Encl_2_IT_Security_Management_Plan_Template.pdf

PDF 1 MB Posted

Attached to
Supra Thermal Ion Sensor (STIS) Instrument Federal contract opportunity
Solicitation number
80GSFC19R0033
Issued by
National Aeronautics and Space Administration Goddard Space Center

About this file

This document provides an Information Technology Security Management Plan template for a federal contract. The template outlines requirements for identifying the contract and responsible organizations. It includes sections for describing security control implementations and Federal Information Security Management Act reporting. The template requests information on the contract name and number, responsible organization contact details, information system categorization and security categorization. It also lists applicable federal laws, regulations and policies. The template aims to document security requirements for information technology systems involved in federal contracting work.

The related federal contract opportunity is a solicitation from NASA Goddard Space Flight Center for a Supra Thermal Ion Sensor instrument. The instrument will be part of the Space Weather Follow On L1 satellite mission to provide solar wind and coronal mass ejection data to NOAA. The scope of work involves design, development, testing, calibration, evaluation, launch support and operations for the ion sensor. It is anticipated one flight model, one engineering development unit, flight harnesses and spares will be delivered. The contract type will be cost-plus-incentive-fee and incentives are planned for cost and schedule. The solicitation release is expected in fall 2019 with responses due 45 days later. The opportunity falls under NAICS code 336414 with a size standard of 1,250 employees.

Enclosure 2 IT Security Management Plan Template

View the file

Other files for this federal contract opportunity

Other files attached to Supra Thermal Ion Sensor (STIS) Instrument, newest first.
File Type Posted
STIS Questions and Responses 1-24-20.(additional).pdf PDF
STIS Questions and Responses 1-24-20.pdf PDF
STIS Questions and Responses 12-19-19.pdf PDF
STIS Questions and Responses 12-11-19.pdf PDF
Att B_Amend 003_changes identified_L1-STISSPEC-0002_Ver0.2.pdf PDF
Att C_Amend 003_changes identified_L1-STISCDRL-0003_Ver0.2 .pdf PDF
Att A_Amend 003_changes identified__L1-STISSOW-0001_Ver0.2.pdf PDF
STIS SF33 Amend 003.pdf PDF
Att B_Amend 003_L1-STISSPEC-0002_Ver0.2 12-6-19-sign.pdf PDF
Att A_Amend 003_-L1-STISSOW-0001_Ver0.2-signed.pdf PDF
Att C_Amend 003_L1-STISCDRL-0003_Ver0.2-signed.pdf PDF
STIS Amendment 003 continuation page.pdf PDF
STIS RFP Cover letter Amend 003.pdf PDF
STIS SF30 Amend 003.pdf PDF
STIS_SF30_Amend_002_(003).pdf PDF
STIS_Questions_and_Responses_Amendment_002_Final.pdf PDF
STIS_SF33_Amendment_002_Final.pdf PDF
STIS_Sections_L_and_M_Amendment_002_Final.pdf PDF
RFP_80GSFC19R0033_Amd_001.pdf PDF
Amd_1_SF30.pdf PDF
SF33.pdf PDF
Encl_1_STIS_QASP.pdf PDF
Att_E_533_instructions.pdf PDF
Encl_3_PastPerfQues.pdf PDF
Att_A_422-L1-STISSOW-0001_Ver0.1_-_Signed.pdf PDF
1RFP_80GSFC19R0033.pdf PDF
Att_K_IT_Security_Applicable_Documents_List.pdf PDF
Att_C_422-L1-STISCDRL-0003_Ver0.1(1)_-_Signed.pdf PDF
Exhibit_1_SB_SC_Goals.pdf PDF
Att_B_422-L1-STISSPEC-0002_Ver0.1_-_Signed.pdf PDF
RFP_Cover_Letter.pdf PDF
Att_D_422-L1-IMAR-0004_Ver0.1_-_Signed.pdf PDF
Show all 32

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SENSITIVE BUT UNCLASSIFIED (SBU)

Information Technology Security Management Plan

Issue Date Effective Date:

Version 1 03-01-17

(Insert Contract # Here)

IT Security Management Plan Review and Approval

This Information Technology Security Management Plan (ITSMP) for the was prepared for the exclusive use of NASA and completed on

I have reviewed the contents of this plan, and believe that it presents an accurate representation.

Reviewed by: ________________________________

ISSO, or equivalent Date

Concurred by: ________________________________

COR/Task Monitor Date

Approved by: ________________________________

Center CISO Date

Accepted by: ________________________________

Contracting Officer Date

Contents

Change History .......................................................................................................................................................................................... ii IT Security Management Plan Review and Approval ............................................................................................................................... iii 1 Contract Identification

1.1 Contract Name

1.2 Contract Number

1.3 Responsible Organization

1.4 Contact Information

1.4.1 Physical Location

1.4.2 Points of Contact

1.5 General Contract Description

1.5.1 Information System Categorization

1.5.2 Security Categorization

1.5.3 Information System

1.5.4 Contractor Badging

1.5.5 Supply Chain Risk Management (SCRM)

1.5.6 Related Laws/Regulations/Policies

2 Security Control Implementations 3 Federal Information Security Management Act (FISMA) Reporting Appendix A: Acronyms

1.5.6 Related Laws/Regulations/Policies

• 5 U.S.C. 552, Freedom of Information Act, 1967

• 5 U.S.C. 552a, Privacy Act, 1974

• FIPS 199, Standards for Security Categorization of Federal Information and Information Systems

• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems

• NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems

• NIST SP 800-30, Risk Management Guide for Information Technology Systems

• NIST SP 800-34, Contingency Planning Guide for Information Technology Systems

• NIST SP 800-37, Guide for the Security Authorization of Federal Information Systems

• NIST SP 800-42, Guideline on Network Security Testing

• NIST SP 800-53, Recommended Security Controls for Federal Information Systems

• NIST SP 800-53A, Techniques and Procedures for Verifying the Effectiveness of Security Controls in Federal Information

Systems

• NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories

• NIST SP 800-61, Computer Security Incident Handling Guide

• NIST SP 800-64, Security Considerations in the Information System Development Life Cycle

• OMB Circular A-130, Appendix III, Security of Federal Automated Information Systems

• Public Law (PL) 99-474, The Computer Fraud and Abuse Act of 1986

• PL 93-502 -Freedom of Information Act 1974

• Presidential Decision Directive (PDD-63), Critical Infrastructure Protection Federal Information Security Management Act of 2002 (FISMA)

• NPR 2810.1, Security of Information Technology

Additional Information: If there is any additional information that you wish to provide, please use the box below.

File details come from the government source that posted it. Updated .