Attachment A - CyPrESS PWS Updated Amendment 01.pdf
PDF 991 KB Posted
- Attached to
- Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
- Solicitation number
- 80TECH21R0007
About this file
This performance work statement outlines cybersecurity and privacy services required by the National Aeronautics and Space Administration. The contractor shall provide a range of cybersecurity capabilities including cybersecurity program management support, oversight support, standards and architecture engineering, and cybersecurity and privacy services such as continuous monitoring, incident response, vulnerability management, and risk management framework services. The contractor must have necessary security clearances and be able to support distributed operations at multiple NASA locations. The work includes both core requirements for all NASA centers and potential additional work awarded on an indefinite delivery/indefinite quantity basis. The contractor will consolidate various existing cybersecurity contracts to provide these services in a cost-plus-award-fee arrangement over an initial ordering period of one year with the potential to transition some tasks to firm-fixed-price thereafter.
The solicitation number 80TECH21R0007 provides additional context, as it seeks proposals for the Cybersecurity and Privacy Enterprise Solutions and Services contract described in the attached performance work statement. Offerors would deliver the products and services outlined to support the National Aeronautics and Space Administration's cybersecurity and privacy program.
View the file
Other files for this federal contract opportunity
Show all 50
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT A
PERFORMANCE WORK STATEMENT
RFP 80TECH21R0007
CONTRACT # TBD
June 2021
CyPrESS 80TECH21R0007
Table of Contents
ATTACHMENT A
1.0 Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS)
1.1 Introduction and Overview
1.2 Principal CyPrESS Stakeholders and Places of Performance
1.3 Center and Cybersecurity Services Transition
1.4 CSPP’s Goals
1.5 PWS Overview
2.0 Contract Management
2.1 Program Management
2.1.1 Program Management
2.1.2 Documentation Management
2.1.3 Communication
2.2 Contract Administration System
2.3 Critical Staffing Positions
2.4 Financial Management
2.5 Property/Inventory Management/Logistics
2.6 Quality Management
2.7 Safety, Health, and Environmental (SHE) Management
3.0 Cybersecurity and Privacy Program Management Support
3.1 Office of Cybersecurity Services (OCSS) Support
3.1.1 Service Management
3.1.2 Performance Management
3.1.3 Change Management
3.1.4 Customer Outreach and Communications
3.2 Security Operations Center (SOC) Support
3.3 CSPP Business Management
3.4 Policy Management
3.5 Privacy Management Support
3.6 Controlled Unclassified Information (CUI) Management Support
3.7 Cybersecurity and Privacy Risk Management Support
3.7.1 Risk Management Strategy
3.7.2 Governance, Risk and Compliance Management
3.7.3 Vulnerability Management
4.0 Cybersecurity and Privacy Oversight Support
5.0 Cybersecurity Standards, Architecture and Engineering
5.1 Cybersecurity Standards and Architecture
5.2 Identity, Credential and Access Management (ICAM) Engineering
5.3 Applications Engineering
5.4 Cybersecurity Cloud Engineering
5.5 Cybersecurity Network Engineering and Design Support
5.6 Operational, Research and Test Environments Support
5.7 Project Management and Technical Reviews
6.0 Cybersecurity and Privacy Services
6.1 Continuous Monitoring and Detection (M&D) and Triage
6.2 Incident Response and Management
6.3 Cyber Forensics and Incident Analysis
6.4 Cyber Threat Detection and Hunt
6.5 Cyber Threat Analysis
6.6 Cybersecurity Infrastructure Services
6.7 Training and Awareness
6.8 Supply Chain Risk Management (SCRM) Support
6.9 Risk Management Framework (RMF) Services
6.9.1 Independent Assessment Services
6.9.2 Assessment & Authorization (A&A) Services
6.9.3 Information System Security Official (ISSO) Services – IDIQ Only
6.10 Cybersecurity Posture Assessment Services
6.10.1 Cybersecurity Scanning and Vulnerability Detection
6.10.2 Cyber Hygiene Management
6.10.3 In-Depth Cybersecurity Technical Assessments
6.10.4 High Value Asset (HVA) Assessment
6.10.5 Penetration Testing
6.10.6 Social Engineering Assessments
6.10.7 Cybersecurity Incident Response Assessments
1.0 Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS)
1.1 Introduction and Overview
The information technology (IT) mission of the National Aeronautics and Space Administration (NASA) Office of the Chief Information Officer (OCIO) is to enable the secure use of data to accomplish NASA’s Mission. The NASA OCIO Cybersecurity & Privacy Division (CSPD) established the Cybersecurity & Privacy Program (CSPP) to correct known vulnerabilities, reduce barriers to cross- Center collaboration, and provide cost-effective cybersecurity services in support of NASA’s information systems, and e-Gov initiatives.
The CSPP ensures that cybersecurity activities across NASA support confidentiality, integrity, and availability objectives for data and information systems, to include disaster recovery and continuity of operations, in order to support the business requirements of critical Agency programs and missions. The CSPP develops and maintains consistent security policy, identifies and implements risk-based security controls, and tracks security metrics to gauge effectiveness and compliance.
The CyPrESS contract is the first enterprise cybersecurity and privacy services contract.
