HBG_DRFP80GSFC18R0078_ATTACHMENT_J.pdf
PDF 250 KB Posted
- Attached to
- Hydrosphere, Biosphere and Geophysics (HBG) Support Services Federal contract opportunity
- Solicitation number
- 80GSFC18R0078
About this file
This document contains an IT security applicable documents list and a notice of a forthcoming federal contract opportunity for hydrosphere, biosphere and geophysics support services. The applicable documents list specifies various NASA policies, procedures, requirements and standards related to IT security. The forthcoming contract opportunity is anticipated to be a cost plus fixed fee IDIQ single award contract issued through a small business set-aside competition. The draft RFP is planned for mid-November 2018 with comments due in mid-December. A 45-day phase-in transition is anticipated. The requirement includes services across biospheric, hydrospheric, cryospheric science, geodesy and geophysics ranging from experiment design through publications. Support categories involve science, computing, instrumentation, calibration and validation, field campaigns, communications and outreach. The contractor must submit an IT security management plan within 30 days of contract effectiveness.
IT SECURITY APPLICABLE DOCS LIST
View the file
Other files for this federal contract opportunity
Show all 50
Hydrosphere, Biosphere and Geophysics (HBG) Support Services has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DRFP80GSFC18R0078
ATTACHMENT J
INFORMATION TECHNOLOGY (IT) SECURITY
APPLICABLE DOCUMENTS LIST
Information Technology (IT) Security Applicable Documents List
JANUARY 2013
NASA Policy Directives (NPD) and NASA Procedural Requirements (NPR)
Document Subject Effective Date
NPR 1382.1 NASA Privacy Procedural Requirements August 10, 2007
NPD 1382.17H NASA Privacy Policy June 24, 2009
NPD 1440.6H NASA Records Management March 24, 2008
NPR 1441.1D
NASA Records Retention Schedules (w/Change
5, 6/29/09) February 24, 2003
NPD 2540.1G
Personal Use of Government Office Equipment
Including Information Technology June 08, 2010
NPD 2800.1B Managing Information Technology March 21, 2008
NPR 2800.1B Managing Information Technology March 20, 2009
NPD 2810.1D NASA Information Security Policy May 9, 2009
NPR 2810.1A
Security of Information Technology w/ Change 1, May 19, 2011) May 16, 2006
NPD 2830.1 NASA Enterprise Architecture December 16, 2005
NPR 2830.1 NASA Enterprise Architecture Procedures February 9, 2006
NPR 7120.7
NASA Information Technology and Institutional
Infrastructure Program and Project Management
Requirements
November 3, 2008
NPR 2841.1 Identity, Credential, and Access Management January 6, 2011
NASA Interim Directive
NM2810-64
NASA Interim Directive: Information Technology
Security and Efficiency Requirements May 22, 2008
NASA Interim Technical Requirements (NITR)
NITR 2800_2 Email Services and Email Forwarding September 18, 2009
NITR 2800_1
NASA Information Technology Waiver
Requirements and Procedures August 13, 2009
NITR 2830-1B
Networks in NASA Internet Protocol (IP) Space or
NASA Physical Space February 12, 2009
NITR 1382_2
NASA Rules and Consequences to Safeguarding
PII, with Change 1, dated 02/04/2008 January 28, 2008
SOPs (ITS-SOP) and Handbooks (ITS-HBK)
ITS-HBK-
2810.0001A
Format and Procedures for an IT Security
Handbook
March 29, 2011
ITS-HBK-2810.0002 Roles and Responsibilities Crosswalk January 3, 2012
ITS-HBK-2810.0201 Security Assessment and Authorization May 6, 2011
ITS-HBK-2810.0202
Security Assessment and Authorization: FIPS
199 Moderate & High Systems
October 24, 2012
ITS-HBK-2810.0203
Security Assessment and Authorization: FIPS
