Attachment A - Performance Work Statement.pdf

PDF 1009 KB Posted

Attached to
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
Solicitation number
80TECH21R0007
Issued by
National Aeronautics and Space Administration

About this file

This document outlines a forthcoming federal contract opportunity for Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) from the National Aeronautics and Space Administration (NASA). The contract will provide cybersecurity and privacy program management support, oversight support, standards and engineering, and services. Key details include:

  • The solicitation is expected to be released in Q2 2021 as a full and open competition with a single award cost-plus-award-fee contract including both cost reimbursable and firm fixed price elements.

  • Services will cover all NASA centers and facilities and include areas such as program management, risk management, architecture, operations, and more.

  • The base period is 20 months with four 24-month option periods and a final 12-month option period.

  • A facility security clearance at the Top Secret level will be required.

  • The North American Industry Classification System (NAICS) code is 541519 with a small business size standard of $30 million.

  • Questions on the forthcoming draft RFP should be directed to the point of contact by email only.

  • Potential offerors should monitor the beta.SAM.gov website for release of the solicitation and amendments.

View the file

Other files for this federal contract opportunity

Other files attached to Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS), newest first.
File Type Posted
CyPrESS DRFP Questions and Answers.pdf PDF
Industry Day - CyPrESS April 19 2021.pdf PDF
NASA Industry Day -Registered CyPrESS Attendees.xlsx XLSX spreadsheet
Exhibits 20-22.xlsx XLSX spreadsheet
CyPrESS Industry Day Registration.pdf PDF
Draft Request for Proposals 80TECH21R0007 (CyPrESS).pdf PDF
Historical Data - NICS Contract - Performance Work Statement.pdf PDF
Historical Data - Historical Metrics.pdf PDF
Historical Data - HQ - HITSS_III_RFP_Attach._A_-PWS Page 295.pdf PDF
Historical Data - GSFC GITISS - NNG16VU01C.pdf PDF
Historical Data - SSC PWS.pdf PDF
Historical Data - Estimated Historical Labor.pdf PDF
Historical Data - MITS II-pws section 3.pdf PDF
Historical Data - GSFC SES II - NNG15CR67C.pdf PDF
Attachment E - Attachment 2 to DD Form 254_SBU_20210125 DRAFT.pdf PDF
Attachment I - IAGP.pdf PDF
Enclosure EE CyPrESS Labor Categories.xlsx XLSX spreadsheet
Enclosure DD - GPM-Specified Non-Mgmt DL Categories - DL Hours and PDs Enclosure.pdf PDF
Exhibit 23 PastPerfQues.pdf PDF
Attachment Q - Fixed Price Rate Matrix.pdf PDF
Attachment J - OCI Avoidance Plan Cover Page.pdf PDF
Attachment F - Personal Identiy Verification (PIV) Card Issuance Procedures.pdf PDF
Attachment E - DD Form 254 Cover Page.pdf PDF
Attachment B - Applicable Documents List.pdf PDF
Exhibits 20-22.pdf PDF
Enclosure BB - CyPrESS CPAF PEP Core Plus IDIQ Services.pdf PDF
Exhibits 1A-1C.xlsx XLSX spreadsheet
Attachment H - Small Business Subcontracting Plan Cover Page.pdf PDF
Attachment E - DD Form 254 Contract Security Classification Specification.pdf PDF
80TECH21R0007 (CyPrESS) Draft Request For Proposals.pdf PDF
Enclosure CC - Cover Page.pdf PDF
Attachment P - DIRECT LABOR RATES AND INDIRECT RATES AND FEE MATRICES.pdf PDF
Attachment O - Wage Determinations.pdf PDF
Attachment O - Wage Determinations Cover Page.pdf PDF
Attachment N - Phase-in Plan Cover Page.pdf PDF
Attachment I - Installation Accountable Government Property (IAGP) Cover Page.pdf PDF
Enclosure CC - IT Security Management Plan Template.pdf PDF
Enclosure AA - Quality Assurance Surveillance Plan (QASP).pdf PDF
Exhibits 2-19.xlsx XLSX spreadsheet
Attachment L - IT Security Management Plan Cover Page.pdf PDF
Attachment K - Contract Management Plan Cover Page - Copy.pdf PDF
Attachment G - Safety and Health Plan Cover Page.pdf PDF
Attachment E - Attachment 1 to DD Form 254_20210125 DRAFT.pdf PDF
Attachment D - Financial Management Reporting.pdf PDF
Attachment C - Data Requirements Descriptions.pdf PDF
Show all 45

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CyPrESS 80TECH21R0007

Table of Contents

1.0 Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS)