Cybersecurity and privacy work is being consolidated from various Center and enterprise IT contracts. This contract is a Single Award, Cost Plus Award Fee (CPAF) Core and Hybrid Indefinite- Delivery, Indefinite-Quantity (IDIQ) with the ability to award CPAF and Firm-Fixed Price (FFP) task orders, and a FFP Phase-in. First year ordering period will be CPAF with the ability to transition tasks to FFP for the remaining duration of the ordering period. The CyPrESS Core requirements are all of the services listed in the Performance Work Statement (PWS) and Centers, with the exception of the current and future IDIQ, such as Information System Security Official (ISSO) Services, Glenn Research Center (GRC), the NASA Shared Service Center (NSSC), and any future cybersecurity requirements.
The CyPrESS contract will be awarded during a period of significant transformation for NASA. NASA has proactively engaged in a disciplined approach to improving the agency’s operating model over the past several years. One of the top initiatives under NASA’s Mission Support Directorate is the Mission Support Future Architecture Program or MAP. MAP will transform mission support services to an enterprise operating model while maintaining mission focus, improving efficiency, ensuring local authority and valuing the workforce. Mission support services are the functions traditionally managed and operated at each NASA center and headquarters and include information technology.
The NASA OCIO is currently in the implementation phase of its MAP Project. This Project will culminate in a fundamental reshaping of the way NASA provisions and consumes IT services.
While the CSPP is responsible for overall management of cybersecurity and privacy requirements, processes, services and capabilities for NASA, other service lines provide enterprise IT services across the Agency, e.g. networking and telecommunications services, end-user services, applications, web services, collaboration, etc. These enterprise IT service areas are all stakeholders, and sometimes customers, of the CSPP and the CyPrESS contract. Several of these service lines are also supported by enterprise contracts, such as NASA End-User Services & Technologies (NEST), Advanced Enterprise Global IT Solutions (AEGIS), and other NASA contractors, whereas agreements are expected to be established with those NASA contractors. The CyPrESS contractor will be
Nex-Gen NSSC’s Cybersecurity Support Service 10/1/2023
1.4 CSPP’s Goals
The CSPP developed a Cybersecurity Strategy for NASA, comprised of high-level program goals and strategic objectives and sub-objectives. This strategy supports, and is in direct alignment with, the NASA IT Strategic Plan. The CSPP goals are the following:
• Partnership & Communication: Strengthen relationship and visibility with partners across the Agency and promote cybersecurity best practices and awareness
• Service Delivery: Deliver effective cybersecurity services consistently across the Agency
• Risk Management: Manage cybersecurity risks in a standardized way that maps to Agency risk management framework and informs better risk-based decisions
• Cybersecurity Architecture: Develop Agency-wide security architecture to manage complexity while meeting strategic goals
• Cybersecurity Operations: Develop comprehensive security operations capability to prevent and mitigate impact from threats and improve incident response
1.5 PWS Overview
The Performance Work Statement (PWS) addresses NASA’s core requirements for CyPrESS. The Contractor shall serve as the primary provider of cybersecurity and privacy capabilities through the implementation of the CyPrESS PWS. Prior to beginning work on the contract, the Contractor shall ensure that all employees have completed the required background checks, approvals, a minimum of an OPM Tier 1 and clearance requirements for IT and Physical access (see Section 1.2, Principal CyPrESS Stakeholders and Places of Performance) and data according to directives and policies of the requesting organizations.
Performance under this contract will require some positions at the Secret and Top Secret clearance for access to and/or generation of classified information, work in a security area, or both.
Additionally, some positions under this contract will require personnel with access to Top Secret Sensitive Compartmented Information (SCI).
Throughout the PWS, IT system(s) denotes IT Systems, Operational Technology (OT) and/or cloud systems.
The PWS consists of work divided into the following sections:
• Contract Management o The requirements in this section include Program Management, Contract Administration System, Financial Management, Property/Inventory Management/Logistics, Quality Assurance and Management, and Safety, Health & Environmental Management.
• Cybersecurity and Privacy Program Management Support o The work contained in this category includes providing support for the operations, business management, and policy created and maintained by the Cybersecurity and Privacy Division, the NASA Office of Cybersecurity Services (OCSS), the NASA Security Operations Center (SOC), and any Center and local support as needed.
• Cybersecurity and Privacy Oversight Support o Tasks included in this category include assisting Agency and Center personnel in ensuring compliance with NASA policies and Federal mandates, performing risk management and reporting, and interpreting Agency cybersecurity and privacy policy, procedures, and requirements.
• Cybersecurity Standards, Architecture and Engineering o Requirements in this area include assisting NASA in designing and developing cybersecurity architecture and engineering in order to improve the Agency’s cybersecurity posture, take advantage of modern technologies such as cloud, meet Federal requirements, and enhance the user experience.
• Cybersecurity and Privacy Services o This category enables the delivery of effective enterprise cybersecurity and privacy support services. This includes assisting NASA with providing services for continuous monitoring and threat detection, incident response and management, vulnerability management, cyber forensics and analysis, implementation of the National Institute of Standards and Technology (NIST) risk management framework, and cybersecurity posture assessment. Additionally, this category includes cybersecurity infrastructure services, which encompass the delivery of all cybersecurity tools and solutions to support NASA’s implementation of Dynamic Evolving Federal Enterprise Network Defense (DEFEND) from the Department of Homeland Security’s (DHS) Continuous Diagnostics and Mitigation (CDM) Program.
