Attachment B - Applicable Documents List.pdf

PDF 528 KB Posted

Attached to
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
Solicitation number
80TECH21R0007
Issued by
National Aeronautics and Space Administration

About this file

This document provides details on a forthcoming solicitation from the National Aeronautics and Space Administration for cybersecurity and privacy enterprise solutions and services. Key information includes that NASA's Information Technology Procurement Office plans to issue a request for proposal for a single award, cost plus award fee contract over 20 months base and up to 120 months total to provide cybersecurity and privacy program management, oversight, standards, architecture, engineering, and services support across all NASA centers and facilities. Offerors must hold a top secret facility clearance by the anticipated second quarter 2021 proposal due date. NASA will release a draft RFP in the second quarter of 2021 and hold an industry day event with final RFP anticipated then as well. Interested parties should monitor beta.sam.gov for additional details and amendments.

View the file

Other files for this federal contract opportunity

Other files attached to Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS), newest first.
File Type Posted
CyPrESS DRFP Questions and Answers.pdf PDF
NASA Industry Day -Registered CyPrESS Attendees.xlsx XLSX spreadsheet
Industry Day - CyPrESS April 19 2021.pdf PDF
Exhibits 20-22.xlsx XLSX spreadsheet
CyPrESS Industry Day Registration.pdf PDF
Draft Request for Proposals 80TECH21R0007 (CyPrESS).pdf PDF
Historical Data - SSC PWS.pdf PDF
Historical Data - Estimated Historical Labor.pdf PDF
Historical Data - HQ - HITSS_III_RFP_Attach._A_-PWS Page 295.pdf PDF
Historical Data - GSFC GITISS - NNG16VU01C.pdf PDF
Historical Data - MITS II-pws section 3.pdf PDF
Historical Data - GSFC SES II - NNG15CR67C.pdf PDF
Historical Data - NICS Contract - Performance Work Statement.pdf PDF
Historical Data - Historical Metrics.pdf PDF
80TECH21R0007 (CyPrESS) Draft Request For Proposals.pdf PDF
Enclosure CC - Cover Page.pdf PDF
Attachment P - DIRECT LABOR RATES AND INDIRECT RATES AND FEE MATRICES.pdf PDF
Attachment O - Wage Determinations.pdf PDF
Attachment O - Wage Determinations Cover Page.pdf PDF
Attachment N - Phase-in Plan Cover Page.pdf PDF
Exhibits 20-22.pdf PDF
Enclosure BB - CyPrESS CPAF PEP Core Plus IDIQ Services.pdf PDF
Exhibits 1A-1C.xlsx XLSX spreadsheet
Attachment H - Small Business Subcontracting Plan Cover Page.pdf PDF
Attachment E - DD Form 254 Contract Security Classification Specification.pdf PDF
Attachment I - Installation Accountable Government Property (IAGP) Cover Page.pdf PDF
Enclosure CC - IT Security Management Plan Template.pdf PDF
Enclosure AA - Quality Assurance Surveillance Plan (QASP).pdf PDF
Exhibits 2-19.xlsx XLSX spreadsheet
Attachment L - IT Security Management Plan Cover Page.pdf PDF
Attachment K - Contract Management Plan Cover Page - Copy.pdf PDF
Attachment G - Safety and Health Plan Cover Page.pdf PDF
Attachment E - Attachment 1 to DD Form 254_20210125 DRAFT.pdf PDF
Attachment D - Financial Management Reporting.pdf PDF
Attachment C - Data Requirements Descriptions.pdf PDF
Attachment E - Attachment 2 to DD Form 254_SBU_20210125 DRAFT.pdf PDF
Attachment I - IAGP.pdf PDF
Enclosure EE CyPrESS Labor Categories.xlsx XLSX spreadsheet
Enclosure DD - GPM-Specified Non-Mgmt DL Categories - DL Hours and PDs Enclosure.pdf PDF
Exhibit 23 PastPerfQues.pdf PDF
Attachment Q - Fixed Price Rate Matrix.pdf PDF
Attachment J - OCI Avoidance Plan Cover Page.pdf PDF
Attachment F - Personal Identiy Verification (PIV) Card Issuance Procedures.pdf PDF
Attachment E - DD Form 254 Cover Page.pdf PDF
Attachment A - Performance Work Statement.pdf PDF
Show all 45

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Information Technology (IT) Security Applicable Documents List October 2020

NASA Policy Directives (NPD) and NASA Procedural Requirements (NPR)

Document Subject

NPR 1040.1 NASA Continuity of Operations (COOP) Planning Procedural Requirements

NPD 1280.1 NASA Integrated Management System Policy

NPR 1382.1 NASA Privacy Procedural Requirements

NPD 1382.17 NASA Privacy Policy

NPD 1440.6 NASA Records Management

NPR 1441.1 NASA Records Management Program Requirements

NPR 1600.1 NASA Security Program Procedural Requirements

NPR 1600.2 NASA Classified National Security Information (CNSI)

