Amendment 2 RFP 80HQTR20R0016 ENCLOSURE 2 -ITSMP.pdf

PDF 3 MB Posted

Attached to
FINAL RFP - U. S. Global Change Research Support Program National Coordination Office Support Services Federal contract opportunity
Solicitation number
80HQTR20R0016
Issued by
National Aeronautics and Space Administration Headquarters

About this file

This document contains an Information Technology Security Management Plan template for a federal contract supporting the U.S. Global Change Research Program. The template requires the contractor to provide their contract and organization details, describe the information system and security categorization, and outline their implementation of NIST security controls. Contractors must submit the completed plan within 30 days of contract award. The related solicitation seeks proposals for National Coordination Office support services, with a proposal deadline of September 11, 2020. Questions about the solicitation are due by August 26, 2020. The awarded contract will provide support to the U.S. Global Change Research Program National Coordination Office.

View the file

Other files for this federal contract opportunity

Other files attached to FINAL RFP - U. S. Global Change Research Support Program National Coordination Office Support Services, newest first.
File Type Posted
SF30 Amendment 4.pdf PDF
4. USGCRP RFP 80HQTR20R0016 - Sections L-M_Amendment 3.pdf PDF
3. USGCRP RFP 80HQTR20R0016 - Sections B - K_Amend 3.pdf PDF
SF30 Amendment 3.pdf PDF
EXHIBIT 16 - USGCRP Technical Scenario_Amendment 3.pdf PDF
RFP 80HQTR20R0016 Q and A Set 2.pdf PDF
ATTACHMENT A - USGCRP SOW_Amendment 3.pdf PDF
3. USGCRP RFP 80HQTR20R0016 - Sections B - K_Amend 2.pdf PDF
4. USGCRP RFP 80HQTR20R0016 - Sections L-M_Amend 2_update.pdf PDF
Amendment 2 RFP 80HQTR20R0016 ENCLOSURE 3 -Historical.pdf PDF
SF30 Amendment 2.pdf PDF
USGCRP RFP 80HQTR20R0016 Q and A_Set 1.pdf PDF
SF30 Amendment 1.pdf PDF
1. Final Request for Proposal (RFP) Cover Letter.pdf PDF
ATTACHMENT A - USGCRP SOW.pdf PDF
ATTACHMENT I- PIV Attachment.pdf PDF
ATTACHMENT C - Financial Management Reporting Requirements.pdf PDF
ENCLOSURE 1 - QASP Cost-Type Contract.pdf PDF
ATTACHMENT J - IT SECURITY MANAGEMENT PLAN.pdf PDF
ATTACHMENT G - SAFETY AND HEALTH PLAN.pdf PDF
ATTACHMENT E- Position Description.pdf PDF
2. SF30-Front Page.pdf PDF
ATTACHMENT H - Contract Historical Data.pdf PDF
EXHIBIT 1-15 - Cost Plus FF Hybrid CORE-IDIQ.pdf PDF
EXHIBIT 16 - USGCRP Technical Scenario.pdf PDF
3. USGCRP RFP 80HQTR20R0016 - Sections B - K.pdf PDF
4. USGCRP RFP 80HQTR20R0016 Sections L - M.pdf PDF
EXHIBIT 17 - Past Perf Questionnaire.pdf PDF
ATTACHMENT F - SMALL BUSINESS SUBCONTRACTING PLAN.pdf PDF
1. Final Request for Proposal (RFP) Cover Letter.pdf PDF
ATTACHMENT D - IT Security Applicable Documents List-Final.pdf PDF
ATTACHMENT B - IDIQ Matrix.pdf PDF
Show all 32

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ENCLOSURE 2

INFORMATION TECHNOLOGY SECURITY

MANAGEMENT PLAN TEMPLATE

THE U.S. GLOBAL CHANGE RESEARCH PROGRAM

(USGCRP)

SUPPORT SERVICES

RFP 80HQTR20F0016

To Be Submitted within 30 Days after the contract effective date

SENSITIVE BUT UNCLASSIFIED (SBU)

Information Technology Security Management Plan

Issue Date Effective Date:

Version 1 03-01-17

(Insert Contract # Here)

IT Security Management Plan Review and Approval

This Information Technology Security Management Plan (ITSMP) for the was prepared for the exclusive use of NASA and completed on

I have reviewed the contents of this plan, and believe that it presents an accurate representation.

Reviewed by: ________________________________

ISSO, or equivalent Date

Concurred by: ________________________________

COR/Task Monitor Date

Approved by: ________________________________

Center CISO Date

Accepted by: ________________________________

Contracting Officer Date

Contents

Change History .......................................................................................................................................................................................... ii IT Security Management Plan Review and Approval ............................................................................................................................... iii 1 Contract Identification

1.1 Contract Name

1.2 Contract Number

1.3 Responsible Organization

1.4 Contact Information

1.4.1 Physical Location

1.4.2 Points of Contact

1.5 General Contract Description

1.5.1 Information System Categorization

1.5.2 Security Categorization

1.5.3 Information System

1.5.4 Contractor Badging

1.5.5 Supply Chain Risk Management (SCRM)

1.5.6 Related Laws/Regulations/Policies

2 Security Control Implementations 3 Federal Information Security Management Act (FISMA) Reporting Appendix A: Acronyms

1.5.6 Related Laws/Regulations/Policies

• 5 U.S.C. 552, Freedom of Information Act, 1967

• 5 U.S.C. 552a, Privacy Act, 1974

• FIPS 199, Standards for Security Categorization of Federal Information and Information Systems

• FIPS 200, Minimum Security Requirements for Federal Information and Information Systems

• NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems

• NIST SP 800-30, Risk Management Guide for Information Technology Systems

• NIST SP 800-34, Contingency Planning Guide for Information Technology Systems

• NIST SP 800-37, Guide for the Security Authorization of Federal Information Systems

• NIST SP 800-42, Guideline on Network Security Testing

• NIST SP 800-53, Recommended Security Controls for Federal Information Systems

• NIST SP 800-53A, Techniques and Procedures for Verifying the Effectiveness of Security Controls in Federal Information

Systems

• NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories

• NIST SP 800-61, Computer Security Incident Handling Guide

• NIST SP 800-64, Security Considerations in the Information System Development Life Cycle

• OMB Circular A-130, Appendix III, Security of Federal Automated Information Systems

• Public Law (PL) 99-474, The Computer Fraud and Abuse Act of 1986

• PL 93-502 -Freedom of Information Act 1974

• Presidential Decision Directive (PDD-63), Critical Infrastructure Protection Federal Information Security Management Act of 2002 (FISMA)

• NPR 2810.1, Security of Information Technology

Additional Information: If there is any additional information that you wish to provide, please use the box below.

File details come from the government source that posted it. Updated .