2.0 Contract Management
The Contract Management section includes requirements for program management, financial management, property/inventory management/logistics, Safety, Health and Environmental (SHE) Management, and quality management.
The CyPrESS contract will initially be Cost Plus but NASA intends to convert specific areas of the contract to Firm Fixed Price, if feasible. To that end, the contractor is expected to submit annual Fixed Price Transition plans. NASA will review the submitted Fixed Price Transition Plans and CyPrESS PWS efforts to identify areas which can be converted during the performance of the contract to Fixed Firmed Price.
The Contractor shall align their services and operations processes with the current version of the Information Technology Infrastructure Library (ITIL) to establish common terminology and processes. It is intended that the requirements outlined in the IT Service Management (ITSM) are performed within each service area, rather than as a separate entity. Additionally, the contractor shall comply with other ITSM functions and processes SPECIFICALLY annotated in each Service section of the PWS. ITIL is a commonly accepted information technology Service Management framework that provides a cohesive set of public and private sector best practices which are supported by a comprehensive qualifications scheme, accredited training and certification organizations, and implementation and assessment tools.
The contractor shall utilize the NASA ITSM system, an integrated cloud-based platform which is used by Enterprise IT Services Contractors to track, manage, and fulfill service requests, incident tickets, knowledge items, change requests, and problem tickets, create/run reports, and other processes and activities as defined in the Enterprise contracts. The NASA ITSM System also provides NASA end users with an automated tool to submit and track service requests, incidents, and feedback, take customer satisfaction surveys, search the knowledge base, and run reports.
2.1 Program Management
The Program Management section provides the requirements for cost, schedule, risk and technical management of all CyPrESS services, functions and tasks.
2.1.1 Program Management
The Contractor shall:
• Ensure the implementation of effective systems engineering, business management, and other quality practices to deliver the services in an efficient and integrated manner and at a sustained high level of success
• Implement practices to ensure effective communication of management, technical, quality, financial, and customer satisfaction issues that may arise in the performance of this contract
• Support the execution of the Agency’s established cybersecurity and privacy governance model, processes and policies to ensure well-informed strategy, policy, architecture, standards and investment decisions
• Ensure the implementation of management practices to proactively pursue innovation and technology advancement to enhance customer satisfaction and service delivery
• Apprise the Contracting Officer (CO), Contracting Officer’s Representative (COR) and Senior Agency Information Security Official (SAISO) immediately of any issues that could have an adverse impact on successful performance of the contract requirements
• Manage records in accordance with NASA’s policies and processes
• Measure and report the service level objectives and performance for work defined in each of the sections of this PWS in accordance with DRD MA-025, CyPrESS Monthly Status Review Report
• Align services and operations processes with the current version of the IT Infrastructure Library (ITIL) Framework utilized by the Government and current applicable OCIO policies and procedures, to establish common terminology and processes
• Ensure all staff obtain and maintain the requisite clearance level in accordance with NASA policy and procedures for system, data, or facilities to perform assigned duties when performance starts
• Support the CyPrESS COR on any customers’ issues and resolutions
2.1.2 Documentation Management
The Contractor shall:
• Review the Data Requirement Documentation for the entire list of required documentation and the due date
• Provide, implement and maintain the Contract Management Plan in accordance with Data Requirements Document (DRD) MA-001, Contract Management Plan
• Prepare and submit monthly reports of projects, initiatives and activities in accordance with DRD MA-025, CyPrESS Monthly Status Review Report.
• Prepare and submit a contractor self-assessment report in accordance with DRD MA- 021, Contract Self-Assessment Report
• Prepare and submit an IT Security Management Plan in accordance with DRD MA-003, IT Security Management Plan
• Prepare and submit an Annual Work Plan in accordance with DRD MA-018, Annual Work Plan
• Submit annual Fixed Price Transition plans starting 1 year after the CyPrESS performance start date, in accordance with DRD MA-022, Fixed Price Transition Plan
2.1.3 Communication
• Prepare and conduct monthly program management reviews, which include but are not limited to, presentations, discussions of program priorities, project statuses, significant accomplishments, risk management, problem areas, etc.
• Track and provide status of official communication with the COR, which includes but is not limited to, technical direction requests for information and transmittals
• Ensure communications in performance of all work under this PWS are professional and accurate, are consistent with the goals of the CSPP, and promote positive working relationships with consumers of CyPrESS solutions and services
2.2 Contract Administration System
NASA’s contract administration system facilitates contract administration and oversight for the CyPrESS contract. The system will be utilized for requesting new work/tasks, revising existing work/tasks, financial planning, technical performance feedback gathering, and as the primary system for communicating financial and funding information. The system allows electronic initiation, receiving, reviews, approvals, issuances and modification of work under this contract.
The Contractor shall:
• Utilize NASA’s contract administration system to manage the contract
• Provide a primary point of contact to engage with NASA’s contract administration system team
2.3 Critical Staffing Positions
The Contractor shall:
• Provide a management staff and structure to efficiently implement the requirements of this
PWS
• Designate a single Point of Contact (POC) with contractual obligation authority for all contract administration functions and activities required in performance of this contract. This POC shall have access to all contract administration data and information related to performance of this contract. Additionally, this POC will function as an onsite Program Manager (PM) who shall have authority over all technical, business, personnel, performance, schedule and cost components of Contractor activities in execution of this PWS
• Recommend and, as approved by the Government, implement and maintain a contractor management structure that establishes responsible contractor POCs for each Center, facility and PWS section, while ensuring appropriate separation of duties for the performance of CyPrESS work
2.4 Financial Management
The Contractor’s work is based on the PWS Core and Indefinite Delivery Indefinite Quantity (IDIQ) services.
The Contractor shall:
• Perform all business and financial functions necessary to fulfill the requirements of this contract and integrate these functions across all areas of performance
• Provide on-going business analysis and respond to requests and inquiries from the Government relating to budget, schedule, Work Year Equivalents (WYEs), cost plans, NASA defined work packages/IDIQ and cost performance
• Prepare and submit all data elements required to produce financial reports, in accordance with DRD MA-020 Monthly Contractor Financial Report (533M) and DRD MA-020 Quarterly Contractor Financial Report (533Q) in NASA’s contract administration system for all PWS elements in this contract
• Assist the Government in the following:
o Preparation of status for customer-funded efforts o Preparation of financial data for business cases o Preparation of Office of Management Budget (OMB) Agency IT Portfolio data collection activities, as needed
• Provide quarterly spend plan vs. actual updates to funding customers with details on current and estimated spend, in accordance with DRD MA-020 Monthly Contractor Financial Report (533M), which includes but is not limited to actual plus/minus (+/-) five (5) percent (%) variance explanations, etc.
2.5 Property/Inventory Management/Logistics
The Contractor shall manage all NASA’s cybersecurity and privacy equipment/property, with which the Contractor has been furnished and/or has acquired on behalf of the Government.
The Contractor shall:
• Perform logistics management functions in accordance with NASA’s policies and processes
• Perform property management functions in accordance with NASA’s policies and processes
• Enter all acquired property into the NASA provided system, as directed by COR
• Prepare and maintain an asset management report
• Perform property custodian and user functions in accordance with NASA’s policies and processes
• Perform all requirements of the NASA’s supply chain risk management (SCRM) process before acquiring equipment
• Utilize NASA’s systems to screen for excess property needed in support of the contract and use resulting components in support of the infrastructure in a cost-effective manner
• Identify excess, obsolete, and end-of-life assets, and initiate disposal in accordance with NASA’s policies and processes
• Ensure all equipment removed from service have all data sanitized prior to excess in accordance with NASA policies and processes
• Utilize NASA property tags process for all existing and new assets
• Establish loan agreements for all Installation Accountable Government Property (IAGP) that will be utilized at off-site locations
• Conduct an annual physical inventory of all equipment and provide results to the NASA COR
• Track all changes, such as locations, disposals, etc., monthly to the NASA COR in the NASA approvedsystem
2.6 Quality Management
The Contractor shall document the planned quality controls in the Quality Management Plan in accordance with DRD QE-001, Quality Management Plan.
2.7 Safety, Health, and Environmental (SHE) Management
The Contractor shall provide, implement, and maintain a comprehensive Safety and Health Plan in accordance with DRD SA-001, Safety and Health Plan.
3.0 Cybersecurity and Privacy Program Management Support
NASA established the Cybersecurity & Privacy Program, headed by the NASA Senior Agency Information Security Official, to develop and implement an Agency-wide cybersecurity vision and strategic direction to serve customers’ needs, appropriately safeguard NASA information and information systems, and ensure compliance with Federal cybersecurity and privacy mandates and NASA policies. The vision of the CSPP is to enable NASA’s success by safeguarding data and IT assets to protect safety, intellectual capital, and privacy. The scope of the CSPP encompasses the entire NASA technology environment, including the mission, corporate, and operational technology (OT)1 domains.
The contractor shall support the management of all aspects of the CSPP. This includes supporting all organizations that manage various components and functions of the CSPP, such as the Cybersecurity and Privacy Division, the Office of Cybersecurity Services, the Security Operations Center, and local Center cybersecurity and privacy functions. Further detail about CSPP management support is provided in this section.
1 Operational technology is defined, per NASA Policy Directive (NPD) 2800.1E, Managing Information Technology, as hardware and software that is physically part of, dedicated to, or essential in real time to the performance, monitoring, or control of physical devices and processes.
3.1 Office of Cybersecurity Services (OCSS) Support
The Office of Cybersecurity Services was established to deliver enterprise cybersecurity services to all NASA organizations and to strengthen NASA’s cybersecurity posture. The OCSS is driven by NASA business and mission needs and leverages industry and IT service management best practices.
Partnerships and collaboration with other NASA organizations and services within the OCIO are key to the success of the OCSS. Below are the guiding principles OCSS aims to deliver:
• Leverage existing services and tools that can benefit the NASA community
• Provide seamless alignment of services that will create mission collaboration and engagement in meeting customer requirements and increase the likelihood for mission success
• Provide broader exposure to NASA OCIO leadership teams, governance boards, and the NASA community so that policies and standards can be enforced and unified across the Agency
3.1.1 Service Management
The Contractor shall:
• Support the overall service management and service delivery functions of the OCSS
• Manage the delivery of all services listed in Section 6.0, Cybersecurity and Privacy Services, of this document and reduce cybersecurity risk
• Provide support to the service owners and associated service elements, which includes, but is not limited to, the development of strategies, roadmaps, or other planning tools to assist in aligning short-term and long-term activities with the Agency’s cybersecurity goals
• Provide the following business management support for each new OCSS Service:
o Service establishment process.
o Development and review of service charter(s).
o Service provider interest, assessment, and assignment process.
• Assist the Government with Service Level Agreement (SLA) and Organizational Level Agreement (OLA) documentation, training, and processes
• Assist the Government with maintaining the OCSS Service Portfolio
• Assist the Government in identifying alternate strategies, service opportunities, and emerging trends by analyzing customer feedback and needs
• Schedule and support regular Service Owners’ meetings
• Assist OCSS to mature service processes in alignment with ITIL best practices
• Support the development and operation of the Continual Service Improvement processes
• Support the financial review and analysis of actual expenses and funding. Assist the
Government with recommendations based on the analysis
• Support the governance, operation, maintenance, and management of a centralized OCSS knowledge repository for artifact storage and access in accordance with NASA’s policies, processes and procedures
• Develop and manage the OCSS services in the NASA service catalog and assure that all requests are assigned, tracked, and managed in an effective manner based on priority
• Provide project management for various OCSS service projects, as assigned, utilizing NASA policies and procedures
• Manage the schedule, delivery, and risks of assigned projects to maximize effectiveness and benefit delivery of assigned projects
• Update the NASA portfolio management tool and other management reporting monthly or as directed by the Government
• Configure, operate, maintain and mature OCSS problem management tracking using the NASA enterprise IT Service Management (ITSM) tool
• Support the disposition and management of Continual Service Improvement submissions using NASA’s established tool
• Support the governance of the Problem Management and Continual Service Improvement
3.1.2 Performance Management
• Monitor metrics and deliverables to ensure that SLAs and OLAs are being met and are reviewed and updated as applicable
• Assist with creating, maintaining, and delivering regular Key Performance Indicators (KPIs) and other scorecard/metric reports on OCSS Performance Management as defined by the Government
• Leverage NASA tool(s) to store, compute, and report on OCSS’s KPIs, Outcomes and Key Results (OKR), and performance management metrics
• Routinely correlate and analyze performance management data to develop recommendations for the Government to improve OCSS’s services and reduce cybersecurity risks
• Provide ongoing reporting to OCSS and CSPP management that includes progress achieved, issues, constraints, and risks
3.1.3 Change Management
• Assist the Government with managing the OCSS Change Management and Governance Processes for the OCSS to minimize the impact of change-related requests to customers and ensure the prompt handling and quality of all changes
• Assist with facilitating the OCSS Change Management Boards/Meetings
• Assist with the development, maintenance, and support of the OCSS Change Management tool(s)
• Develop, deliver, and communicate training and process guide documentation, in coordination with OCSS and CSPP management, for the OCSS Change Management tool(s)
• Report Change Management performance, status, and effectiveness based on defined metrics
3.1.4 Customer Outreach and Communications
• Assist the Government with developing marketing and outreach notifications in accordance with NASA’s policies, procedures and processes
• Assist with engaging NASA consumers of cybersecurity and privacy services to identify and provide business requirements for new and existing services in collaboration with the appropriate NASA organizations
• Support the Government with regular and adhoc engagements within OCSS, CSPD, and with customers and stakeholders
• Conduct Service Offering Reviews on a semi-annual basis for new and existing customers and prepare notifications in accordance with NASA’s policies, procedures and
3.2 Security Operations Center (SOC) Support
NASA’s Security Operations Center is the single, authoritative nerve center for cybersecurity incident monitoring, detection, reporting, response, mitigation, and prevention, and for cyber threat analysis for the Agency. Its purview includes all NASA networks and systems across the mission, corporate, and operational technology (OT) domains. The NASA SOC provides real-time, continuous cybersecurity monitoring and triage, uninterrupted event detection, incident analysis, coordination and response, situational awareness, and cybersecurity countermeasure implementation capabilities for maintaining a secure cybersecurity and information assurance posture. The NASA SOC has the authority to implement mitigation actions, in coordination with other enterprise IT services and local system administrators, in order to reduce the Agency’s exposure to cybersecurity threats and incidents. Furthermore, the SOC provides incident data, reporting on the exposure of sensitive information, and threat indicators to the Department of Homeland Security's National Cybersecurity and Communications Integration Center (NCCIC).
The NASA SOC provides continuous operations, from multiple distributed operation sites, twenty-four hours a day, seven days a week, three hundred sixty-five days a year (24/7/365). Each distributed operations site is designed with operational capabilities to maintain security operations services when another operations site is degraded or disabled for varying reasons or lengths of time.
The SOC includes a geographically dispersed team of technicians located across NASA locations identified in Section 1.2, Principal CyPrESS Stakeholders and Places of Performance.
The SOC is the first point of contact and customer service interface for anything related to cybersecurity incidents or threats. It receives incident management service requests through all accessible communication channels and utilizes an enterprise solution (Incident Management System) to track and monitor cybersecurity incidents, related requests, and actions. The SOC communicates through a variety of customer channels (currently, telephone, email, and web inquiries) to provide guidance, support, and resolve cyber incidents in a timely manner. The SOC is responsible for responding to, prioritizing, and coordinating resolution of cyber incidents and service requests. The SOC provides support for mission applications, first call resolution for SOC service requests, and dispatch-ready cyber incident response teams to assist NASA personnel. The SOC provides remote support as well as onsite support.