1.1 Introduction and Overview

1.2 Principal CyPrESS Stakeholders and Places of Performance

1.3 Center Transition

1.4 Goals and Objectives

1.5 PWS Overview

2.0 Contract Management

2.1 Program Management

2.2 Contract Administration System

2.3 Critical Staffing Positions

2.4 Financial Management

2.5 Property/Inventory Management/Logistics

2.6 Quality Management

2.7 Safety, Health, and Environmental (SHE) Management

3.0 Cybersecurity and Privacy Program Management Support

3.1 Office of Cybersecurity Services (OCSS) Support

3.2 Security Operations Center (SOC) Support

3.3 CSPP Business Management

3.4 Policy Management

3.5 Privacy Management Support

3.6 Controlled Unclassified Information (CUI) Management Support

3.7 Cybersecurity and Privacy Risk Management Support

3.7.1 Risk Management Strategy

3.7.2 Governance, Risk and Compliance Management

3.7.3 Vulnerability Management

4.0 Cybersecurity and Privacy Oversight Support

5.0 Cybersecurity Standards, Architecture and Engineering

5.1 Cybersecurity Standards and Architecture

5.2 Identity, Credential and Access Management (ICAM) Engineering

5.3 Applications Engineering

5.4 Cloud Engineering

5.5 Cybersecurity Network Engineering and Design Support

5.6 Operational, Research and Test Environments Support

5.7 Project Management and Technical Reviews

6.0 Cybersecurity and Privacy Services

6.1 Continuous Monitoring and Detection (M&D) and Triage

6.2 Incident Response and Management

6.3 Cyber Forensics and Incident Analysis

6.4 Cyber Threat Detection and Hunt

6.5 Cyber Threat Analysis

6.6 Cybersecurity Infrastructure Services

6.7 Training and Awareness

6.8 Supply Chain Risk Management (SCRM) Support

6.9 Risk Management Framework (RMF) Services

6.9.1 Independent Assessment Services

6.9.2 Assessment & Authorization (A&A) Services

6.9.3 Information System Security Official (ISSO) Services

6.10 Cybersecurity Posture Assessment Services

6.10.1 Cybersecurity Scanning and Vulnerability Detection

6.10.2 Cyber Hygiene Management

6.10.3 In-Depth Cybersecurity Technical Assessments

6.10.4 High Value Asset (HVA) Assessment

6.10.5 Penetration Testing

6.10.6 Social Engineering Assessments

6.10.7 Cybersecurity Incident Response Assessments

1.4 Goals and Objectives

The CSPP developed a Cybersecurity Strategy for NASA, comprised of high-level program goals and strategic objectives and sub-objectives. This strategy supports, and is in direct alignment with, the NASA IT Strategic Plan. The CSPP goals are the following:

• Partnership & Communication: Strengthen relationship and visibility with partners across the Agency and promote cybersecurity best practices and awareness

• Service Delivery: Deliver effective cybersecurity services consistently across the Agency

• Risk Management: Manage cybersecurity risks in a standardized way that maps to Agency risk management framework and informs better risk-based decisions

• Cybersecurity Architecture: Develop Agency-wide security architecture to manage complexity while meeting strategic goals

• Cybersecurity Operations: Develop comprehensive security operations capability to prevent and mitigate impact from threats and improve incident response

1.5 PWS Overview

The Performance Work Statement (PWS) addresses NASA’s core requirements for CyPrESS. The Contractor shall serve as the primary provider of cybersecurity and privacy capabilities through the implementation of the CyPrESS PWS. Prior to beginning work on the contract, the Contractor shall ensure that all employees have completed the required background checks, approvals, and clearance requirements for access to worksites (see Section 1.2) according to directives and policies of the requesting organizations.

Performance under this contract will require some positions at the Secret and Top Secret clearance for access to and/or generation of classified information, work in a security area, or both.

Additionally, some positions under this contract will require personnel with access to Top Secret Sensitive Compartmented Information (SCI).

The PWS consists of work divided into the following sections:

• Contract Management o The requirements in this section include Program Management, Contract Administration System, Financial Management, Property/Inventory Management/Logistics, Quality Assurance and Management, and Safety, Health & Environmental Management .

• Cybersecurity and Privacy Program Management Support o The work contained in this category includes providing support for the operations, business management, and policy created and maintained by the Cybersecurity and Privacy Division, the NASA Office of Cybersecurity Services (OCSS), the NASA Security Operations Center (SOC), and any Center and local support as needed.

• Cybersecurity and Privacy Oversight Support o Tasks included in this category include assisting Agency and Center personnel in ensuring compliance with NASA policies and Federal mandates, performing risk management and reporting, and interpreting Agency cybersecurity and privacy policy, procedures, and requirements.

• Cybersecurity Standards, Architecture and Engineering o Requirements in this area include assisting NASA in designing and developing cybersecurity architecture and engineering in order to improve the Agency’s cybersecurity posture, take advantage of modern technologies such as cloud, meet Federal requirements, and enhance the user experience.

• Cybersecurity and Privacy Services o This category enables the delivery of effective enterprise cybersecurity and privacy support services. This includes assisting NASA with providing services for continuous monitoring and threat detection, incident response and management, vulnerability management, cyber forensics and analysis, implementation of the National Institute of Standards and Technology (NIST) risk management framework, and cybersecurity posture assessment. Additionally, this category includes cybersecurity infrastructure services, which encompass the delivery of all cybersecurity tools and solutions to support NASA’s implementation of Dynamic Evolving Federal Enterprise Network Defense (DEFEND) from the Department of Homeland Security’s (DHS) Continuous Diagnostics and Mitigation (CDM) Program.

2.0 Contract Management

The Contract Management section includes requirements for program management, financial management, property/inventory management/logistics, Safety, Health and Environmental (SHE) Management, and quality management.

The CyPrESS contract will initially be Cost Plus but NASA intends to convert specific areas of the contract to Firm Fixed Price, if feasible. To that end, the contractor is expected to submit annual Fixed Price Transition plans. NASA will review the submitted Fixed Price Transition Plans and CyPrESS PWS efforts to identify areas which can be converted during the performance of the contract to Fixed Firmed Price.

2.1 Program Management

The Program Management section provides the requirements for cost, schedule, risk and technical management of all CyPrESS services, functions and tasks.