NPR 1620.3 Physical Security Requirements for NASA Facilities and Property

NPR 1800.1 Occupational Health Programs

NPD 2190.1 NASA Export Control Program

NPR 2190.1 NASA Export Control Program

NPD 2540.1 Acceptable Use of Government Office Property Including Information Technology

NPD 2800.1 Managing Information Technology

NPR 2800.1 Managing Information Technology

NPD 2810.1 NASA Information Security Policy

NPR 2810.1 Security of Information Technology

NPD 2830.1 NASA Enterprise Architecture

NPR 2830.1 NASA Enterprise Architecture Procedures

NPR 2841.1 Identity, Credential, and Access Management

NPR 3792.1 NASA’s Plan for a Drug Free Workplace

NPR 4100.1 NASA Supply Support and Material Management

NPD 4200.1 Equipment Management

NPR 4200.1 NASA Equipment Management Procedural Requirements

NPR 4300.1 NASA Personal Property Disposal Procedural Requirements

NPD 6000.1 Transportation Management

NPR 6200.1 NASA Transportation and General Traffic Management

NPR 7120.5 NASA Space Flight Program and Project Management Requirements (The document is applicable to PWS <number> ISSO Services only.)

NPR 7120.7 NASA Information Technology Program and Project Management Requirements

NPR 7120.8 NASA Research and Technology Program and Project Management Requirements (The document is applicable to PWS <number> ISSO Services only.)

NPR 7123.1 NASA Systems Engineering Processes and Requirements

NPR 7150.2 NASA Software Engineering Requirements

NPR 8621.1 NASA Procedural Requirements for Mishap and Close Call Reporting, Investigating, and Recordkeeping

NPR 8715.1 NASA Safety and Health Programs

NPR 8715.3 NASA General Safety Program Requirements

NPD 8730.5 NASA Quality Assurance Program Policy

NPD 8800.14 Policy for Real Estate Management

NPR 8831.2 Facilities Maintenance and Operations Management

NASA Interim Directive (NID)

NASA Records Retention Schedules (NRRS)

NRRS 1441.1 NASA Records Retention Schedule

IT Security Handbooks (ITS-HBK)

ITS-HBK-1382.02-01 Privacy Goals and Objectives: Overview

ITS-HBK-1382.03-01

Privacy Risk Management and Compliance: Collections, PIAs and SORNs

ITS-HBK-1382.03-02

Privacy Risk Management and Compliance: Annual Reporting Procedures for Reviewing and Reducing Personally Identifiable Information (PII) and Eliminating the Unnecessary Use of SSN

ITS-HBK-1382.04-01 Privacy and Information Security: Overview

ITS-HBK-1382.05-01

Privacy Incident Response and Management: Breach Response Team

ITS-HBK-1382.06-01

Privacy Notice and Redress: Web Privacy and Written Notice, Complaints, Access and Redress

ITS-HBK-1382.07-01 Privacy Awareness and Training: Overview

ITS-HBK-1382.08-01 Privacy Accountability

ITS-HBK-1382.09-01

Privacy Rules of Behavior and Consequences: Overview

IT-HBK-1441.01.01 Records Retention and Disposition: Overview

IT-HBK-1440.01.01 Records Planning & Management: Records Management and Records Life Cycle - Overview

ITS-HBK-2841.003 Identity, Credential, and Access Management Services (ICAM)

ITS-HBK-2810.02-01 Security Assessment and Authorization

ITS-HBK-2810.02-02

Security Assessment and Authorization: Information System Security Assessment and Authorization Process

ITS-HBK-2810.02-04

Security Assessment and Authorization: Continuous Monitoring

– Security Control Ongoing Assessments and Authorization

ITS-HBK-2810.02-05 Security Assessment and Authorization: External Information Systems

ITS-HBK-2810.02-06

Security Assessment and Authorization: Extending and Information Systems Authorization to Operate Process and Template

ITS-HBK-2810.02-08

Security Assessment and Authorization: Plan of Action and Milestones

(POA&M)

ITS-HBK-2810.03-02

Planning

ITS-HBK-2810.04-01

Risk Assessment: Security Categorization, Risk Assessment, Vulnerability Scanning, Expedited Patching & Organizationally Defined Values

ITS-HBK-2810.05-02 Systems and Service Acquisition

ITS-HBK-2810.06-02 IT Security Awareness, Training, and Education

ITS-HBK-2810.07-02 Configuration Management

ITS-HBK-2810.08-01 Contingency Planning

ITS-HBK-2810.09-01 Incident Response and Management

ITS-HBK-2810.09-02

NASA Information Security Incident Management

ITS-HBK-2810.09-03 Collection of Electronic Data

ITS-HBK-2810.09-04

Incident Response and Management: Guidelines for Data Spillage & Sanitization Procedures

ITS-HBK-2810.10-02 Maintenance

ITS-HBK-2810.11-2 Media Protection and Sanitization

ITS-HBK-2810.12-02 Physical and Environmental Protection

ITS-HBK-2810.13-01 Personnel Security

ITS-HBK-2810.14-03 System and Information Integrity

ITS-HBK-2810.15-01 Access Control

ITS-HBK-2810.15-02 Access Control: Managed Elevated Privileges (EP)

ITS-HBK-2810.16-02 Audit and Accountability

ITS-HBK-2810.17-02 Identification and Authentication

ITS-HBK-2810.18-02 System and Communications Protection

ITS-HBK-2810.19.01 Operational Technology

ITS-HBK-2810.002-1 Format and Procedures for IT Security Policies and Handbooks: Privacy, Security & Sensitive Information

Standards

NASA-STD-2804 Minimum Interoperability Software Suite

NASA-STD-2805 Minimum Hardware Configurations

J-10-9

Executive

Orders and FIPS

Document Subject

Executive Order

(EO) 13556

Controlled Unclassified Information (CUI)

EO 13636 Improving Critical Infrastructure Cybersecurity

EO 13834 Efficient Federal Operations Federal Information Processing Standards (FIPS) 140-2

Security Requirements For Cryptographic Modules

FIPS 180 Secure Hash Standard (SHS)

FIPS 186 Digital Signature Standard (DSS)

FIPS 197 Advanced Encryption Standard (AES)

FIPS 198 The Keyed-Hash Message Authentication Code (HMAC)

FIPS 199 Standards for Security Categorization of Federal Information and Information Systems

FIPS 200 Minimum Security Requirements for Federal Information and Information Systems

FIPS 202 SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions

NIST

NIST SP 800-100 Information Security Handbook: A Guide for Managers

NIST SP 800-101 Guidelines on Mobile Device Forensics

NIST SP 800-107 Recommendation for Applications Using Approved Hash Algorithms

NIST SP 800-111 Guide to Storage Encryption Technologies for End User Devices

NIST SP 800-113 Guide to SSL VPNs

NIST SP 800-114 User’s Guide to Telework and Bring Your Own Device (BYOD) Security

J-10-10

NIST SP 800-115 Technical Guide to Information Security Testing and Assessment

NIST SP 800-116 Guidelines for the Use of PIV Credentials in Facility Access

NIST SP 800-12 An Introduction to Information Security

NIST SP 800-121 Guide to Bluetooth Security

NIST SP 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)

NIST SP 800-123 Guide to General Server Security

NIST SP 800-124 Guidelines for Managing the Security of Mobile Devices in the Enterprise

NIST SP 800-125 Guide to Security for Full Virtualization Technologies

NIST SP 800-125A Security Recommendations for Server-based Hypervisor Platforms

NIST SP 800-125B Secure Virtual Network Configuration for Virtual Machine (VM) Protection

NIST SP 800-126 The Technical Specification for Security Content Automation Protocol (SCAP): SCAP Version 1.1

NIST SP 800-126A SCAP 1.3 Component Specification Version Updates: An Annex to NIST Special Publication 800-126 Revisions 3

NIST SP 800-126

Rev. 2

The Technical Specification for Security Content Automation Protocol (SCAP): SCAP Version 1.2

NIST SP 800-126

Rev. 3

The Technical Specification for Security Content Automation Protocol (SCAP): SCAP Version 1.3

NIST SP 800-128 Guide for Security-Focused Configuration Management of Information Systems

NIST SP 800-130 A Framework for Designing Cryptographic Key Management Systems

NIST SP 800-133 Recommendation for Cryptographic Key Generation

NIST SP 800-135 Recommendation for Existing Application-Specific Key Derivation Functions

J-10-11

NIST SP 800-137

Series

Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations

NIST SP 800-140

including A-F

FIPS 140-3 Derived Test Requirements (DTR): Cryptographic Module Validation Program (CMVP) Validation Authority Updates to ISO/IEC 24759 and all requirements from the series

NIST SP 800-144 Guidelines on Security and Privacy in Public Cloud Computing

NIST SP 800-145 The NIST Definition of Cloud Computing

NIST SP 800-146 Cloud Computing Synopsis and Recommendations

NIST SP 800-147 BIOS Protection Guidelines

NIST SP 800-147B BIOS Protection Guidelines for Servers

NIST SP 800-150 Guide to Cyber Threat Information Sharing

NIST SP 800-152 A Profile for U.S. Federal Cryptographic Key Management System (CKMS)

NIST SP 800-156 Representation of PIV Chain-of-Trust for Import and Export

NIST SP 800-157 Guidelines for Derived Personal Identity Verification (PIV) Credentials.

NIST SP 800-16 Information Technology Security Training Requirements: a Role- and Performance-Based Model

NIST SP 800-160

Vol. 1 & 2

Systems Security Engineering: Multidisciplinary Approach and Developing Cyber Resilient Systems

NIST SP 800-161 Supply Chain Risk Management Practices for Federal Information Systems and Organizations

NIST SP 800-163 Vetting the Security of Mobile Applications

J-10-12

NIST SP 800-166 Derived PIV Application and Data Model Test Guidelines

NIST SP 800-167 Guide to Application Whitelisting

NIST SP 800-168 Approximate Matching: Definition and Terminology

NIST SP 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

NIST SP 800-171A Assessing Security Requirements for Controlled Unclassified Information

NIST SP 800-

175A

Guideline for Using Cryptographic Standards in the Federal Government: Directives, Mandates and Policies

NIST SP 800-

175B

Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms

NIST SP 800-177 Trustworthy Email

NIST SP 800-18 Guide for Developing Security Plans for Federal Information Systems

NIST SP 800-181 National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework

NIST SP 800-183 Network of ‘Things’

NIST SP 800-184 Guide for Cybersecurity Event Recovery

NIST SP 800-187 Guide to LTE Security

NIST SP 800-189 Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation

NIST SP 800-190 Application Container Security Guide

NIST SP 800-192 Verification and Test Methods for Access Control Policies/Models

J-10-13

NIST SP 800-193 Platform Firmware Resiliency Guidelines

NIST SP 800-204

Series

Security Strategies for Microservices-based Applications Systems

NIST SP 800-205 Attribute Considerations for Access Control Systems

NIST SP 800-207 Zero Trust Architecture

NIST SP 800-210 General Access Control Guidance for Cloud Systems

NIST SP 800-25 Federal Agency Use of Public Key Technology for Digital Signatures and Authentication

NIST SP 800-30 Guide for Conducting Risk Assessments

NIST SP 800-32 Introduction to Public Key Technology and the Federal PKI Infrastructure

NIST SP 800-34 Contingency Planning Guide for Federal Information Systems

NIST SP 800-35 Guide to Information Technology Security Services

NIST SP 800-37 Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy

NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View

NIST SP 800-40 Guide to Enterprise Patch Management Technologies

NIST SP 800-41 Guidelines on Firewalls and Firewall Policy

NIST SP 800-44 Guidelines on Securing Public Web Servers

NIST SP 800-45 Guidelines on Electronic Mail Security

NIST SP 800-46 Guide to Enterprise Telework, Remote Access, and Bring Your Own Device (BYOD) Security

NIST SP 800-47 Security Guide for Interconnecting Information Technology Systems

NIST SP 800-50 Building an Information Technology Security Awareness and

NIST SP 800-52 Guidelines for Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations

NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations

J-10-14

NIST SP 800-53A Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans

NIST SP 800-53B Control Baselines for Information Systems and Organizations

NIST SP 800-55 Performance Measurement Guide for Information Technology Systems

NIST SP 800-57

Parts 1- 3

Recommendation for Key Management

NIST SP 800-58 Security Considerations for Voice Over IP Systems

NIST SP 800-59 Guideline for Identifying an Information System as a National Security System

NIST SP 800-60

Volume I

Guide for Mapping Types of Information and Information Systems to Security Categories

NIST SP 800-60

Volume II

Guide for Mapping Types of Information and Information Systems to Security Categories: Appendices

NIST SP 800-61 Computer Security Incident Handling Guide

NIST SP 800-63

also includes B and C

Digital Identity Guidelines

NIST SP 800-66 An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule

NIST SP 800-70 National Checklist Program for IT Products: Guidelines for Checklist Users and Developers

NIST SP 800-72 Guidelines on PDA Forensics

NIST SP 800-73 Interfaces for Personal Identity Verification

NIST SP 800-76 Biometric Specifications for Personal Identity Verification

NIST SP 800-77 Guide to IPsec VPNs

NIST SP 800-79 Guidelines for the Authorization of Personal Identity Verification Card Issuers (PCI) and Derived PIV Credential Issuers (DPCI)

NIST SP 800-81 Secure Domain Name System (DNS) Deployment Guide

NIST SP 800-82 Guide to Industrial Control Systems (ICS) Security

NIST SP 800-83 Guide to Malware Incident Prevention and Handling for Desktops and Laptops

NIST SP 800-84 Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities

NIST SP 800-85A PIV Card Application and Middleware Interface Test Guidelines

NIST SP 800-85B PIV Data Model Test Guidelines

File details come from the government source that posted it. Updated .