Attachment D - IT Master Plan 2020.pdf
PDF 3 MB Posted
- Attached to
- Professional, Administrative, Computational, and Engineering Services contract (PACE V) Federal contract opportunity
- Solicitation number
- 80GRC020R0010
About this file
This document provides information on a forthcoming solicitation for Professional, Administrative, Computational, and Engineering Services (PACE V) from the National Aeronautics and Space Administration Glenn Research Center (NASA GRC). The PACE V contract will continue providing IT solutions and services to NASA GRC customers, anticipating changes in requirements and ensuring alignment with agency missions. A Request for Information was previously released under solicitation 80GRC019R0022.
The new solicitation 80GRC020R0010 will be issued as a total small business set-aside, with a North American Industry Classification System code of 541519 and $30 million small business size standard. The base period is 22 months with options to extend up to 60 months total. A draft RFP will be available on February 7, 2020 on SAM.gov, with the final RFP issued around March 13, 2020. An Industry Day will take place on February 25, 2020 at NASA GRC to discuss the draft RFP. One-on-one meetings will also be available after the Industry Day. Interested parties should register on the provided website and monitor SAM.gov for solicitation documents and amendments.
View the file
Other files for this federal contract opportunity
Show all 23
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
NASA – Glenn Research Center: Office of the Chief Information Officer
IT Master Plan 2020 October 2019
Contents
Introduction
Purpose
NASA Glenn’s Information Consumers and Stakeholders
IT Strategic Planning Process
Guiding Objectives
NASA Glenn’s IT Environment
Applications Planning
Communications Planning
Computing Planning
CyberSecurity Planning
End-User Planning
Information Management Planning
IT Management and Governance Planning
Appendix A1: Applications Program Roadmap
Appendix A2: Applications Program Target State
Appendix B1: Communications Program Roadmap
Appendix B2: Communications Program Target State
Appendix C1: Computing Program Roadmap
Appendix C2: Computing Program Target State
Appendix D1: CyberSecurity Program Roadmap
Appendix D2: CyberSecurity Program Target State
Appendix E1: End-User Program Roadmap
Appendix E2: End-User Program Target State
Appendix F1: Information Management Program Roadmap
Appendix F2: Information Management Program Target State
Appendix G1: IT Management and Governance Program Roadmap
Appendix G2: IT Management and Governance Program Target State
Introduction
Technology is evolving at unprecedented rates and creating countless opportunities to improve mission productivity, data insights, and business intelligence. Technological advances across industry including mobile computing, process automation, software defined networking, data analytics, machine learning, artificial intelligence, and more lead to new opportunities to advance NASA Glenn Research Center’s programs and projects. Complementing those technological advances, new and innovative service delivery and acquisition practices including shared services and cloud computing promise to create efficiencies and open new opportunities to shift personnel and financial resources towards strategic investments.
These opportunities are balanced by a series of risks facing NASA Glenn Research Center (GRC).
Legacy IT systems and infrastructure are costly to maintain, even more costly to replace, and create unnecessary operational and security risks. Cybersecurity threats are multiplying rapidly, anchored by a legacy environment unprotected from modern threats while a proliferation of connected devices and cloud services open up new and still uncovered avenues for malicious actors. Information management is accelerating towards critical importance as NASA strives to maximize the benefits of the data it produces. Throughout all of this change, NASA GRC’s IT Workforce is challenged to transition from traditional “service delivery” functions to new “service broker” roles while staying current with technology trends in order to both manage service providers and effectively consult with the Center’s researchers and engineers for tailored technology solutions.
NASA’s Mission Support Future Architecture Program (MAP) is transforming the way the Agency does business. Our implementation of this transformation is helping us to identify opportunities for efficiencies, to facilitate collaboration, and to minimize redundancies, while enabling our implementation of the Federal Information Technology Acquisition Reform Act (FITARA).
The OCIO will manage IT at NASA GRC as a strategic resource in order to enable the use of data to drive advances in space missions and aeronautics in support of NASA GRC’s research and engineering efforts.
The OCIO will implement solutions and provide oversight of NASA GRC's IT strategic resources in order to enable the production, use, security, and management of data to support these strategic advances.
Purpose
This plan guides the local investment, implementation, acquisition, and governance of Information
Technology to best enable NASA Glenn’s mission and mission support functions in alignment with the
Agency IT Strategic Plan and the Center’s strategic priorities.
Agency IT Strategic Plan GRC Strategic Plan
Excellence: Partner with customers to consistently deliver excellence and enable mission success
Data: Capitalize on data management, access, and innovation
Cybersecurity: Safeguard
NASA’s data and IT assets
Value: Maximize business value by optimizing IT
People: Care for our people today and prepare them for tomorrow
Provide world-class research & technology, revolutionizing aeronautics & space exploration
Advance space missions and aeronautics by leveraging our core competencies to deliver from concept through applications
Deliver program and project management excellence that results in safe and successful missions for our customers and challenging, long-term assignments for the Center
Provide excellent institutional capability to enable NASA mission success
Be an integral part of the Ohio community and the Nation
This plan integrates that strategic guidance to best address Center out-year requirements for fiscal years
2020 through 2024 and provides input to the FY22 Center and Agency Information Technology Capital
Investment Review (ITCIR) and the FY22 Planning, Programing, Budgeting, and Execution (PPBE) processes. This IT Master Plan also provides the guidance, principles, and prioritization to be utilized in annual project planning and resource prioritization by the OCIO and the Center’s IT governance bodies.