The Contractor shall:

• Ensure the implementation of effective systems engineering, business management, and other quality practices to deliver the services in an efficient and integrated manner and at a sustained high level of success

• Implement practices to ensure effective communication of management, technical, quality, financial, and customer satisfaction issues that may arise in the performance of this contract

• Support the execution of the Agency’s established cybersecurity and privacy governance model, processes and policies to ensure well-informed strategy, policy, architecture, standards and investment decisions

• Ensure the implementation of management practices to proactively pursue innovation and technology advancement to enhance customer satisfaction and service delivery

• Apprise the Contracting Officer (CO), Contracting Officer’s Representative (COR) and Senior Agency Information Security Official (SAISO) immediately of any issues that could have an adverse impact on successful performance of the contract requirements

• Provide, implement and maintain the Contract Management Plan in accordance with Data Requirements Document (DRD) MA-001, Contract Management Plan

• Manage records in accordance with NASA’s policies and processes

• Prepare and submit monthly reports of projects, initiatives and activities in accordance with DRD

MA-025, CyPrESS Monthly Status Review Report.

• Prepare and conduct monthly program management reviews, which include but are not limited to, presentations, discussions of program priorities, project statuses, significant accomplishments, risk management, problem areas, etc.

• Track and provide status of official communication with the COR, which includes but is not limited to, technical direction requests for information and transmittals

• Measure and report the service level objectives and performance for work defined in each of the sections of this PWS in accordance with DRD MA-025, CyPrESS Monthly Staus Review Report

• Prepare and submit a contractor self-assessment report in accordance with DRD MA-021, Contract Self-Assessment Report

• Submit annual Fixed Price Transition plans, starting 1 year after the CyPrESS performance start date, in accordance with DRD MA-022, Fixed Price Transition Plan

• Align services and operations processes with the current version of the IT Infrastructure Library (ITIL) Framework utilized by the Government and current applicable OCIO policies and procedures, to establish common terminology and processes

• Support the CyPrESS COR on any customers’ issues and resolutions

• Ensure communications in performance of all work under this PWS are professional and accurate, are consistent with the goals of the CSPP, and promote positive working relationships with consumers of CyPrESS solutions and services

2.2 Contract Administration System

NASA’s contract administration system facilitates contract administration and oversight for the CyPrESS contract. The system will be utilized for requesting new work/tasks, revising existing work/tasks, financial planning, technical performance feedback gathering, and as the primary system for communicating financial and funding information. The system allows electronic initiation, receiving, reviews, approvals, issuances and modification of work under this contract.

The Contractor shall:

• Utilize NASA’s contract administration system to manage the contract

• Assist the Government with configuring the system through the lifecycle of the contract, which includes but is not limited to, transitioning each Center to the system, ensuring the system is configured during the transition period, etc.

• Provide a primary point of contact for managing the contract management system

2.3 Critical Staffing Positions

The Contractor shall:

• Provide a management staff and structure to efficiently implement the requirements of this

PWS

• Designate a single Point of Contact (POC) with contractual obligation authority for all contract administration functions and activities required in performance of this contract. This POC shall have access to all contract administration data and information related to performance of this contract. Additionally, this POC will function as an onsite Program Manager (PM) who shall have authority over all technical, business, personnel, performance, schedule and cost components of Contractor activities in execution of this PWS

• Recommend and, as approved by the Government, implement and maintain a contractor management structure that establishes responsible contractor POCs for each Center, facility and PWS section, while ensuring appropriate separation of duties for the performance of CyPrESS work

2.4 Financial Management

The Contractor’s work is based on the PWS Core and Indefinite Delivery Indefinite Quantity (IDIQ) services.

The Contractor shall:

• Perform all business and financial functions necessary to fulfill the requirements of this contract and integrate these functions across all areas of performance

• Provide on-going business analysis and respond to requests and inquiries from the Government relating to budget, schedule, Work Year Equivalents (WYEs), cost plans, NASA defined work packages/IDIQ and cost performance

• Prepare and submit all data elements required to produce financial reports, in accordance with DRD MA-020 Monthly Contractor Financial Report (533M), DRD MA-020 Quarterly Contractor Financial Report (533Q) if not waived, DRD MA-029 WYE Report, and DRD MA-018 Cost Reports in NASA’s contract administration system for all PWS elements in this contract

• Assist the Government in the following:

o Preparation of status for customer-funded efforts.

o Preparation of financial data for business cases.

o Preparation of Office of Management Budget (OMB) Agency IT Portfolio data collection activities, as needed.

• Support the Government throughout the NASA Planning, Programming, Budgeting and

Execution (PPBE) process

• Provide quarterly spend plan vs. actual updates to funding customers with details on current and estimated spend, in accordance with DRD MA-018 Cost Reports, which includes but is not limited to actual plus/minus (+/-) five (5) percent (%) variance explanations, etc.

2.5 Property/Inventory Management/Logistics

The Contractor shall manage all NASA’s cybersecurity and privacy equipment/property, with which the Contractor has been furnished and/or has acquired on behalf of the Government.

• Perform logistics management functions in accordance with NASA’s policies and processes

• Perform property management functions in accordance with NASA’s policies and processes

• Enter all acquired property into the NASA provided system, as directed by COR

• Prepare and maintain an asset management report

• Perform property custodian and user functions in accordance with NASA’s policies and processes

• Perform all requirements of the NASA’s supply chain risk management (SCRM) process before acquiring equipment

• Utilize NASA’s systems to screen for excess property needed in support of the contract and use resulting components in support of the infrastructure in a cost-effective manner

• Identify excess, obsolete, and end-of-life assets, and initiate disposal in accordance with NASA’s policies and processes

• Ensure all equipment removed from service have all data removed prior to excess in accordance with NASA policies and processes

• Utilize NASA property tags process for all existing and new assets

• Establish loan agreements for all Installation Accountable Government Property (IAGP) that will be utilized at off-site locations

• Conduct an annual physical inventory of all equipment and provide results to the NASA COR

• Track all changes, such as locations, disposals, etc., monthly to the NASA COR in NASA’s system

2.6 Quality Management

The Contractor shall document the planned quality controls in the Quality Management Plan in accordance with DRD QE-001, Quality Management Plan.

2.7 Safety, Health, and Environmental (SHE) Management

The Contractor shall provide, implement, and maintain a comprehensive Safety and Health Plan in accordance with DRD SA-001, Safety and Health Plan.

3.0 Cybersecurity and Privacy Program Management Support

NASA established the Cybersecurity & Privacy Program, headed by the NASA Senior Agency Information Security Official, to develop and implement an Agency-wide cybersecurity vision and strategic direction to serve customers’ needs, appropriately safeguard NASA information and information systems, and ensure compliance with Federal cybersecurity and privacy mandates and NASA policies. The vision of the CSPP is to enable NASA’s success by safeguarding data and IT assets to protect safety, intellectual capital, and privacy. The scope of the CSPP encompasses the entire NASA technology environment, including the mission, corporate, and operational technology (OT)1 domains.

The contractor shall support the management of all aspects of the CSPP. This includes supporting all organizations that manage various components and functions of the CSPP, such as the Cybersecurity

1 Operational technology is defined, per NASA Policy Directive (NPD) 2800.1E, Managing Information Technology, as hardware and software that is physically part of, dedicated to, or essential in real time to the performance, monitoring, or control of physical devices and processes.

and Privacy Division, the Office of Cybersecurity Services, the Security Operations Center, and local Center cybersecurity and privacy functions. Further detail about CSPP management support is provided in this section.

3.1 Office of Cybersecurity Services (OCSS) Support

The Office of Cybersecurity Services was established to deliver enterprise cybersecurity services to all NASA organizations and to strengthen NASA’s cybersecurity posture. The OCSS is driven by NASA business and mission needs and leverages industry and IT service management best practices.

Partnerships and collaboration are key to the success of the OCSS. Below are the guiding principles OCSS aims to deliver:

• Leverage existing services and tools that can benefit the NASA community

• Provide seamless alignment of services that will create mission collaboration and engagement in meeting customer requirements and increase the likelihood for mission success

• Provide broader exposure to NASA OCIO leadership teams, governance boards, and the NASA community so that policies and standards can be enforced and unified across the Agency

The Contractor shall:

• Support the overall service management and service delivery functions of the OCSS

• Help manage the delivery of all services listed in Section 6.0 Cybersecurity and Privacy Services of this document into a cohesive set of services that deliver value to NASA and reduce cybersecurity risk

• Provide support to the service owners and associated service elements, which includes, but is not limited to, the development of strategies, roadmaps, or other planning tools to assist in aligning short-term and long-term activities with the Agency’s cybersecurity goals

• Provide ongoing reporting to OCSS and CSPP management that includes progress achieved, issues, constraints, and risks

• Provide the following business management support for each new OCSS Service:

o Service establishment process.

o Development and review of service charter(s).

o Service provider interest, assessment, and assignment process.

• Assist the Government with managing the OCSS Change Management and Governance Processes for the OCSS to minimize the impact of change-related requests to customers and ensure the prompt handling and quality of all changes

• Assist with facilitating the OCSS Change Management Boards/Meetings

• Assist with the development, maintenance, and support of the OCSS Change Management tool(s)

• Develop, deliver, and communicate training and process guide documentation, in coordination with OCSS and CSPP management, for the OCSS Change Management tool(s)

• Report Change Management performance, status, and effectiveness based on defined metrics

• Assist the Government with developing marketing and outreach notifications

• Assist the Government with maintaining the OCSS Service Portfolio

• Assist with engaging NASA consumers of cybersecurity and privacy services to identify and provide business requirements for new and existing services

• Support the Government with regular, e.g., weekly, engagements within OCSS, CSPD, and with customers and stakeholders

• Assist the Government with Service Level Agreement (SLA) and Organizational Level Agreement (OLA) documentation, training, and processes

• Monitor metrics and deliverables to ensure that SLAs and OLAs are being met and are reviewed and updated as applicable

• Assist with creating, maintaining, and delivering regular Key Performance Indicators (KPIs) and other scorecard/metric reports on OCSS Performance Management as defined by the Government

• Leverage NASA tool(s) to store, compute, and report on OCSS’s KPIs, Outcomes and Key Results (OKR), and performance management metrics

• Routinely correlate and analyze performance management data to develop recommendations for the Government to improve OCSS’s services and reduce cybersecurity risks

• Assist the Government in identifying alternate strategies, service opportunities, and emerging trends by analyzing customer feedback and needs

• Conduct Service Offering Reviews on a semi-annual basis for new and existing customers

• Assist with engaging customers to gather requirements

• Schedule and support regular Service Owners’ meetings

• Assist OCSS to mature service processes in alignment with ITIL best practices

• Support the development and operation of the Continual Service Improvement processes

• Configure, operate, maintain and mature OCSS problem management tracking using the NASA enterprise IT Service Management (ITSM) tool

• Support the disposition and management of Continual Service Improvement submissions using

NASA’s established tool

• Support the governance of the Problem Management and Continual Service Improvement processes

• Support the development and management of the OCSS budget and PPBE submissions to align with CSPP’s requirements, to include response to audits, phasing plan and other financial data calls

• Support the financial review and analysis of actual expenses and funding. Assist the Government with recommendations based on the analysis

• Support the operation, maintenance, and management of a centralized OCSS knowledge repository for artifact storage and access

• Support the governance of the use of the OCSS’s knowledge repository

• Support the development and delivery of OCSS’s services requested from the NASA service catalog

