Attachment S - IT Security Applicable Docs.pdf
PDF 157 KB Posted
- Attached to
- NASA Sounding Rocket Operations Contract (NSROC) IV - FINAL Request for Proposal Federal contract opportunity
- Solicitation number
- 80GSFC21R0037
About this file
This document provides an Information Technology (IT) Security Applicable Documents List for the NASA Sounding Rocket Operations Contract IV solicitation. The solicitation seeks services to operate and maintain government-owned facilities at NASA's Wallops Flight Facility in Virginia and White Sands Missile Range in New Mexico for conducting sounding rocket operations from multiple launch sites, including remote launch campaigns. The list identifies applicable NASA policies, procedures, requirements, standards, and handbooks on topics including IT security, privacy, records management, software engineering, and risk assessment that offerors must comply with in performance of the contract. Within 30 days of contract award, the contractor must develop and deliver an IT Security Management Plan to the Contracting Officer for approval.
View the file
Other files for this federal contract opportunity
Show all 50
NASA Sounding Rocket Operations Contract (NSROC) IV - FINAL Request for Proposal has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOLICITATION NUMBER 80GSFC21R0037
NASA SOUNDING ROCKET OPERATIONS CONTRACT IV
(NSROC IV)
ATTACHMENT S
INFORMATION TECHNOLOGY (IT) SECURITY
APPLICABLE DOCUMENTS LIST
JULY 2021
Solicitation No. 80GSFC21R0037 NASA Sounding Rocket Operations Contract IV
ATTACHMENT T – IT SECURITY APPLICABLE DOCUMENTS LIST
Information Technology (IT) Security Applicable Documents List
June 2021
NASA Policy Directives (NPD) and NASA Procedural Requirements (NPR)
Document Subject
Effective Date
NPR 1382.1A NASA Privacy Procedural Requirements July 10, 2013
NPD 1382.17J NASA Privacy Policy June 29, 2016
NPD 1440.6I NASA Records Management July 30, 2019
NPR 1441.1E NASA Records Management Program Requirements
(Updated w/Change 3)
January 29, 2015
NPD 2540.1I Acceptable Use of Government Office Property Including
Information Technology
August 19, 2019
NPD 2800.1E Managing Information Technology December 09, 2019
NPD 2810.1E NASA Information Security Policy January 31, 2020
NPR 2810.1A Security of Information Technology w/ Change 1, May
19, 2011
May 16, 2006
NPR 2810.2 Possession and Use of NASA Information and
Information Systems Outside of the United States and
United States Territories
October 29, 2019
NPD 2830.1D NASA Enterprise Architecture November 17, 2020
NPR 2830.1A NASA Enterprise Architecture Procedures December 19, 2013
NPR 2841.1 Identity, Credential, and Access Management
(Revalidated w/change 1)
January 6, 2011
NPR 7120.7A NASA Information Technology Program and Project
Management Requirements
August 17, 2020
NPR 7150.2C NASA Software Engineering Requirements August 02, 2019
NASA Interim Directive
Document Subject
Effective Date
NID 2810.135 NASA Interim Directive: Controlled Unclassified
Information
February 2, 2021
NID 1420.123 NASA Interim Directive: NASA Forms June 25, 2019
NID 7150.1 NPR 7150.2A, NASA Software Engineering Requirements
December 18, 2013
NASA Advisory Implementing Instruction (NAII)
Document Subject Effective Date
NAII 2810.1 Networks in NASA Internet Protocol (IP) Space or NASA
Physical Space
June 12, 2020
NAII 2810.2 Email Services November 4, 2020
Information and Information Systems Handbooks (ITS-HBK)
ITS-HBK-2810.15-01A Access Control December 6, 2019
ITS-HBK-2810.15-02A Access Control: Managed Elevated Privileges July 1, 2020
ITS-HBK-2810.16-02B Audit and Accountability October 9, 2018
ITS-HBK-2810.09-03A Collection of Electronic Data (CUI) June 1, 2020
ITS-HBK-2810.07-02B Configuration Management May 25, 2021
ITS-HBK-2810.08-01A Contingency Planning July 30, 2019
ITS-HBK-2810.02-04A Continuous Monitoring: Security Control
Ongoing Assessment and Authorization
May 23, 2019
ITS-HBK-CUI_v1.0.0 Controlled Unclassified Information Handbook May 4, 2021
ITS-HBK-2810-002.1C Format and Procedure for IT Security Policies and Handbooks
October 28, 2019
ITS-HBK-2810.17-02B Identification and Authentication May 22, 2019
IT-HBK-2841-03A Identity, Credential, and Access Management
(ICAM) Services
November 2, 2020
ITS-HBK-2810.09-01 Incident Response and Management November 6, 2019
ITS-HBK-2810.09-04 Incident Response and Management: Guidelines for Data Spillage and Sanitization Procedures
November 6, 2019
ITS-HBK-SCRM.2810.v1 Information & Communications Technology
Supply Chain Risk Management (ICT SCRM)
April 28, 2021
ITS-HBK-2810.06-2B IT Security Awareness, Training and Education September 10, 2020
ITS-HBK-2810.02-01 IT Security Handbook: Security Assessment and
Authorization
December 7, 2015
ITS-HBK-2810.10-02C Maintenance May 25, 2021
ITS-HBK-2810.11-2C Media Protection and Sanitization May 25, 2021
ITS-HBK-2810.09-02A NASA Information Security Incident
Management
November 1, 2019
ITS-HBK-2810.19-01 Operational Technology September 18, 2020
ITS-HBK-2810.13-01B Personnel Security May 22, 2019
ITS-HBK-2810.12-02B Physical and Environmental Protection May 22, 2019
ITS-HBK-2810.03-02B Planning December 4, 2019
ITS-HBK-1382.08-01 Privacy Accountability November 19, 2018
ITS-HBK-1382.04-1 Privacy and Information Security Overview March 12, 2020
ITS-HBK-1382.07-01 Privacy Awareness and Training November 18, 2018
ITS-HBK-1382.02-01 Privacy Goals and Objectives November 18, 2018
ITS-HBK-1382.05-01 Privacy Incident Response and Management:
Breach Response Team Checklist
October 10, 2018
ITS-HBK-1382.06-01 Privacy Notice and Redress — Web Privacy and
Written Notice, Complaints, Access, and Redress
March 12, 2020
ITS-HBK-1382.03-01 Privacy Risk Management — Collections, PIAs, and SORNs
July 23, 2020
ITS-HBK-1382.03-02 Privacy Risk Management and Compliance:
Annual Reporting Procedures to Reduce
Personally Identifiable Information and
Eliminate Unnecessary Use of Social Security
Numbers
August 4, 2017
ITS-HBK-1382.09-01 Privacy Rules of Behavior and Consequences March 12, 2020
IT-HBK-1440.01-01 Records Management Program and Records Life
Cycle: Chapter 1 — Overview
July 2, 2014
IT-HBK-1441.01-01 Records Retention and Disposition: Chapter 1 —
Overview
July 2, 2014
ITS-HBK-2810.04-01A Risk Assessment, Vulnerability Scanning, and
Expedited Patching
May 23, 2019
IT-SOP-2810.01A Risk Assessment: Vulnerability Assessment
Program Standard Operating Procedure
July 13, 2018
ITS-HBK 2810.02-02E Security Assessment and Authorization November 6, 2019
ITS-HBK-2810.02-06 Security Assessment and Authorization:
Extending an Information System Authorization to Operate Process and Templates
November 6, 2019
ITS-HBK-2810.02-05B Security Assessment and Authorization: External
Information Systems
May 11, 2021
ITS-HBK-2810.02-08A Security Assessment and Authorization: Plan of
Action and Milestones
November 6, 2019
ITS-HBK-2810.18-02B System and Communications Protection October 16, 2018
ITS-HBK-2810.14-03C System and Information Integrity October 28, 2019
ITS-HBK-2810.05-2B System and Service Acquisition August 14, 2019
Standards
NASA-STD-2601.v1 Minimum Cybersecurity Requirements for
Computing Systems
August 12, 2019
NASA-STD-2602.v1 Minimum Information System Owner and End
User Security for Data at Rest
June 13, 2018
NASA-STD-2603.v1 Minimum Security and Privacy Requirements for
Agency and Center Information System
Implementations
Octoer 9, 2019
NASA-STD-2604.v1 Computing System Configuration Management August 12, 2019
NASA-STD-2804 Minimum Interoperability Software Suite March 27, 2020
NASA-STD-2805 Minimum Hardware Configurations November 12, 2020
NASA-STD-8739.8A Software Assurance and Software Safety Standard June 10, 2020
Within 30 days after contract effective date, the Contractor shall develop and deliver an IT
Security Management Plan to the Contracting Officer for approval.
File details come from the government source that posted it. Updated .