199 Low Systems
October 24, 2012
ITS-HBK-2810.0204
Security Assessment and Authorization:
Continuous Monitoring – Annual Security Control
Assessments
October 24, 2012
ITS-HBK-2810.0205 Security Assessment and Authorization:
External Information Systems
October 24, 2012
ITS-HBK-2810.0206
Security Assessment and Authorization:
Extending and Information Systems
Authorization to Operate Process and Templates
October 24, 2012
ITS-HBK-2810.0207
Security Assessment and Authorization:
Information System Security Plan Numbering
Schema
November 10, 2010
ITS-HBK-2810.0208
Security Assessment and Authorization: Plan of
Action and Milestones (POA&M)
August 21, 2012
ITS-HBK-2810.0301 Planning May 6, 2011
ITS-HBK-2810.0302
Planning: Information System Security Plan
Template, Requirements, Guidance and
Examples
February 9, 2011
ITS-HBK-
2810.0401A
Risk Assessment: Security Categorization, Risk
Assessment, Vulnerability Scanning, Expedited
Patching & Organizationally Defined Values
October 12, 2012
ITS-HBK-2810.0402
Risk Assessment: Procedures for Information
System Security Penetration Testing and Rules of Engagement
February 11, 2011
ITS-HBK-2810.0501 Systems and Service Acquisition November 21, 2011
ITS-HBK-2810.0601 Awareness and Training May 6, 2011
ITS-HBK-2810.0701 Configuration Management May 6, 2011
ITS-HBK-2810.0801 Contingency Planning April 26, 2012
ITS-HBK-2810.0802
Contingency Planning: Guidance and
Templates for Plan Development, Maintenance and Test
February 11, 2011
ITS-HBK-2810.0901 Incident Response and Management May 6, 2011
ITS-HBK-2810.0902
NASA Information Security Incident
Management
August 24, 2011
ITS-HBK-2810.0903 Targeted Collection of Electronic Data August 24, 2011
ITS-HBK-2810.1001 Maintenance May 6, 2011
ITS-HBK-2810.1101 Media Protection July 13, 2012
ITS-HBK-2810.1102 Media Protection: Digital Media Sanitization July 13, 2012
ITS-HBK-2810.1201 Physical and Environmental Protection May 6, 2011
ITS-HBK-2810.1301 Personnel Security May 6, 2011
ITS-HBK-2810.1401 System and Information Integrity May 6, 2011
ITS-HBK-2810.1501 Access Control September 4, 2012
ITS-HBK-
2810.1502A Access Control: Elevated Privileges (EP) January 3, 2012
ITS-HBK-2810.1601 Audit and Accountability May 6, 2011
ITS-HBK-2810.1701 Identification and Authentication May 6, 2011
ITS-HBK-2810.1801 System and Communications Protection May 6, 2011
Standards
EA-STD 0001.0 Standard for Integrating Applications into the
NASA Access Management, Authentication, and Authorization Infrastructure
August 1, 2008
EA-SOP 0003.0 Procedures for Submitting a NASA Agency
Forest (NAF) Deviation Request and Transition
Plan
August 1, 2008
EA-SOP 0004.0 Procedures for Submitting an Application
Integration Deviation Request and Transition
Plan
August 1, 2008
NASA-STD-2804-O Minimum Interoperability Software Suite August 9, 2011
NASA-STD-2805-O Minimum Hardware Configurations August 9, 2011
Memoranda
From To Subject Effective
Date
Posted
Date
Associate
Deputy
Administrator
All NASA
Employees
Breach of Personally Identifiable
Information (PII) [Laptop
DAR/Encryption]
11/13/12 11/13/12
Charles F.
Bolden, Jr., NASA
Administrator
All NASA
Employees
Protection of Sensitive Agency
Information
4/3/2012 4/3/2012
Chief
Information
Officer
All NASA
Civil
Service and
Contractor
Employees
Policy for Use of Removable Media, Such as USB Thumb Drives
11/21/2008 11/21/2008
Within 30 days after contract effective date, the Contractor shall develop and deliver an
IT Security Management Plan to the Contracting Officer for approval.
File details come from the government source that posted it. Updated .