This plan is to be reviewed and approved annually by the Center’s IT Advisory Board and, when needed, updated by the Office of the CIO.
NASA Glenn’s Information Consumers and Stakeholders
NASA GRC workforce is comprised of more than 3,000 civil servants and contractors serving in a wide variety of mission and mission support roles. NASA GRC is an active participant in missions across each of the Agency’s Mission Directorates. The Center’s unique, world-class test facilities at Lewis
Field and Plum Brook Station are strategic national assets and integral in NASA’s missions. The Center pairs its workforce and unique test facilities in six core competencies aligned to best address the Agency and Nation’s needs.
The Center’s stakeholders and information consumers depend on responsive, reliable, and innovative
Information Technology.
IT Strategic Planning Process
This IT Master Plan is an integral element of the Center’s strategic planning process for IT. Led by the
OCIO the process is inclusive of all organizations across the Center and relies heavily on the IT
Advisory Board; the Center’s strategic governance body for IT. The strategic planning process is outlined in the image below and relies on this IT Master Plan as the foundation for the annual investment review process and fiscal year planning and prioritization.
Air-Breathing Propulsion Research
& Development
Communications Technology & Development
In-Space Propulsion and Cryogenic Fluids
Management
Power, Energy Storage, and Conversion
Materials & Structures for
Extreme Environments
Physical Sciences and Biomedical
Technologies in Space
IT Master Plan
IT Service Roadmaps
Industry Trends
Alignment to Center Requirements (Competencies, Facilities, Workforce)
IT Capital Investment Review (ITCIR)
5-year spend projections
Strategic Investments
Portfolio Analysis
DME vs. Steady State
Issue Papers
Fiscal Year Plan and Priorities
Center & Agency Priorities/Initiatives
CMO Requirements
Project Prioritization
In-Guide/Over-Guide Determinations
MSC Bill Determination
Budget Year Execution
MSC Monitoring
Contract Monitoring
Budget Guidelines
Project Execution
Performance Monitoring
Service Delivery
Guiding Objectives
The Agency’s IT Strategic Plan identifies several mission oriented strategic outcomes that serve as guiding principles for decisions the Center makes on its IT investments, projects, and policies.
NASA Glenn’s IT Environment
Supporting GRC’s missions, the Center has a large and diverse portfolio of IT services and projects.
The Center’s organizations annually spend an estimated $60M-$65M (including Civil Servant Labor) on a mix of IT products and services. ~60% of the total IT is procured and delivered by the Center and
Agency OCIO organizations. The remaining 40% (~$40M) is procured and implemented by other organizations across the Center. These services are a mix of Enterprise Services, Center Standard
Services, and Center Unique Services.
Enterprise Services are acquired through the Agency
OCIO’s enterprise programs and federal shared service providers. GRC’s OCIO brokers those services ensuring the Center’s requirements are met by the enterprise services and projects are successfully communicated and implemented.
Center Standard Services are primarily delivered by the
Center OCIO (with some exceptions) and are comprised of systems and services utilized by large portions of the Center’s workforce and programs.
GRC’s OCIO delivers these services and in those cases, it is responsible for the successful oversight and governance.
Center Unique Services are those consumed by small populations and individual projects at the Center. Often associated with mission-specific IT, these services are most often procured, implemented, and delivered by organizations outside of the OCIO. The GRC OCIO provides oversight and governance of the acquisition and delivery of Center
Unique Services.
To effectively manage this diverse environment, the IT portfolio is organized into 7 IT Programs, 45
Capabilities, and 188 Services.
This IT Master Plan outlines strategic investments, divestments and practices that enable the Center to balance efficiency and effectiveness for the capabilities and services within each of these programs.
Optimizing the mix of enterprise, center standard, and center unique services will ensure the Center’s programs and projects are positioned with agile and responsive IT services to best meet the Center’s needs.
Applications Communications Information Management
CyberSecurity End-UserComputing IT Management and Governance
Applications Planning
The IT Applications Program addresses NASA’s 21st Century Information Technology Web
Services demands. The Program provides support for the design, development, implementation and maintenance of applications, databases, and web services, and delivers solutions according to customer demand and industry best practices.
Current Situation
NASA Glenn’s current Applications Program is comprised of hundreds of websites, business applications, and software applications in direct support of the Center’s mission and mission support functions. Comprised of 5 capabilities and 28 services, the Center spends upwards of $19M annually on this portfolio of solutions. While the bulk of the annual investment is in software licenses, the Center spends approximately $1.5M annually in sustaining basic web and business application services for the
Center.
Recent years have seen a reduction in platforms for web sites and business applications, but the Center retains a legacy application platform hindering access to new and evolving requirements and technologies. Opportunities face the Center in the areas of process automation, mobile applications, business intelligence, artificial intelligence, cloud computing, and the management of the increasing use of software applications. Cybersecurity will remain a focus as the Center and Agency look to ensure the confidentiality, integrity, and availability of NASA’s data for internal and external applications and data.