The NASA SOC is organized into three strategic areas, which work together to provide cybersecurity functions and services to the NASA enterprise:
1. The NASA SOC Watch is comprised of the Agency Senior Watch Officer (SWO), Agency Watch Officers (WO), Monitoring and Detection (M&D) team, and Triage team.
2. Agency Incident Response Management (AIRM) is comprised of the Agency Incident Response Manager (IRM) and SOC Incident Response Teams (IRT).
3. Cyber Threat Hunt is comprised of the Cyber Threat Analysis (CTA) team, Cyber Forensics and Incident Analysis (CFIA) team, and Cyber Threat Detection (CTD) and Intrusion Analysis team.
The SOC provides the following services to all NASA organizations, frequently in collaboration and coordination with Center and organizational service providers and partners:
• Continuous Monitoring and Detection (M&D) and Triage
• Incident Response and Management
• Cyber Forensics and Incident Analysis
• Cyber Threat Detection and Hunt
• Cyber Threat Analysis.
This section details the technical requirements related to supporting the management and operations of the NASA SOC. Requirements related to delivery of specific SOC services are stated below in Section 6.0, Cybersecurity and Privacy Services.
The Contractor shall:
• Support the 24/7/365 operations of the NASA SOC and overall service delivery of SOC services to
NASA
• Maintain 24/7/365 staffing on premises at the NASA SOC Distributed Operating Sites (in accordance with the locations identified in Section 1.2, Principal CyPrESS Stakeholders and Places of Performance) to support the strategic areas of NASA SOC Watch and Agency Incident Response Management
• Maintain on premise coverage at the NASA SOC Distributed Operating Sites during the designated core hours, after hours support on call, and respond on premise within 2 hours of notification to support the Cyber Threat Hunt strategic area
• Balance 24/7/365 workload, staffing, and coverage between the designated NASA SOC Distributed Operations Sites to ensure business continuity of the NASA SOC.
• Provide 100% coverage for the NASA SOC Watch and AIRM for an initial 24 hours of unscheduled outage and 50% coverage for the NASA SOC Watch and AIRM beyond the initial 24 hours of any unscheduled outage from either distributed operation site. If one distributed location suffers an unscheduled or unplanned outage that affects the operational capabilities of that one location, the other distributed operations site must be able sustain 100% of workload of both locations for a duration of 24 hours and then a diminished sustainment of 50% of workload for the remaining duration of a single site outage.
• Ensure all staff supporting the NASA SOC obtain and maintain the requisite clearance level in accordance with NASA policy and procedures for system, data, or facilities to perform assigned duties when performance starts
• Ensure all staff supporting the Cyber Threat Hunt strategic area obtain and maintain an active TS/SCI clearance in accordance with NASA policy and procedures for system, data, or facilities to perform assigned duties when performance starts.
• Ensure a minimum coverage per shift at each NASA SOC Distributed Operating Site with an active TS/SCI clearance
• Ensure the appropriate staff have access to the National Security System (NSS) Secret systems, physical space(s) designated by the Government, which includes but is not limited to, access to voice/data workstations/devices, maintain active user and email accounts, and access to physical safes in those designated space(s)
• Ensure a minimum coverage per shift at each NASA SOC Distributed Operating Site have access to the NASA Intelligence Network (NIN) systems, Top Secret physical space(s),access to voice/data workstations/devices, maintain active user and email accounts, and access to physical safes in those designated space(s). Minimum coverage per shift per location must possess a TS/SCI clearance with access.
• Provide real-time response to requests for emergency web site blocking/unblocking upon receipt of notification from authorized IT Security Office personnel in accordance with relevant service level agreements
• Support the development and dissemination of enterprise communications products and strategic reporting from the SOC in accordance with NASA’s policies, procedures and processes
• Develop, update and maintain the Standard Operating Procedures (SOP) for each strategic area and function of the SOC
• Support the identification of requirements for infrastructure and tools used by the SOC. This may include participating in requirements development meetings, evaluating software on a SOC analyst workstation, and providing feedback
• Assist in system and service restoration of SOC infrastructure and tools by conducting end-user validation checks after any maintenance or emergency restoration actions performed by a service provider
• In support of service restoration after an interruption, ensure that data is updating, full functionality is restored on SOC analyst workstations, and information is reachable from the system or service that was interrupted
• Execute commands as needed to update information within the SOC environment to ensure systems and/or services have been restored
• Provide customers a self-help capability, such as the SOC intranet site, and continually enhance self-service capabilities to reduce SOC service requests in accordance with NASA’s policies, procedures and processes
• Document and track call metrics, service request/resolutions, and analyze trends to implement measures that prevent recurring problems and improve customer experience. Trend analysis and reporting shall be customized based on the request of the Government (may request details on the type of technical issue, location, tier, etc.).
• Provide a weekly status report on all call and service metrics
• Provide internal SOC training and knowledge transfer as required
• Participate in exercises, as requested by the Government, to test and strengthen NASA’s cybersecurity posture, processes and tools
3.3 CSPP Business Management
The contractor shall support various business management functions of the enterprise Cybersecurity and Privacy Program. This support is required at the Agency level by the Cybersecurity and Privacy Division, at each Center by local cybersecurity and privacy representatives such as Center Chief Information Security Officers, and by other CSPP organizations such as the OCSS, SOC and service provider organizations. While this section focuses on the requirements of the CSPD front office, similar support will be required by the other CSPP organizations listed in the previous sentence. The contractor shall also collaborate with other services within the NASA OCIO.
• Assist with and provide recommendations for the organization, execution and continuous improvement of the NASA Cybersecurity and Privacy Program
• Support the development of integrated cybersecurity and privacy strategies, roadmaps, tactical plans, touch points, and dependencies between CSPP, other IT service lines, and NASA mission or institutional activities
• Support the development and continuous improvement of a portfolio management approach in order to ensure that CSPP Projects, Initiatives, and Activities are managed and resourced effectively to achieve the intended outcomes; to enable CSPP to demonstrate and clearly communicate the value that the CSPP brings to NASA; to drive effective and consistent prioritization and decision making; and to manage program and cybersecurity risks effectively and transparently
• Support the execution of CSPP portfolio management processes
• Support cybersecurity and privacy related data calls, including the design and communication of data calls, collection of data, consolidation and analysis of responses, and reporting of results
• Support NASA’s quarterly and annual reporting, as required by the Federal Information Security
Modernization Act (FISMA)
• Develop and propose innovative strategies to improve NASA’s FISMA compliance and outreach campaigns in accordance with NASA’s outreach policies, procedures and processes
• Assist with the development and implementation of automating FISMA reporting across the cybersecurity services areas
• Assist with development of a strategy for cybersecurity and privacy knowledge management
• Support the Government in managing audits from the Office of Inspector General (OIG), Government Accountability Office (GAO), and other external reviewers. This includes coordinating with auditors; responding to questions and data calls in preparation for audits and during the course of audits; reviewing audit findings and providing recommendations for NASA’s response; tracking audit findings, recommendations and completion of responses; and supporting the Government in completing audit-related actions
• Support the continuous maturation of CSPP governance and its integration within the NASA IT governance model
• Assist the Government with proactively and regularly identifying opportunities to improve service and technology integration among all cybersecurity and privacy functions and services, with other OCIO IT service lines and Program Offices, and with external stakeholders
• Support the operation of CSPP governance bodies and working groups, such as the Cybersecurity and Privacy Program Management Board (CSPPMB), the IT Security Management Board (ITSMB), etc.
• Provide administrative support, sufficiently knowledgeable in the subject matter, for cybersecurity and privacy meetings, working groups, etc., including but not limited to developing and distributing agendas, managing meetings, developing and distributing minutes, action tracking and follow-up
• Ensure communications are professional, consistent, and support a positive group identity to effectively advertise and promote the technical standards and work products as established
• Provide assistance with document development and formal document review preparation, and presentation development and preparation. This includes, but is not limited to, formal and informal communication plans and training materials to inform OCIO management, Center and Mission personnel, and various decision boards about cybersecurity operations, status, project deliverables, issues, and other relevant topics
• Assist the Government with improving SLAs/Service Delivery Metrics and OLAs, including but not limited to availability of service, return to service, and new service requests metrics
• Support the development and maintenance of workflows in the NASA Account Management System, as requested, to ensure that access to all NASA IT assets is managed according to Agency policies and procedures
• Develop special studies, as requested, e.g., trade studies, feasibility studies, trend analyses, business cases, etc.
3.4 Policy Management
NASA manages all policies on cybersecurity, privacy and Controlled Unclassified Information (CUI) at the Agency level, including NASA Policy Directives (NPD), NASA Procedural Requirements (NPR), Handbooks, Standard Operating Procedures (SOP), policy memoranda, and other guidance documents. The scope of these policies includes all NASA information, NASA and partner information systems, and OT.
The Contractor shall support NASA’s cybersecurity, privacy, and CUI policy management activities, which includes, but is not limited to, cultivating relationships and interfacing with various Government officials and partners to promote the advancement of new policies and guidance.
The Contractor shall:
• Support NASA in cybersecurity, privacy and CUI policy lifecycle management, including policy development, review, maintenance, communications, and governance of NPDs, NPRs, handbooks, and other policy documents
• Review and assess the Agency’s current policies and procedures to determine any gaps or duplication, and the level of compliance with Federal mandates regarding cybersecurity, privacy and CUI, including FISMA and other relevant statutes, current and relevant Office of Management and Budget (OMB) Memoranda, Department of Homeland Security policy and program guidance, and National Institute of Standards and Technology guidance
• Provide recommendations regarding updates and changes to cybersecurity policies and procedures to ensure ongoing compliance with Federal mandates and NASA policy needs
• As directed by the Government, update and maintain NASA policies
• Continuously update NASA websites with the latest version of all policies and interim directives
• Provide outreach, FAQs, and other communications, in accordance with NASA’s outreach policies, procedures and processes, on new or updated policies to NASA through a variety of mechanisms
• Maintain expertise in all NASA cybersecurity, privacy, and CUI policies and provide support in researching and supporting applicable policies
• Support the development and update of NASA cybersecurity, privacy, and CUI policy management processes
• Support NASA in coordinating and managing the review, comment disposition, and governance of new or updated policies to result in approval or rejection of proposed policy changes
• Communicate directly with NASA customers (including security officials, security analysts, mission stakeholders, managers, etc.) to solicit and address feedback regarding new policies and policy revisions
• Coordinate and conduct the review of new or changed policies through NASA legal and union representatives
• Develop recommendations on how to address comments, edits, and questions from policy reviews and ensure that review dispositions are clearly documented and communicated
• Review and assess relevant NASA policies, procedures, standards, handbooks, and other applicable documents to identify gaps related to the cybersecurity of OT, including assessment & authorization (A&A) of OT systems
• Provide recommendations to address policy and process gaps identified and associated with the A&A for NASA OT systems in accordance with Federal guidance such as NIST Special Publication (SP) 800-37. The contractor shall focus on gaps related to minimum network architecture requirements, industry best practices, and emerging requirements for OT systems
3.5 Privacy Management Support
Protecting all of NASA’s sensitive information is a high priority. The technical requirements in this section support the NASA Agency Chief Privacy Officer (CPO) and the Center Privacy Managers
(CPM).
The Contractor shall:
• Assist NASA organizations in understanding and interpreting NASA policy and procedures relative to privacy
• Assist NASA in implementing privacy information protection in accordance with NASA policies and Federal mandates
• Assist NASA Breach Response Teams (BRT), as needed per NASA policies and procedures
• Support the NASA CPMs and other stakeholders in all privacy related aspects, including but not limited to, interpretation of privacy guidance; supporting BRTs, supporting annual review and reduce activities; assisting, reviewing and finalizing privacy documentation in the approved NASA system security plan repository; ITAR/EAR, etc.
• Develop reports and respond to Federal privacy inquiries at the direction of the Government
• Implement and validate the privacy requirements as defined in NASA policies
• Scan, analyze and report findings to the Government
3.6 Controlled Unclassified Information (CUI) Management Support Controlled Unclassified Information is defined in 32 CFR Part 2002. The NASA CUI program standardizes how sensitive information is marked, handled and shared, while the ensuring the information remains appropriately protected across the Agency.
• Support the NASA Agency CPO and CUI Liaisons with the transition of NASA requirements, procedures, processes and solutions for Sensitive But Unclassified (SBU) information to CUI based on Federal mandates and requirements
• Respond to CUI inquiries and develop self-inspection reports at the direction of the government
• Provide the Agency OCIO with subject matter expertise that can support the CUI roadmap implementation
• Develop and provide communications and outreach material in accordance with NASA’s outreach policies, procedures and processes
• Develop required annual reports based on the Federal mandates and guidelines
• Recommend and draft enterprise policy and procedures, in coordination with the NASA CSPP
• Ensure appropriate banner markings are labeled on CUI documents
• Store and maintain the documentation in the NASA repository
3.7 Cybersecurity and Privacy Risk Management Support
The contractor shall support the Cybersecurity and Privacy Program in developing, managing and communicating the NASA Agency strategy, frameworks, processes, requirements and solutions for cybersecurity and privacy risk management across all tiers, per NIST SP 800-39 (Tier 1 = Organization, Tier 2 = Mission/Business Processes, Tier 3 = Information Systems), as described in this section and its subsections. Requirements for supporting the implementation of risk management processes, practices and solutions are described in other sections of this PWS, e.g. in Section 6.0, Cybersecurity and Privacy Services.
3.7.1 Risk Management Strategy
The requirements in this subsection relate to cybersecurity and privacy risk management at Tiers 1 and 2, and to ensuring that risks identified at lower tiers are communicated appropriately and managed holistically across the NASA enterprise.
The Contractor shall:
• Support NASA’s objective of achieving a comprehensive, organization-wide approach to cybersecurity and privacy risk management in alignment with the following NIST publications:
o SP 800-39 – Managing Information Security Risk o SP 800-37 – Risk Management Framework for Information Systems and
Organizations o SP 800-30 – Guide for Conducting Risk Assessments o NIST Interagency Report 8286 – Integrating Cybersecurity and Enterprise Risk
Management
• Support the Government in ensuring that cybersecurity and privacy risk management is consistent throughout the Agency, reflects organizational risk tolerance, and is considered along with other types of risk to ensure mission/business success, and that risk-related considerations for information systems (including authorization decisions) are viewed from an Agency-wide perspective in alignment with an Agency-level Cybersecurity Risk Management Strategy
• Maintain the Agency-level Cybersecurity Risk Management Strategy and recommend updates to facilitate implementation as needed
• Coordinate the design and implementation of practices that assess, quantify, and articulate the relevance of cybersecurity and privacy risk and stay abreast of current risk management methodologies and models
• Review and recommend updates to the Agency’s risk taxonomy, register, and policies on a regular basis
• Track technology trends and other factors in order to recommend, develop, and implement innovative risk management processes, procedures, tools, and mechanisms that help improve and advance the Agency’s cybersecurity posture.
• Design, create, and assess reports addressing organizational performance and maturity against various aspects of the NIST Cybersecurity Framework
• Recommend, develop, and implement processes, procedures, tools, and mechanisms to identify, report, and improve cybersecurity and privacy performance metrics that fall below established thresholds
• Recommend and draft training materials and…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .