Attachment I - IT Security Applicable Documents List.pdf

PDF 2 MB Posted

Attached to
NRESS-II Federal contract opportunity
Solicitation number
80HQTR20R0001
Issued by
National Aeronautics and Space Administration Headquarters

About this file

This document provides details for the NRESS-II federal contract opportunity. The National Aeronautics and Space Administration Headquarters is seeking proposals for a follow-on contract to provide professional support services, information technology support, and other related services to support the agency's peer review life cycle and research objectives. The contract will be a cost-plus-fixed-fee indefinite delivery indefinite quantity contract with a five-year ordering period and estimated value of $7 million. The solicitation is anticipated to be released on February 3, 2020, with proposals due on March 4, 2020. The contract award is expected to be issued on December 1, 2020. This will be an 8(a) small business set-aside. All responsible sources may submit proposals.

View the file

Other files for this federal contract opportunity

Show all 21

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT I

INFORMATION TECHNOLOGY (IT) SECURITY

APPLICABLE DOCUMENTS LIST

June 2016

RFP 80HQTR20R0001

CONTRACT TBD

Contract TBD Attachment I

(06/2016)

Information Technology (IT) Security Applicable Documents List June 2016

NASA Policy Directives (NPD) and NASA Procedural Requirements (NPR)

Document Subject Effective Date

NPR 1382.1A NASA Privacy Procedural Requirements July 10, 2013

NPD 1382.17H NASA Privacy Policy June 24, 2009

NPD 1440.6I NASA Records Management September 10, 2014

NPR 1441.1E

NASA Records Management Program

Requirements January 29, 2015

NPD 2540.1H

Personal Use of Government Office Equipment

Including Information Technology February 24, 2016

NPD 2800.1B Managing Information Technology March 21, 2008

NPR 2800.1B Managing Information Technology March 20, 2009

NPD 2810.1E NASA Information Security Policy July 14, 2015

NPR 2810.1A

Security of Information Technology w/ Change 1, May 19, 2011) May 16, 2006

NPD 2830.1A NASA Enterprise Architecture November 2, 2011

NPR 2830.1A NASA Enterprise Architecture Procedures December 19, 2013

NPR 2841.1 Identity, Credential, and Access Management January 6, 2011

NASA Interim Directive (NID)

NM2810-64 NASA Interim Directive: Information Technology Security and Efficiency Requirements

May 22, 2008

NID 7120.99

NASA Information Technology and Institutional Infrastructure Program and Project Management Requirements

December 22, 2011

NASA Interim Technical Requirements (NITR)

NITR 2800_2

Email Services and Email Forwarding

September 18, 2009

NITR 2800_1 NASA Information Technology Waiver Requirements and Procedures

August 13, 2009

IT Security Handbooks (ITS-HBK)

ITS-HBK-1382.02-01 Privacy Goals and Objectives July 27, 2012

ITS-HBK-1382.03-01

Privacy Risk Management and Compliance:

PIAs and SORNs

September 25, 2012

ITS-HBK-1382.03-02

Privacy Risk Management and Compliance:

Annual Reporting Procedures for Reviewing and

Reducing PII and Eliminating the Unnecessary

Use of SSN

September 7, 2011

ITS-HBK-1382.04-01 Privacy and Information Security: Overview August 28, 2012

ITS-HBK-1382.05-01

Privacy Incident Response and Management:

Breach Response Team Checklist

September 25, 2012

ITS-HBK-1382.06-01

Privacy Notice and Redress: Web Privacy &

Written Notice, Complaints, Access and

Redress

September 7, 2012

ITS-HBK-1382.07-01 Privacy Awareness and Training: Overview September 7, 2014

ITS-HBK-1382.08-01 Privacy Accountability: Overview August 28, 2012

ITS-HBK-1382.09-01

Privacy Rules of Behavior and Consequences:

Overview

September 7, 2012

ITS-HBK-2810.0001-B

Format and Procedures for an IT Security

Policies and Handbooks

June 19, 2014

IT Security Handbooks (ITS-HBK)

Document Subject Effective Date

NITR 2810.1

NASA Information Technology Security

Disclaimer

Sept 30, 2014

ITS-HBK-1441.01.01 Records Retention and Disposition: Overview Jul 02, 2014

ITS-HBK-1440.01.01 Records Planning & Management: Records Jul 02, 2014

ITS-HBK-2841.001-A Identity, Credential, and Access Management

Services

Feb 01, 2011

IT-SOP-2841.001-A Identity and Credential Service Providers

Federation Requests

Feb 01, 2011

IT-SOP-2841.002-A Identity, Credential, and Access Management

(ICAM): Service Deviation Requests

Management & Records Life Cycle-Overview

Feb 01, 2011

IT-STD-1441.1 NASA Records Retention Schedules May 07, 2014

ITS-HBK-2810.02-01 Security Assessment and Authorization May 6, 2011

ITS-HBK-2810.0002-A

Roles and Responsibilities Crosswalk &

Definitions

May 2, 2013

ITS-HBK-2810.02-02D

Information System Security Assessment and

Authorization Process

February 1, 2015

ITS-HBK-2810.02-04A

Security Assessment and Authorization:

Continuous Monitoring – Annual Security

Control Assessments

March 18, 2014

ITS-HBK-2810.02-05 Security Assessment and Authorization:

External Information Systems

October 24, 2012

ITS-HBK-2810.02-06

Security Assessment and Authorization:

Extending and Information Systems

Authorization to Operate Process and

Templates

October 24, 2012

ITS-HBK-2810.02-08A

Security Assessment and Authorization: Plan of

Action and Milestones (POA&M)

December 11, 2013

IT Security Handbooks (ITS-HBK)

Document Subject Effective Date

ITS-HBK-2810.03-01 Planning May 6, 2011

ITS-HBK-2810.03-02

Planning: Information System Security Plan

Template, Requirements, Guidance and

Examples

February 9, 2011

ITS-HBK-2810.04-01A

Risk Assessment: Security Categorization, Risk

Assessment, Vulnerability Scanning, Expedited

Patching & Organizationally Defined Values

October 12, 2012

ITS-HBK-2810.04-02

Risk Assessment: Procedures for Information

System Security Penetration Testing and Rules of Engagement

April 30, 2013

ITS-HBK-2810.04-03

Risk Assessment: Web Application Security

Program

April 30, 2013

ITS-HBK-2810.05-01 Systems and Service Acquisition November 21, 2011

ITS-HBK-2810.06a-01 Awareness and Training May 5, 2011

ITS-HBK-2810.07-01 Configuration Management May 6, 2011

ITS-HBK-2810.08-01 Contingency Planning May 06, 2011

ITS-HBK-2810.08-02

Contingency Planning: Guidance and

Templates for Plan Development, Maintenance and Test

February 10, 2011

ITS-HBK-2810.09-01A Incident Response and Management December 30, 2014

ITS-HBK-2810.09-02

NASA Information Security Incident

Management

August 24, 2011

ITS-HBK-2810.09-03 Targeted Collection of Electronic Data August 24, 2011

ITS-HBK-2810.09-04

Incident Response and Management:

Guidelines for Data Spillage & Sanitization

Procedures

February 27, 2014

ITS-HBK-2810.10-01 Maintenance May 6, 2011

IT Security Handbooks (ITS-HBK)

Document Subject Effective Date

ITS-HBK-2810.11-01 Media Protection July 13, 2012

ITS-HBK-2810.11-02 Media Protection: Digital Media Sanitization July 13, 2012

ITS-HBK-2810.12-01 Physical and Environmental Protection May 6, 2011

ITS-HBK-2810.13-01 Personnel Security May 6, 2011

ITS-HBK-2810.14-01 System and Information Integrity May 6, 2011

ITS-HBK-2810.15-01 Access Control September 4, 2012

ITS-HBK-2810.15-02A Access Control: Elevated Privileges (EP) September 20, 2012

ITS-HBK-2810.16-01 Audit and Accountability May 6, 2011

ITS-HBK-2810.17-01 Identification and Authentication Jan 17, 2011

ITS-HBK-2810.18-01 System and Communications Protection Apr 6, 2011

Standards

EA-STD 0001.0 Standard for Integrating Applications into the

NASA Access Management, Authentication, and

Authorization Infrastructure

August 1, 2008

EA-SOP 0003.0 Procedures for Submitting a NASA Agency

Forest (NAF) Deviation Request and Transition

Plan

August 1, 2008

EA-SOP 0004.0 Procedures for Submitting an Application

Integration Deviation Request and Transition

Plan

August 1, 2008

NASA-STD-2804-P Minimum Interoperability Software Suite September 22, 2014

NASA-STD-2805-P Minimum Hardware Configurations September 22, 2014

File details come from the government source that posted it. Updated .