Drivers
Drivers for change within the Applications Program come from a mix of mission-enabling, cybersecurity, and compliance sources
Share Information about GRC, its missions, activities, and competencies
Ability to Locate information
Out Dated web information
Aging Infrastructures and Technologies
Compliance with Federal web standards and guidelines
Compliance secure web sites via HTTPS/SSL configurations
Strong authentication on GRC websites and applications
Strategic Priorities
To best meet these needs, the Glenn Research Center will undertake the following investment and divestments. Detailed roadmaps and plans stemming from the drivers and priorities for the Applications
Program are provided in Appendices A1 and A2.
Funded Unfunded Unfunded Mandate/Obsolescence
Drivers Investment/Divestment 2020 2021 2022 2023 2024
Reliance on email or paper based processes, approvals, or action tracking reduces process visibility, tracking, and efficiency.
Invest: Implement a service and capability to automate business processes, approval workflows, action/issue tracking.
Divest: Reduce custom-developed process automation solutions, email or paper-based processes
The continued availability of a suite of up to date applications needed by the
S&E community and increase cost efficiencies through enterprise licensing.
Invest: Operate and maintain the suites of S&E applications for researchers and engineers (i.e., CREO, Solidworks, AutoCad, MagicDraw, etc.), and migrate from Center to Agency software licensing model and reporting dashboard.
Establish standards for increased visibility for application costs, standardize platform technologies, more responsive end user configurable platforms, Invest: Rationalize application inventory to find high-value ROI opportunities to move to enterprise solutions. Standardize platforms, frameworks, and programming languages. Inventory dependencies on non-NASA systems.
portfolio management to increase delivery of services against requirements.
Divest: Decommission numerous redundant applications, applications development efforts, and obsolete programming languages.
HSPD-12 M-11-11 and related mandates such as evolving to User Based
Authentication and eliminating passwords.
OMB BOD 18-01 & IT
Security requirements call for augmenting the IPv4 addressing and the removal of non-secure HTTP.
Invest: Track and migrate remaining
GRC applications to Launchpad
(eAuthentication). Track, Guide, and
Transition all web sites and web applications to HTTPS security and IPv6 network compliance.
Divest: Decommission and/or transition, as many as possible, non-compatible eAuth applications. Decommission IPv4 networking and HTTP.
Web-based code repositories with automated reviews are becoming the industry standard due to efficiency and, programming error reduction, and cost reduction.
Invest: Improve the DevOps model for delivering applications. Improve the code repository capabilities (GitLab) while exploring/implementing an industry supported standard code repository for GRC, which will provide automated code reviews for developed websites and web apps.
Divest: Reduce need for individual non-standard code repositories and reduce duplicative and repeated programming of common application modules.
Increased management and security of website administration resources and cost reduction.
Invest: Review internal websites to determine which ones should be targeted for migration to the Central infrastructure for better management and security of resources; migrate or eliminate 10% of the internal websites per year.
Divest: Centralize and decommission numerous and redundant website infrastructures.
Increased management and security of website administration resources and cost reduction.
Removal of unnecessary and outdated web content causing communication of misinformation.
Invest: Consolidate public-facing websites into a central environment to provide a consistent user experience.
Update content to reflect the mission of
Glenn Research Center to align with
Center and Agency priorities.
Divest: Update, centralize and decommission numerous outdated and redundant website infrastructures.
There is a business need to be able to analyze data and represent it in ways to make business decisions.
Organizations use various methods to meet this need
(Excel, databases, etc.)
Web-based tools that automate the function and enable the sharing of the data, capabilities and results would facilitate better decisions.
Invest: Continue to use, operate, and maintain the business intelligence applications (Tableau, Power BI, SharePoint, etc.), while assessing the portfolio for possible optimization to approved Agency solutions and implementations.
Divest: Reduction of siloes of information and knowledge.
Tools to deliver embedded software continues to evolve, enhancing the current capabilities and easing/automating the development of software.
Invest: Create a GRC embedded software library and development support/tutorial web site to enable researchers to efficiently begin their embedded software development efforts.
Communications Planning
The Communications Program ensures any person participating in fulfilling NASA’s mission will have the ability to communicate securely anywhere, at any time, utilizing communication technology that is reliable, available, responsive and robust. The communications infrastructure uses a combination of commercial and private entities to enable the delivery of data, voice and video services.
NASA Glenn’s current Communications Program provides a diversity of critical center functions ranging from local area networks to thousands of employees and facilities to end user communication devices and software fostering a collaborative and dynamic work environment. Comprised of 6 capabilities and 32 services, the Center spends upwards of $10M annually on this portfolio of solutions.
These investments comprise a broad mix of enterprise provided functions as well as Center unique communications services for the unique missions, facilities, and labs at Lewis Field and Plum Brook
Station.
The majority of the Center’s $10M annual investment in the Communications Program provides sustainment operations and maintenance for services and infrastructure that have been in place for decades. NASA GRC’s existing communications infrastructure represents a total capital value of greater than $75M, elements of which require replacement at time intervals ranging as short as 5 years to as long as 25 years. Certain elements of the Center’s Communications Program are as old as 40 years leading to substantial risk to performance, availability, and security. Recent years have seen a concerted focus on lifecycle obsolescence planning, however budget planning is not commensurate with the financial burdens and alternative. Creative options will need to be evaluated. Opportunities face the
Center in the areas of increased bandwidth and performance, transactional on-demand contract options for tenants and external partners, and improved visibility into performance and cybersecurity of the networks. Cybersecurity will remain a focus as the Center and Agency look to ensure the confidentiality, integrity, and availability of NASA’s data for internal and external applications and data.
Drivers for change within the Communications Program come from a mix of mission-enabling, Continuity of Operations
Obsolete Video Distribution
Networking to meet Mission requirements
Unified Communications
High-Speed Wireless
IPv6 Mandate
Cable Plant Obsolescence
GRC Facilities Master Plan divestments. Detailed roadmaps and plans stemming from the drivers and priorities for the
Communications Program are provided in Appendices B1 and B2.
Funded Unfunded Unfunded Mandate/Obsolescence
Drivers Investment/Divestment 2020 2021 2022 2023 2024
GRC’s communications services, technologies, and infrastructures need to be updated in order to keep pace with trends and developments in industry standards and best practices.
Invest: Plan and implement replacement of the GRC central 2-way trunked radio system.
Divest: Possible leasing option could divest from on premise centralized radio infrastructure.
GRC’s communications services, technologies, and
Invest: Next Gen GTV Project combines and modernizes desktop TV and CATV infrastructures need to be updated in order to keep pace with trends and developments in industry standards and best practices. The NTSC analog video standard has been obsolete since ATSC digital television took off in the 2000’s.
distributions into a single, supportable, streaming-based format for TVs and desktops across PBS and LF.
Divest: Divest from legacy coax video infrastructure.
infrastructures need to be updated in order to keep pace with trends in industry standards and best practices. Paging system components in GRC Test
Facilities are as old as 40+ years in some cases and are at risk of failure.
Additionally, the digital telephones and cabling in
GRC's 8x6/9x15, 10x10, and PSL facilities rely on outdated technology that should be explored for replacement.
Invest: Modernize and Secure Paging and Intercom Systems throughout secure test facilities at GRC to met safety and mission assurance requirement and ensure mission success. Modernize cabling and phone instrumentation in
GRC Test Facilities that is aligned with facility security and safety and mission assurance requirements.
Divest: Decommission legacy cabling and paging systems. Divest from high risk service.
GRC's cable plant needs to be updated to the current
CAT 6/6A standard in order to accommodate current and future data rates for the wired and wireless network. As is, networks may not perform adequately on the aged infrastructure, and could result in phantom errors, lost packets, and reduced performance over time.
Invest: Replace current legacy institutional building cabling with modern CAT 6/CAT 6A cabling.
Evaluate opportunities for technology advancements, including fiber replacing copper and increased usage of wireless.
Divest: Decommission current CAT 5 legacy cabling.
GRC communications services need to adapt to meet “Internet-of-Things” requirements which are becoming more prevalent in today’s IT landscape.
Invest: Document requirements for an
Internet-of-Things wired/wireless network for monitoring of Emergency
Lights, Fire Extinguishers; and explore improved integration between PBS and
LF for industrial control and institutional monitoring systems.
Divest: Decommission use of non-institutional network.
Enable NASA’s mission while protecting our people, systems, and data through an improved
Cybersecurity posture and deliberate authorized access.
Invest: Implement Network Access
Control per direction from the Agency’s
NASA Strategy to Improve Network
Security initiative.
Invest: Divestment from Manual DHCP and Network Access Approval Processes.
services, technologies, and infrastructures need to be updated in order to keep pace with trends and developments in industry standards and best practices.
Invest: Refresh obsolete conference and
ViTS rooms in accordance with the
OCIO annual conference room obsolescence and center advocacy process.
Divest: Explore consolidation of conference room requirements during obsolescence cycle where possible.
GRC’s fiber infrastructures at PBS and LF provide service to the test facility data network, telecommunications, life safety and security systems, Energy Management and
Control System (EMCS) and electrical metering.
The current system is undersized, unreliable, and subject to single point failure.
Invest: FHCI Projects at Lewis Field and
Plum Brook station will design and deploy the next generation of institutional fiber infrastructure for
GRC’s various network infrastructures, which is a critical enabler for network electronics operated by a multitude of organizations and functions at Glenn
Research Center.
Divest: Legacy fiber plants runs by distinct organizations (FTK, C, FD, V, etc.) will be consolidated under a common outside building cable system.
Addresses gaps in Agency and Center target architectures for communications services.
Currently the GRC network is unable to guarantee the target SLA of 99.99% availability due to single points of failure in the network core infrastructure, and single system failure could result in a quarter of the lab losing connectivity for up to 4 hours.
Invest: Plan and execute “Phase 2” of
Network Core Risk Reduction, which will improve network reliability by eliminating single points of failure in the
GRC network, and align the GRC network topology to the agency and GRC target architectures.
Divest: Improving reliability and eliminating single points of failure in the
GRC LAN will enable consolidation and divestment of SCADA and specialized networks.
Computing Planning
The Computing Program provides excellence in centralized on-demand compute, application, and storage services with efficiency, flexibility, elasticity, and high functionality to meet immediate mission demands. Provided are the hardware, software, and expertise to enable greater use of computational and visualization technologies to take advantage of the bandwidth of the human visual system.
Computing services provide GRC’s tenant programs, researchers, and business units with the storage, processing, and computing facility resources needed to execute advanced technology research and mission critical programs. Comprised of 6 capabilities and 17 services, the Center spends upwards of
$5M annually on this portfolio of solutions. Organized by IT Facilities Management, Infrastructure as a
Service, Platform as a Service, Storage, and High Performance Computing, these services provide the foundational computing infrastructure for applications and services.
As program and project demand continues to increase for computational, computing, storage, and application services, NASA GRC must move to more efficiently and effectively manage data center and compute assets through a mix of modernization activities, funding/business model improvements, and a strategic shift to enterprise and cloud resources where appropriate.
Drivers for change within the Computing Program come from a mix of mission-enabling, cybersecurity, and compliance sources
GRC Mission Requirements
Cost Elastic Cloud Services; Only Pay for What is Required and Used
Technology Evolution across Industry
Obsolescence management
Efficiencies
Agency Strategy Alignment
Compliance
Security divestments. Detailed roadmaps and plans stemming from the drivers and priorities for the Computing
Program are provided in Appendices C1 and C2.
Funded Unfunded Unfunded Mandate/Obsolescence
Drivers Investment/Divestment 2020 2021 2022 2023 2024
Update existing projects dedicated HPC service architecture to a transactional model to gain efficiency and reduce overall provisioning cost.
Invest: Implement and provision shared
HPC services based on assessments including funding model and infrastructure changes, which may involve consolidation (when appropriate) of on-site High-Performance Computing to either central services and AMES offered NAS or cloud services.
Divest: Migrate and decommission appropriate locally provisioned HPC to centralized and/or Cloud model.
Implement a variety of demand based storage options that include various service levels.
Invest: Develop and Implement a centralized storage environment to keep up with the increasing storage growth that potentially supports an elastic business model (i.e., subscription based, brokered pay for what you use Cloud mode).
Divest: Migrate appropriate distributed storage to central model.
Enable new capabilities within the test facilities by migrating away from the decades old systems in place. ESCORT end of life is April 2023.
Invest: Replace all ESCORT Systems with COBRA and update obsolete data acquisition components.
Divest: Sunset the old ESCORT data systems.
Migrate to a more modern implementation of a centrally managed system for maintaining industrial controls.
Invest: Modernize small test facility processors and software, and replace
CPS and PCLs for GRC’s industrial process and institutional control systems.
Data Center Optimization
Initiative (DCOI) established in OMB M-16-
19 directs to transition to more efficient, optimized, and centrally provided services.
Invest: Collaborate with system owners of non-tiered data center (servers) to perform requirements analysis to determine housing/hosting requirements of services provided, and implement findings to prioritize cloud alternatives to optimize services and reducing overall cost while improving performance.
Divest: By exception only, servers that are required to be co-located will be waivered with full knowledge from the hosting organization, OCIO and agency program office.
In order to keep the Data
Center current, a cascading technology refresh cycle is required to maintain overall modern capabilities and spread costs.
Invest: Annual cyclical technology refresh of central Data Center servers and storage in order to maintain currency.
Divest: Decommission aging Data
Center technology; 5-year refresh cycle.
Cloud based services may result in a decrease in on premise need for hardware.
Data Centers are required to maintain and enhance both logical and physical measures to increase security.
Invest: Develop and implement a near
Tier II Data Center with included physical security for a smaller room and significantly less personnel having access.
Divest: Cloud based services may result in a decrease in on premise need for hardware, lessening the need for full Tier
2 services.
Limited localized high-speed storage is limiting research testing capabilities and GRC’s ability to advance research.
Invest: Restructure Local Temporary storage for data acquisition, internal to test facilities, at the 100 – 200 TB capacity level.
Modernize video data acquisition technologies and increase processing efficiencies at PSL to advance aeronautics research capabilities.
Invest: Investigate, Procure and
Develop new Video System to employ video ingestion systems for PSL.
CyberSecurity Planning
The CyberSecurity Program provides consistent, responsive, cost-effective, and risk-based information security that ensures confidentiality, integrity, and availability of data and information.
NASA and NASA Glenn’s programs and workforce are increasingly reliant on IT systems. This expanding consumption, along with the proliferation of connected devices, cloud computing services, and increasing complexity of IT solutions is broadening the cybersecurity risk posture for the Center and
Agency. Comprised of 5 capabilities and 34 services, the Center spends upwards of $8M annually on this portfolio of solutions. NASA Glenn’s CyberSecurity program includes Security Solutions
Consulting, Program Assessment and Audits, Common Security Controls, and Awareness Education for
NASA’s workforce.
As the internal and external cyber threats evolve, the Center is seeing its core competencies
(engineering, communications, materials) and facilities being increasingly exposed to loss of information confidentiality, integrity, and availability, which is acutely problematic to the Space and
Aero missions. The OCIO and Center must adapt, equip the workforce with new skills, and reprioritize constrained resources to more proactive support of mission programs. The Center will do this by shifting security operations to Agency and Federal common controls where possible and centralizing applications and data to accredited and authorized Center, Agency, and Cloud systems when available.
These efforts will free up traditional security operations staff and audit/assessment staff to realign towards cyber mission assurance priorities. In addition to these shifts, the Center will capitalize on reach-back to previously untapped Agency resources (penetration testing), IV&V (red team testing), and external partnerships (AFRL, NASIC, DHS, and others) to overcome these resource constraints.
Drivers for change within the CyberSecurity Program come from a mix of mission-enabling, Mission Requirements - Center demand for cybersecurity engineering/solutions including:
Mission IT & Communications Design, requests for mission (including ICS) and/or procurement related Accreditation & Authorization, IT Forensics & Investigative support for FBI, CI, OIG, General Council, OPS and HR investigations, and assisting with restoration and recovery of mission IT back to service after IT failures.
Technology & Threat Evolution - Technology evolution across all IT realms and an ever-increasing vulnerability/threat space continue to push the need for continuous security assessment, analysis, engineering, controls, policies and authorizations. Examples include:
Distributed Denial of Service for hire, increased nation states hacking, Advanced Persistent
Threat, Increased prevalence and sophistication of malware such as ransomware and Wannacry, containerization, cloud computing, software defined networking, Internet of Things, Operational
Technology, and Mobile devices.
Compliance - Increased Federal, Agency and Center requirements such as FITARA, Privacy Act, and 2017 Executive Order 138000 – Strengthening the cybersecurity of Federal networks and
Critical Infrastructure.
divestments. Detailed roadmaps and plans stemming from the drivers and priorities for the
CyberSecurity Program are provided in Appendices D1 and D2.
Increased Federal, Agency and Center requirements such as FITARA, Privacy
Act, and 2017 Executive
Order 138000 –
Strengthening the
Invest: Gradually achieve 100% of existing mission systems submit authorization documentation in RISCS, have their security plans annually reviewed, have 50% engage IT security during pre-planning phase, and educate 4
Cybersecurity of Federal networks and Critical
Infrastructure.
Mission Directorate leadership bodies on
Cybersecurity professional services available and the benefit to the mission.
Identify and safeguard instances of GRC PII and
SBU data to prevent unauthorized data disclosure per Federal and
Agency sensitive data protection requirements.
Invest: Assess and identify tools that find sensitive data and utilize them on servers and all endpoints to assist system owners to identify and classify data.
Increased Federal, Agency and Center requirements such as FITARA, Privacy
Act, and 2017 Executive
Order 138000 –
Strengthening the
Cybersecurity of Federal networks and Critical
Infrastructure.
Invest: Implement GRC Data Center application level security plan, identify
GRC Industrial Control systems, and a process for Assessment and
Authorization.
Divest: Transition these categories of systems to standardized process.
such as FITARA, Privacy
Act, and 2017 Executive
Order 138000 –
Strengthening the
Cybersecurity of Federal networks and Critical
Infrastructure.
Invest: Identify, develop, and implement application whitelisting for Operational
Technology (OT) offline systems.
Agency applications evolving use of Cloud technologies require a modification in policy and guidance and additional tools to manage Cloud based applications.
Invest: Develop local policies for cloud use based on Agency cloud office security guidance. Implement tools to monitor and manage applications that have migrated to the cloud.
Divest: Transition away from local hardware and software acquisition and license management.
Agency based requirements for licensing and centralized logging are driving the local centers to consolidate their local log management solutions.
Invest: Implementation/Utilization
Agency centralized logging management environment and provide guidance for installation and usage.
Divest: Decommission, where appropriate, local Splunk log capture and analysis.
such as FITARA, Privacy
Act, and 2017 Executive
Order 138000 –
Strengthening the
Invest: Implement continuous monitoring across 100% of NASA’s environment (except waivered assets) to enable on-going discovery of cybersecurity vulnerabilities to assess
Cybersecurity of Federal networks and Critical
Infrastructure.
and prioritize Agency risk to mission and business assets.
Increased Federal, Agency and Center requirements such as FITARA, Privacy
Act, and 2017 Executive
Order 138000 –
Strengthening the
Cybersecurity of Federal networks and Critical
Infrastructure.
Invest: Investigate, procure, and implement Security Log Management and Intrusion Detection Tools for air-gapped Operational Technology systems.
Technology advancements in hardware and software tools allow increased speed in closure of incident response cases and the quality of analysis.
Invest: Investigate tools to increase
GRC’s ability to respond to and analyze incidents. Modernize the incident response lab with modern and higher capacity technology.
Divest: Decommission current technology in incident response lab.
End-User Planning
The End-User Program provides the administration and management of all desktop/laptop computers, mobile devices, print, and collaboration services provided to employees. It ensures all are configured to federal standards. This includes desktop security tools for these systems as well as the email and Active Directory infrastructure for the agency. The Program also provides the customer interface and support for IT services through Enterprise Service Desk.
The End-User Program is the most readily apparent and pervasive interaction between NASA’s IT services and the GRC workforce. Comprised of 7 capabilities and 29 services, the Center spends upwards of $12M annually on this portfolio of solutions. The End-User Program significantly defines how people get their work done and is a main indicator of how people want to conduct their work. This area is the day-to-day touch point into users interacting with their primary business functions.
Comprised of the devices and software services required for end user computing (workstations, tablets, smartphones, associated software, and support services), NASA GRC consumes ~90% of its end user computing devices from the Agency’s enterprise contract.
Due to the extraordinary reliance on End-User Program services, degradations in service and gaps in requirements fulfillment have a direct and immediate impact on the Center’s missions and institutions.
The OCIO must prioritize a focus on the end user experience to improve alignment of services to requirements and increase workforce productivity and efficiency.
Drivers for change within the End-User Program come from a mix of mission-enabling, cybersecurity, and compliance sources
GRC Mission Requirements
Accelerated technology lifecycles
Strategic Sourcing
Office 365
Software subscriptions
Mobile Platforms
Collaboration Environment Life-Cycle Management
Mobile technologies divestments. Detailed roadmaps and plans stemming from the drivers and priorities for the End-User
Program are provided in Appendices E1 and E2.
Antiquated pager technology limits critical and emergency communication information to critical personnel assigned to quickly respond to incidents. There is a small user community of these one way communication devices. How much supply will be needed in the future is TBD.
Invest: Investigate secure replacements for pagers due to possible upcoming end-of-life.
Divest: Decommission antiquated pager technology.
The Agency has issued guidance to the Centers to leverage enterprise IT contracts (ex., NEST) to the extent possible for end-user systems and to
Invest: Improve processes to decrease the time for new NASA personnel to receive IT services (provided by the End-
User Service Office) by 10% after a request is initiated.
increase services and reduce IT security risks.
GFE workstations typically support mission related work. Comprehensively addressing obsolete GFE workstations better supports the mission of
GRC.
Invest: Develop plan and conduct research to assess and address obsolescence of GFE workstations and integrate it with the Agency GFE hardware waiver process.
Divest: Decommission and refresh antiquated mission related workstations
GRC has additional EUS support through funded on-site technicians. This team provides hands on support above and beyond the basic help/support model.
Consolidation and advanced technologies can increase efficiencies and reduce costs.
Invest: Develop and provide advanced and comprehensive multi-tiered system administration service for non-NEST computers.
Divest: Appropriate consolidation of distributed system administration.
eRoom environment approaching end-of-life and newer document collaboration services offering increased storage and better features.
Agency solutions will reduce costs and may even be an entitlement.
Invest:
• Research, advocate, and implement an Agency document collaboration solution that allows for external users to collaborate on SBU content.
• Develop plan and conduct research to assess GRC's
Collaboration requirements, current tool landscape, and current/upcoming Agency tools in order to modernize the GRC
Collaboration environment.
• Advocate for positioning of Box as the Agency’s external FSS collaboration tool, with an entitlement funding model, and roll out and support Box external
Moderate FSS collaboration tool.
Divest:
• Decommission eRoom.
• Transition unauthorized file synchronization and sharing services to a sanctioned Agency
FSS service
The ability to consistently provide needed SW loads as demanded to systems throughout the Enterprise will provide cost reduction
Invest: Provide enterprise standard software loads to managed seats.
and better service for all users.
Identity information in central directories enables better communication and enhances safety.
Invest: Continue support for local updates in the Global Address List and
NASA Enterprise Directory (NED) for locally managed identity information such as office building and room number.
Information Management Planning
The Information Management Program furthers the development and application of an
Information Architecture that improves the quality and accessibility of data, as well as incorporates the data lifecycle throughout the information creation, usage, and decommissioning process.
The Information Management Program is a relatively new program and in the process of being formulized across the Agency. Likewise, GRC is in the process of program formulization, and establishing dedicated program leadership. Comprised of 6 capabilities and 14 services, the Center spends upwards of $1.5M annually on this portfolio of solutions. Elements of the program include
Records Management, STI, Publishing, Data Management, and Advanced Analytics and Visualization.
Many of these services are delivered and executed out of multiple GRC Directorates – primarily the
Center Operations Directorate and the OCIO.
The need to expand the Center’s paper records storage solutions to capture and make accessible digital records and satisfy federal electronic requirements are imperatives driving the need for local formulation of the Information Management Program. The exponential increases in electronic data accumulated by the Center present opportunities to improve efficiencies and productivity from Data Life-Cycle
Management. The accumulation of this data also introduces the strategic value of Big Data Mining, Advanced Analytics, and improved Center-wide project management. Through FY20, the Center will be challenged to formulate and outline the long-term plans for this Information Management Program.
Drivers for change within the Information Management Program come from a mix of mission-enabling, Compliance for Records Management
Data Management to prevent data loss and expensive re-work
Information and Knowledge Management to address workforce turnover
Data Analysis to extract information in a timely manner
Rapidly increasing interest in visualization for data exploration and explanation divestments. Detailed roadmaps and plans stemming from the drivers and priorities for the Information
Management Program are provided in Appendices F1 and F2.
Data Science technologies essential to creating value from modern datasets.
Current data management
& analytics tools incapable to keeping up with volume and velocity of data. Not getting value from the data generated from expensive tests and simulations.
Invest: Establish centralized data science team to coordinate data science activities at the Center, provide on-demand expertise and projects. Create a data science lab space for access to expertise and tools.
Data management at the
Center is a distributed collection of varying methods and tools. There needs to be greater oversight on data collection, management, and discovery.
Invest: Initiate a data governance framework which includes a governance council and steering committee to develop data policies and standard for the
Center.
After 2022 the National
Archives will no longer accept records in paper format. Many legacy records in storage still have informational value to the
Invest: Determine customer and technology needs for digitization of permanent paper records in storage in advance of 2022 NARA deadline for transfer of analog records.
center and will need to be digitized for continued access.
Divest: Decommission paper records management systems and processes.
The Center is not getting full value from its data. It is too hard to store, discover, and use.
Invest: Prototype a data management solution to make data within systems discoverable and searchable.
Data sets are getting larger and more varied, overwhelming researchers ability to extract information in a timely manner. Big Data/advanced analytics/visualization and machine learning methods support information extraction.
Invest: Define and develop a Data
Science architecture, infrastructure, and utilities; apply to institutional and research organizations to enable value added insight to information.
Increasing demand for exploratory and explanatory visualizations.
Increasing demand for supporting outreach events on Center, in Lab, and in the community.
Invest: Locate additional space for
GVIS Lab to expand and have a sufficiently large space for development, demonstrations, storage, and staff space.
Provide furniture and equipment to have world class facility. Ideally located in a space that is very visible to GRC staff and visitors.
GRC lacking in providing sustainment services for supporting information management. GRC lacks systems, based on a data architecture, to support comprehensive data life-cycle management. Data loss will happen if data not migrated to modern systems.
Invest: Research and develop a list of systems dealing with obsolete or nearly obsolete media. Deliver data obsolescence strategy/plan for data.
Divest: Divest in investments in obsolete media and the systems that read/write them.
Agencies are required to implement electronic recordkeeping to ensure transparency, efficiency, and accountability and demonstrate compliance with Federal records management statutes and regulations. The center is at risk of not being able to maintain and locate records for future use.
Invest: Define a technical architecture, policies, and practices to manage all of
GRC’s records in electronic format with automated retention notifications/management capabilities.
Divest: Decommission manual records management processes and transition to automated records management technologies.
Knowledge loss results in an erosion of NASA’s competitive advantage.
Advancing GRC’s
Knowledge Management environment minimizes loss of critical mission and mission support capabilities.
Invest: Research ways and capture information to use data mining to discover knowledge expertise.
IT Management and Governance Planning
The IT Management and Governance Program ensures the successful intigration and execution of IT Services, their planning, value proposition, effectiveness, via participatory governance and strategic decision making, across full the scope of IT Authority for the Center.
The evolution of IT and NASA Glenn Research Center’s dependency on it for mission execution continues to increasing at a rapid pace. Comprised of 10 capabilities and 34 services, the Center spends upwards of $7M annually on this portfolio of solutions. As the environment becomes more diverse, more technologically advanced, and more integrated, the Center and Agency continues to place an increasingly higher priority on the strategic management of IT. As Federal and Agency operating models for IT trend towards shared services and enterprise services, the GRC OCIO will ensure the
Center’s consumption and delivery of IT is right-sized ensuring an optimal balance between enterprise and local services.
Through this change, the Center’s IT workforce will adapt to the new operating model, stepping away from traditional IT engineering and delivery roles and into solutions architecture and service brokering roles.
Throughout this shift the OCIO must also address the IT governance expectations of federal FITARA and FISMA legislation as well as the Agency’s BSA decisions. The OCIO strives to execute this transition as a value-added enabler to the Center’s missions, and not as a compliance oversight function.
Successful navigation through this transformation requires a disciplined approach to IT Management.
Workforce planning, training and development, and the implementation of a streamlined governance framework are all elements of the 5-year plan for the Center’s IT Management and Governance
Program.
Drivers for change within the IT Management and Governance Program come from a mix of mission-enabling, cybersecurity, and compliance sources
Mission Alignment
IT Workforce Planning
Project Management Excellence
Technology Evolution across Industry
Effective Governance
Efficiencies divestments. Detailed roadmaps and plans stemming from the drivers and priorities for the IT
Management and Governance Program are provided in Appendices G1 and G2.
To better understand and meet customer’s IT requirements, provide a process interface for them to use with the Central IT service providers along with processes and procedures.
Invest: Agency will use “Voice of the
Customer”, automated system feedback analytics, and the adoption/maturation of the ITIL Service Delivery model to proactively drive improvements to the customer experience.
IT contracts are essential for meeting a variety of IT consumer needs.
Centralization adds to service efficiencies and cost reductions.
Invest: Ensure effective operation of the
PACE IV IT Services contract and assure a successful transition to its follow-on IT
Services contract.
Divest: Decommission legacy contract(s) and transition to new IT
Services contract.
Risk-based decision making enables prioritizing and allocating resources to ensure IT services continue to meet GRC’s needs.
Invest: Support an Agency initiative that will effectively manage risk via standardized IT risk management across all of the Agency OCIO (i.e., orgs reporting to NASA CIO, OCIO
Divisions, IT Programs, Center CIO orgs).
Divest: Transition Center and manual processes to Agency and automated processes.
Federal Law, Consolidated
Appropriations Act, 2018, , Division B, Public Law
115-14…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .