Enclosure AA_IT Security Management Plan Template.pdf

PDF 3 MB Posted

Attached to
Geostationary Extended Observations (GeoXO) Atmospheric Composition (ACX) Instrument Implementation Federal contract opportunity
Solicitation number
80GSFC23R0012
Issued by
National Aeronautics and Space Administration Goddard Space Center

View the file

Other files for this federal contract opportunity

Other files attached to Geostationary Extended Observations (GeoXO) Atmospheric Composition (ACX) Instrument Implementation, newest first.
File Type Posted
ACX Instrument Implementation_SF30 Amendment 1.pdf PDF
FRFP 80GSFC23R0012 Amendment 1 Continuation Page.pdf PDF
Enclosure AA_Final IT Security Management Plan Template.pdf PDF
ACX FRFP Cost Exhibits.pdf PDF
Attachment Q_Final GOES Reliable Data Delivery Protocol (GRDDP).pdf PDF
Attachment G_Final EDM.pdf PDF
Attachment B_ACX_ Final PORD.pdf PDF
ACX FRFP SF33.pdf PDF
Attachment U_Final FPGA final v1.0 08112022.pdf PDF
Attachment T_Final DEIA Plan DRD.pdf PDF
Attachment R_Final GOES Reliable Data Delivery Protocol.pdf PDF
Attachment K_Final Small Business Subcontracting Plan.pdf PDF
Attachment I_Final OCI Plan DRD.pdf PDF
Attachment H_Final Financial Rptg.pdf PDF
Attachment E_Final Instrument Mission Assurance Requirements.pdf PDF
Attachment D_ACX_ Final Unique Instrument Interface Document.pdf PDF
Enclosure BB_ACX Final PEP.pdf PDF
Attachment W_Final OCI Plan.pdf PDF
Attachment J_Final Safety and Health Plan.pdf PDF
Attachment C_ Final GIRD.pdf PDF
ACX_Cover Letter FRFP_80GSFC23R0012.pdf PDF
Attachment S_Final Concept of Operations (CONOPS).pdf PDF
Attachment R_GOES Reliable Data Delivery Protocol.pdf PDF
Attachment M_IT Applicable Documents List.pdf PDF
Attachment L - IT Security Management Plan.pdf PDF
Attachment F_ACXCDRL V0.14 DRAFT.pdf PDF
Attachment D_ACX Unique Instrument Interface Document.pdf PDF
Attachment C_GIRD.pdf PDF
Attachment B_ACX_PORD.pdf PDF
Attachment A_ACX_SOW.pdf PDF
Attachment W - OCI Plan.pdf PDF
Attachment Q_GOES Reliable Data Delivery Protocol (GRDDP).pdf PDF
Attachment K - Small Business Subcontracting Plan.pdf PDF
Attachment H_Financial Rptg.pdf PDF
Enclosure DD_418-XO-PLN-0109 GeoXO QASP FINAL V2.0.pdf PDF
Enclosure BB_ACX DRFP Performance Evaluation Plan.pdf PDF
ACX DRFP Cost Exhibits.pdf PDF
Attachment U_FPGA final v1.0 08112022.pdf PDF
Attachment T_DEIA Plan DRD.pdf PDF
Attachment O_ACX DRFP CWBS.pdf PDF
Attachment N_DEIA Plan.pdf PDF
Attachment J - Safety and Health Plan.pdf PDF
Attachment G_EDM.pdf PDF
ACX_DRFP_80GSFC23R0012.pdf PDF
ACX_Cover Letter DRFP_80GSFC23R0012.pdf PDF
Attachment P_ACX Radiance Upwelling.pdf PDF
Enclosure CC_ACX PPQ.pdf PDF
Attachment V_Requirements Statements List.pdf PDF
Attachment S_Concept of Operations (CONOPS).pdf PDF
Attachment I_OCI Plan DRD.pdf PDF
Show all 50

Geostationary Extended Observations (GeoXO) Atmospheric Composition (ACX) Instrument Implementation has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CUI

VERSION 8 2/2022

Preface To carry out its wide-ranging responsibilities, the National Aeronautics and Space Administration (NASA), and its employees and managers have access to diverse and complex automated information systems, which include file servers, local and wide area networks running on various platforms, and telecommunications systems to include communications equipment. The offices within NASA depend on the confidentiality, integrity, and availability of these systems and their data in order to accomplish day-to-day activities.

This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract. Unlike the IT security plan, which addresses the IT system, the IT Security Management Plan addresses how the contractor will manage personnel and processes associated with IT Security on the instant contract.

The ITSMP is a document required by the NASA FAR to be created and submitted within 30 days of contract award for all contracts, regardless of whether they encompass an information system. The ITSMP should be utilized by all contracts to satisfy the ITSMP FAR clause requirement. Additionally, if the contractor is responsible for an external information system, this document may be leveraged for the completion of an external information system IT Security Plan (reference Information Technology Security Handbook ITS- HBK-AASTEP5.v1.0.0).

VERSION 8 2/2022

Contents Preface ....................................................................................................................................................................................................... ii

Change History ......................................................................................................................................................................................... iii

IT Security Management Plan Review and Approval ............................................................................................................................... iv

1 Contract Identification

1.1 Contract Name

1.2 Contract Number

1.3 Responsible Organization

1.4 Contact Information

1.4.1 Physical Location

1.4.2 Points of Contact

1.5 General Contract Description

1.5.1 Information System

1.5.2 Contractor Badging

1.5.3 Supply Chain Risk Management (SCRM)

1.5.4 Related Documents

2 Security Control Implementations

2.1 Management Controls

2.2 Operational Controls

2.3 Technical Controls

3 Federal Information Security Management Act (FISMA) Reporting

Appendix A: Acronyms

VERSION 8 2/2022

1.5.3 Supply Chain Risk Management (SCRM)

Will IT components be procured/purchased in performance of the contract?

Yes No

Are you meeting Federal SCRM requirements documented in the Consolidated Appropriations Act, 2021 (Section 208)?

Yes No

1.5.4 Related Documents

5 U.S.C. 552, Freedom of Information Act, 1967 5 U.S.C. 552a, Privacy Act, 1974 FIPS 199, Standards for Security Categorization of Federal Information and Information Systems FIPS 200, Minimum Security Requirements for Federal Information and Information Systems NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems NIST SP 800-30, Risk Management Guide for Information Technology Systems NIST SP 800-34, Contingency Planning Guide for Information Technology Systems NIST SP 800-37, Guide for the Security Authorization of Federal Information Systems NIST SP 800-42, Guideline on Network Security Testing NIST SP 800-53, Recommended Security Controls for Federal Information Systems NIST SP 800-53A, Techniques and Procedures for Verifying the Effectiveness of Security Controls in Federal Information

Systems NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories NIST SP 800-61, Computer Security Incident Handling Guide NIST SP 800-64, Security Considerations in the Information System Development Life Cycle OMB Circular A-130, Appendix III, Security of Federal Automated Information Systems Public Law (PL) 99-474, The Computer Fraud and Abuse Act of 1986 PL 93-502 -Freedom of Information Act 1974 Presidential Decision Directive (PDD-63), Critical Infrastructure Protection Federal Information Security Management Act of 2002 (FISMA) NPR 2810, Security of Information Technology H.R.133-Consolidated Appropriations Act, 2021 (Section 208)

N/A

VERSION 8 2/2022

The organization establishes terms and conditions, consistent with any trust relationships established with other organizations owning, operating, and/or maintaining external information systems, allowing authorized individuals to

a. Access the information system from the external information systems; and

b. Process, store, and/or transmit organization-controlled information using the external information systems.

3 Federal Information Security Management Act (FISMA) Reporting The contractor shall adhere to the NASA FISMA reporting requirements and provide inputs upon request. In general this includes:

Security Control Review/Assessment Date Authorization to Process/Store (ATP/S) Date2

Contingency Plan Test Date Contingency Plan Test Type (Tabletop, Simulation or Full)

2 ATP/S is not applicable to contactors who are not operating an external system, rather, components used in the performance of the contract are covered under an internal, NASA information system.

File details come from the government source that posted it. Updated .