• Manage the OCSS services in the NASA service catalog and assure that all requests are assigned, tracked, and managed in an effective manner based on priority

• Provide project management for various OCSS service projects, as assigned, utilizing NASA policies and procedures

• Manage the schedule, delivery, and risks of assigned projects to maximize effectiveness and benefit delivery of assigned projects

• Update the NASA portfolio management tool and other management reporting monthly or as directed by the Government

3.2 Security Operations Center (SOC) Support

NASA’s Security Operations Center is the single, authoritative nerve center for cybersecurity incident monitoring, detection, reporting, response, mitigation, and prevention, and for cyber threat analysis for the Agency. Its purview includes all NASA networks and systems across the mission, corporate, and operational technology (OT) domains. The NASA SOC provides real-time, continuous cybersecurity monitoring and triage, uninterrupted event detection, incident analysis, coordination and response, situational awareness, and cybersecurity countermeasure implementation capabilities for maintaining a secure cybersecurity and information assurance posture. The NASA SOC has the authority to implement mitigation actions, in coordination with other enterprise IT services and local system administrators, in order to reduce the Agency’s exposure to cybersecurity threats and incidents. Furthermore, the SOC provides incident data, reporting on the exposure of sensitive information, and threat indicators to the Department of Homeland Security's National Cybersecurity and Communications Integration Center (NCCIC).

The NASA SOC provides continuous operations, from multiple distributed operation sites, twenty-four hours a day, seven days a week, three hundred sixty-five days a year (24/7/365). Each distributed operations site is designed with operational capabilities to maintain security operations services when another operations site is degraded or disabled for varying reasons or lengths of time.

The SOC includes a geographically dispersed team of technicians located across NASA locations identified in Section 1.2.

The SOC is the first point of contact and customer service interface for anything related to cybersecurity incidents or threats. It receives incident management service requests through all accessible communication channels and utilizes an enterprise solution (Incident Management System) to track and monitor cybersecurity incidents, related requests, and actions. The SOC communicates through a variety of customer channels (currently, telephone, email, and web inquiries) to provide guidance, support, and resolve cyber incidents in a timely manner. The SOC is responsible for responding, prioritizing, and coordinating resolution of cyber incidents and service requests. The SOC provides support for mission applications, first call resolution for SOC service requests, and dispatch-ready cyber incident response teams to assist NASA personnel. The SOC provides remote support as well as onsite support.

The NASA SOC is organized into three strategic areas, which work together to provide cybersecurity functions and services to the NASA enterprise:

1. The NASA SOC Watch is comprised of the Agency Senior Watch Officer (SWO), Agency Watch Officers (WO), Monitoring and Detection (M&D) team, and Triage team.

2. Agency Incident Response Management (AIRM) is comprised of the Agency Incident Response Manager (IRM) and Incident Response Teams (IRT).

3. Cyber Threat Hunt is comprised of the Cyber Threat Analysis (CTA) team, Cyber Forensics and Incident Analysis (CFIA) team, and Cyber Threat Detection (CTD) and Intrusion Analysis team.

The SOC provides the following services to all NASA organizations, frequently in collaboration and coordination with Center and organizational service providers and partners:

• Continuous Monitoring and Detection (M&D) and Triage

• Incident Response and Management

• Cyber Forensics and Incident Analysis

• Cyber Threat Detection and Hunt

• Cyber Threat Analysis.

This section details the technical requirements related to supporting the management and operations of the NASA SOC. Requirements related to delivery of specific SOC services are stated below in Section 6.0 Cybersecurity and Privacy Services.

• Support the 24/7/365 operations of the NASA SOC and overall service delivery of SOC services to

NASA

• Maintain 24/7/365 staffing on premises at the two NASA SOC Distributed Operating Sites (in accordance with the locations identified in Section 1.2) to support the strategic areas of NASA SOC Watch and Agency Incident Response Management

• Maintain on premise coverage at the two NASA SOC Distributed Operating Sites during the designated core hours, after hours support on call, and respond on premise within 2 hours of notification to support the Cyber Threat Hunt strategic area

• Balance 24/7/365 workload, staffing, and coverage between the two designated NASA SOC Distributed Operations Sites to ensure business continuity of the NASA SOC to provide 100% coverage for the NASA SOC Watch and AIRM for an initial 24 hours of unscheduled outage and 50% coverage for the NASA SOC Watch and AIRM beyond the initial 24 hours of any unscheduled outage from either distributed operation site. If one distributed location suffers an unscheduled or unplanned outage that affects the operational capabilities of that one location, the other distributed operations site must be able sustain 100% of workload of both locations for a duration of 24 hours and then a diminished sustainment of 50% of workload for the remaining duration of a single site outage.

• Ensure all staff supporting the NASA SOC obtain and maintain at least a Secret clearance

• Ensure all staff supporting the Cyber Threat Hunt strategic area obtain and maintain an active

TS/SCI clearance

• Ensure a minimum coverage per shift at each NASA SOC Distributed Operating Site with an active TS/SCI clearance

• Ensure all staff have access to the National Security System (NSS) Secret systems, physical space(s), to include access to voice/data workstations/devices, maintain active user and email accounts, and access to physical safes in those designated space(s)

• Ensure a minimum coverage per shift at each NASA SOC Distributed Operating Site have access to the NASA Intelligence Network (NIN) systems, Top Secret physical space(s) to include access to voice/data workstations/devices, maintain active user and email accounts, and access to physical safes in those designated space(s). This explicitly implies at minimum coverage per shift per location must possess an TS/SCI clearance with access.

• Provide real-time response to requests for emergency web site blocking/unblocking upon receipt of notification from authorized IT Security Office personnel in accordance with relevant service level agreements

• Support the development and dissemination of enterprise communications products and strategic reporting from the SOC

• Develop, update and maintain the Standard Operating Procedures (SOP) for each strategic area and function of the SOC

• Support the identification of requirements for infrastructure and tools used by the SOC. This may include participating in requirements development meetings, evaluating software on a SOC analyst workstation, and providing feedback

• Assist in system and service restoration of SOC infrastructure and tools by conducting end-user validation checks after any maintenance or emergency restoration actions performed by a service provider

• In support of service restoration after an interruption, ensure that data is updating, full functionality is restored on SOC analyst workstations, and information is reachable from the system or service that was interrupted

• Execute commands as needed to update information within the SOC environment to ensure systems and/or services have been restored

• Provide customers a self-help capability, such as SOC intranet site, and continually enhance self-service capabilities to reduce SOC service requests

• Document and track call metrics, service request/resolutions, and analyze trends to implement measures that prevent recurring problems and improve customer experience. Trend analysis and reporting shall be customized based on the request of the Government (may request details on the type of technical issue, location, tier, etc.).

• Provide a weekly status report on all call and service metrics

• Provide internal SOC training and knowledge transfer as required

• Participate in exercises, as requested by the Government, to test and strengthen NASA’s cybersecurity posture, processes and tools

3.3 CSPP Business Management

The contractor shall support various business management functions of the enterprise Cybersecurity and Privacy Program. This support is required at the Agency level by the Cybersecurity and Privacy Division, at each Center by local cybersecurity and privacy representatives such as Center Chief Information Security Officers, and by other CSPP organizations such as the OCSS, SOC and service provider organizations. While this section focuses on the requirements of the CSPD front office, similar support will be required by the other CSPP organizations listed in the previous sentence.

The Contractor shall:

• Assist with and provide recommendations for the organization, execution and continuous improvement of the NASA Cybersecurity and Privacy Program

• Support the development of integrated cybersecurity and privacy strategies, roadmaps, tactical plans, touch points, and dependencies between CSPP, other IT service lines, and NASA mission or institutional activities

• Support the management of the CSPP budget throughout the Planning, Programming, Budgeting, and Execution (PPBE) lifecycle

• Perform analysis to optimize resource allocation, including but not limited to identifying areas of investment duplication, quantifying investment gaps, aligning investments to documented risks, and identifying workforce allocation efficiencies

• Support the development and continuous improvement of a portfolio management approach in order to ensure that CSPP Projects, Initiatives, and Activities are managed and resourced effectively to achieve the intended outcomes; to enable CSPP to demonstrate and clearly communicate the value that the CSPP brings to NASA; to drive effective and consistent prioritization and decision making; and to manage program and cybersecurity risks effectively and transparently

• Support the execution of CSPP portfolio management processes

• Support cybersecurity and privacy related data calls, including the design and communication of data calls, collection of data, consolidation and analysis of responses, and reporting of results

• Support NASA’s quarterly and annual reporting, as required by the Federal Information Security

Modernization Act of 2014 (FISMA)

• Develop and propose innovative strategies to improve NASA’s FISMA compliance and outreach campaigns

• Assist with the development and implementation of automating FISMA reporting across the cybersecurity services areas

• Assist with development of a strategy for cybersecurity and privacy knowledge management

• Support the Government in managing audits from the Office of Inspector General (OIG), Government Accountability Office (GAO), and other external reviewers. This includes coordinating with auditors; responding to questions and data calls in preparation for audits and during the course of audits; reviewing audit findings and providing recommendations for NASA’s response; tracking audit findings, recommendations and completion of responses; and supporting the Government in completing audit-related actions

• Support the continuous maturation of CSPP governance and its integration within the NASA IT governance model

• Assist the Government with documenting strategy and approach to proactively and regularly identify opportunities to improve service and technology integration among all cybersecurity and privacy functions and services, with other OCIO IT service lines and Program Offices, and with external stakeholders

• Support the operation of CSPP governance bodies and working groups, such as the Cybersecurity and Privacy Program Management Board (CSPPMB), the IT Security Management Board (ITSMB), etc.

• Provide administrative support, sufficiently knowledgeable in the subject matter, for cybersecurity and privacy meetings, working groups, etc., including but not limited to developing and distributing agendas, managing meetings, developing and distributing minutes, action tracking and follow-up

• Ensure communications are professional, consistent, and support a positive group identity to effectively advertise and promote the technical standards and work products as established

• Provide assistance with document development and formal document review preparation, and presentation development and preparation. This includes, but is not limited to, formal and informal communication plans and training materials to inform OCIO management, Center and Mission personnel, and various decision boards about cybersecurity operations, status, project deliverables, issues, and other relevant topics

• Assist the Government with improving SLAs/Service Delivery Metrics and OLAs, including but not limited to availability of service, return to service, and new service requests metrics

• Support the development and maintenance of workflows in the NASA Account Management System, as requested, to ensure that access to all NASA IT assets is managed according to Agency policies and procedures

• Develop special studies, as requested, e.g., trade studies, feasibility studies, trend analyses, business cases, etc.

3.4 Policy Management

NASA manages all policies on cybersecurity, privacy and Controlled Unclassified Information (CUI) at the Agency level, including NASA Policy Directives (NPD), NASA Procedural Requirements (NPR), Handbooks, Standard Operating Procedures (SOP), policy memoranda, and other guidance documents. The scope of these policies includes all NASA information, NASA and partner information systems, and OT.

The Contractor shall support NASA’s cybersecurity, privacy, and CUI policy management activities, which includes, but is not limited to, cultivating relationships and interfacing with various Government officials and partners to promote the advancement of new policies and guidance.

The Contractor shall:

• Support NASA in cybersecurity, privacy and CUI policy lifecycle management, including policy development, review, maintenance, communications, and governance of NPDs, NPRs, handbooks, and other policy documents

• Review and assess the Agency’s current policies and procedures to determine any gaps or duplication, and the level of compliance with Federal mandates regarding cybersecurity, privacy and CUI, including the Federal Information Security Modernization Act (FISMA) and other relevant statutes, current and relevant Office of Management and Budget (OMB) Memoranda, Department of Homeland Security policy and program guidance, and National Institute of Standards and Technology guidance

• Provide recommendations regarding updates and changes to cybersecurity policies and procedures to ensure ongoing compliance with Federal mandates and NASA policy needs

• As directed by the Government, update and maintain NASA policies

• Continuously update NASA policy tools and websites with the latest version of all policies and interim directives

• Provide outreach, FAQs, and other communications on new or updated policies to NASA through a variety of mechanisms

• Maintain expertise in all NASA cybersecurity, privacy, and CUI policies and provide support in researching and supporting applicable policies

• Support the development and update of NASA cybersecurity, privacy, and CUI policy management processes

• Support NASA in coordinating and managing the review, comment disposition, and governance of new or updated policies to result in approval or rejection of proposed policy changes

• Communicate directly with NASA customers (including security officials, security analysts, mission stakeholders, managers, etc.) to solicit and address feedback regarding new policies and policy revisions

• Coordinate and conduct the review of new or changed policies through NASA legal and union representatives

• Develop recommendations on how to address comments, edits, and questions from policy reviews and ensure that review dispositions are clearly documented and communicated

• Review and assess relevant NASA policies, procedures, standards, handbooks, and other applicable documents to identify gaps related to the cybersecurity of OT, including assessment & authorization (A&A) of OT systems

• Provide recommendations to address policy and process gaps identified and associated with the A&A for NASA OT systems in accordance with Federal guidance such as NIST Special Publication (SP) 800-37. The contractor shall focus on gaps related to minimum network architecture requirements, industry best practices, and emerging requirements for OT systems

3.5 Privacy Management Support

Protecting all of NASA’s sensitive information is a high priority. The technical requirements in this section support the NASA Agency Chief Privacy Officer (CPO) and the Center Privacy Managers

(CPM).

The Contractor shall:

• Assist NASA organizations in understanding and interpreting NASA policy and procedures relative to privacy

• Assist NASA in implementing privacy information protection in accordance with NASA policies and Federal mandates

• Assist NASA Breach Response Teams (BRT), as needed

• Support the NASA CPMs and other stakeholders in all privacy related aspects, including but not limited to, interpretation of privacy guidance, supporting BRTs, supporting annual Review and Reduce activities, reviewing and finalizing privacy documentation in the approved NASA system security plan repository, etc.

• Assist NASA in responding to Federal privacy inquiries and reporting requests

• Assist NASA stakeholders to meet and validate the privacy requirements as defined in NASA policies.

3.6 Controlled Unclassified Information (CUI) Management Support Controlled Unclassified Information is defined in 32 CFR Part 2002. The NASA CUI program standardizes how sensitive information is marked, handled and shared, while the ensuring the information remains appropriately protected across the Agency.

The Contractor shall:

• Support the NASA Agency CPO with the transition of NASA requirements, procedures, processes and solutions for Sensitive But Classified (SBU) information to CUI based on Federal mandates and requirements

• Provide the Agency OCIO with subject matter expertise that can support the CUI roadmap implementation

• Assist with developing and providing communications and outreach material

• Assist with developing required annual reports based on the Federal mandates and guidelines

• Recommend and draft enterprise policy and procedures, in coordination with the NASA CSPP

• Ensure appropriate banner markings are labeled on CUI documents

• Store and maintain the documentation in the NASA repository

3.7 Cybersecurity and Privacy Risk Management Support

The contractor shall support the Cybersecurity and Privacy Program in developing, managing and communicating the NASA Agency strategy, frameworks, processes, requirements and solutions for cybersecurity and privacy risk management across all tiers, per NIST SP 800-39 (Tier 1 = Organization, Tier 2 = Mission/Business Processes, Tier 3 = Information Systems), as described in this section and its subsections. Requirements for supporting the implementation of risk management processes, practices and solutions are described in other sections of this PWS, e.g. in Section 6.0 Cybersecurity and Privacy Services.

3.7.1 Risk Management Strategy

The requirements in this subsection relate to cybersecurity and privacy risk management at Tiers 1 and 2, and to ensuring that risks identified at lower tiers are communicated appropriately and managed holistically across the NASA enterprise.

The Contractor shall:

• Support NASA’s objective of achieving a comprehensive, organization-wide approach to cybersecurity and privacy risk management in alignment with the following NIST publications:

o SP 800-39 – Managing Information Security Risk o SP 800-37 – Risk Management Framework for Information Systems and

Organizations o SP 800-30 – Guide for Conducting Risk Assessments o NIST Interagency Report 8286 – Integrating Cybersecurity and Enterprise Risk

Management

• Support the Government in ensuring that cybersecurity and privacy risk management is consistent throughout the Agency, reflects organizational risk tolerance, and is considered along with other types of risk to ensure mission/business success, and that risk-related considerations for information systems (including authorization decisions) are viewed from an Agency-wide perspective in alignment with an Agency-level Cybersecurity Risk Management Strategy

• Maintain the Agency-level Cybersecurity Risk Management Strategy and recommend updates to facilitate implementation as needed

• Coordinate the design and implementation of practices that assess, quantify, and articulate the relevance of cybersecurity and privacy risk and stay abreast of current risk management methodologies and models

• Review and recommend updates to the Agency’s risk taxonomy, register, and policies on a regular basis

• Track technology trends and other factors in order to recommend, develop, or implement innovative risk management processes, procedures, tools, and mechanisms that help improve and advance the Agency’s cybersecurity posture.

• Design, create, and assess reports addressing organizational performance and maturity against various aspects of the NIST Cybersecurity Framework

• Support performance improvement efforts by recommending, developing, and implementing processes, procedures, tools, and mechanisms to identify, report, and improve cybersecurity and privacy performance metrics that fall below established thresholds

• Recommend and draft training materials and presentations on risk management, in coordination with the NASA Training and Awareness service

• Support and advise on program coordination and integration activities with CSPP stakeholders, Mission Directorate organizations, Mission cybersecurity organizations, inter- Agency risk management communities, OCIO and OCIO Center stakeholders

• Participate in classified and non-classified briefings on cybersecurity threats and related risk information to support risk analysis, as directed by the Government

3.7.2 Governance, Risk and Compliance Management

The CSPP maintains and continues to mature the Agency’s assessment & authorization policy, processes and tools to ensure NASA’s compliance with FISMA and the guidance in the NIST Risk Management Framework (RMF), per NIST SP 800-37 and other 800 series Special Publications.

This section details requirements related to program-level support for cybersecurity and privacy risk management for information systems (Tier 3), while the later Section 6.0 Cybersecurity and Privacy Services contains requirements related to implementation of A&A.

• Assist with the maintenance and ongoing development of an integrated governance framework for NASA’s compliance with the RMF

• Assist in the maturing of the NASA continuous monitoring program, in support of ongoing authorization for information systems, including OT systems

• Assist with creation of guidance for better integration of cybersecurity and privacy risk management into the System Development Life Cycle (SDLC), including through the use of CDM solutions

• Assist in the development of A&A policy and guidance

• Assist with the development of automated frameworks that will enhance the processes needed to conduct compliance assessments of NASA information system authorization packages

• Identify, and provide recommendations to address, any gaps associated with the A&A for NASA OT systems in accordance with NIST SP 800 series guidance and NASA requirements

• Provide recommendations on security control requirements, baselines, and criticality ratings applicable to all systems designated as OT

• Provide analysis of impacts of Federal mandates (Binding Operational Directives (BOD), Homeland Security Presidential Directives, etc.) on NASA information systems and recommend guidance on implementing such mandates

3.7.3 Vulnerability Management

The requirements in this section relate to the program-level strategies, frameworks, processes, standards, and solutions for managing cybersecurity vulnerabilities to specific information system and OT system components (Tier 3), including hardware, software, operating systems, etc.

• Analyze requirements and develop recommendations for improving Agency-wide management, tracking, and reporting of cybersecurity vulnerabilities

• Assist the Government in developing innovative processes and solutions for enterprise-wide vulnerability management

• Support the establishment, dissemination and management of NASA requirements and solutions for vulnerability management

• Assist the Government in responding to specific enterprise-wide vulnerabilities or threats identified through DHS BODs, Executive Directives, Executive Orders, other Federal mandates, industry alerts, etc., including:

o Analysis of all available NASA and external data sources to determine NASA’s exposure to specific threats and vulnerabilities o Developing and executing a strategy to eliminate and/or remediate threat o Agency-wide communication, coordination and reporting o Tracking of remediation o Monitoring ongoing compliance with specific remediation mandates and actions o Developing and disseminating lessons learned from enterprise-wide vulnerability management activities

• Perform ongoing evaluations of available technologies, in coordination with NASA’s cybersecurity architecture and engineering organization, and recommend solutions to continuously improve NASA’s vulnerability management capabilities

• Communicate with Government and industry partners to maintain awareness to threat environment, specific threats and vulnerabilities, vulnerability management best practices

• Support the development and documentation of vulnerability management policies, processes, and compliance requirements

4.0 Cybersecurity and Privacy Oversight Support

The Cybersecurity and Privacy Oversight Support provides support to the Center Chief Information Security Officers (CISOs), Center Cybersecurity Risk Managers (CCRMs) and Center Privacy Managers at each Center and facility.

The Contractor shall:

• Assist the Government with interpreting the Agency’s policies and procedures

• Assist the Government with ensuring local information systems are following the A&A and risk management requirements and processes

• Assist the Government with validating all local IT systems are complying with and accurately reporting on security requirements, including but not limited to, patch management, end-of-life (EOL) management, vulnerability management, etc.

• Build and maintain relationships with local organizations and customers, understand local requirements, and represent those requirements to enterprise governance, policy makers, service providers, etc.

• Assist the Government in ensuring security control assessments of NASA’s information systems are being performed in accordance with NASA A&A policies and processes

• Review A&A documents and recommend whether the level of risk is within acceptable limits for each information system, application, and network

• Support the Government in reviewing and answering customer requests and questionsrelated to cybersecurity and privacy policy, procedures, requirements, best practices, and NASA implementation

• Support the CPMs in their oversight of all privacy and CUI related aspects

• Assist the Government in supporting organizational continuity of operations and emergency management activities, as requested

5.0 Cybersecurity Standards, Architecture and Engineering

NASA’s cybersecurity architecture is based on NIST’s Cybersecurity Framework, which provides “guidance, based on existing standards, guidelines, and practices for organizations to better manage and reduce cybersecurity risk”.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .