X PSL0339598441 1/25/2023 1/25/2024 A Professional Liab. PSL0339598441 1/25/2023 Each Claim/Aggregate 1,000,000 General Liability The entity or entities listed in this section is/are hereby named as Additional Insured(s) if required in a written contract or written agreement with the Named Insured. Primary and Non-Contributory provisions apply to the entity or entities listed in this section if required in a written contract or written agreement with the Insured. Waiver of Subrogation is in favor of the entity or entities listed in this section if required in a written contract or written agreement with the Named Insured. Auto Liability SEE ATTACHED ACORD 101 Orange County 300 West Tryon Street P.O. Box 8181 Hillsborough, NC 27278 COLLTEC-01 PGARCIA Fiscus Commercial Insurance Services, Inc. 1164 Road Runner Way Simi Valley, CA 93065 certs@fcisonline.com Lloyds of London 1/25/2024 X X X X X DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB FORM NUMBER: EFFECTIVE DATE: The ACORD name and logo are registered marks of ACORD ADDITIONAL REMARKS ADDITIONAL REMARKS SCHEDULE FORM TITLE: Page of THIS ADDITIONAL REMARKS FORM IS A SCHEDULE TO ACORD FORM, ACORD 101 (2008/01) AGENCY CUSTOMER ID: LOC #: AGENCY NAMED INSURED POLICY NUMBER CARRIER NAIC CODE © 2008 ACORD CORPORATION. All rights reserved. Fiscus Commercial Insurance Services, Inc. COLLTEC-01 SEE PAGE 1 1 SEE PAGE 1 ACORD 25 Certificate of Liability Insurance 1 SEE P 1 Collaborative, Technical & Comprehensive, Security Business Consulting, LLC 113 South U St. #46 Lompoc, CA 93436 SEE PAGE 1 PGARCIA 1 Description of Operations/Locations/Vehicles: The entity or entities listed in this section is/are hereby named as Additional Insured(s) if required in a written contract or written agreement with the Named Insured. Primary and Non-Contributory provisions apply to the entity or entities listed in this section if required in a written contract or written agreement with the Named Insured. Waiver of Subrogation is in favor of the entity or entities listed in this section if required in a written contract or written agreement with the Named Insured. ENTITY: Orange County DocuSign Envelope ID: CCAAE303-70FA-49DE-B23A-944301EA0EEB