Historical Data - MITS II-pws section 3.pdf

PDF 119 KB Posted

Attached to
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
Solicitation number
80TECH21R0007
Issued by
National Aeronautics and Space Administration

About this file

This document contains a performance work statement for a federal contract providing cybersecurity and privacy services to the National Aeronautics and Space Administration. The contractor shall provide services including IT security risk management, vulnerability analysis and management, intrusion detection and incident response. Specifically, the contractor must comply with NASA security requirements, identify an IT security point of contact, obtain approval before deploying security services, and follow NASA incident response procedures. The contractor will also conduct vulnerability scans, analyze risks, support security assessments, and maintain intrusion detection and incident response tools. These cybersecurity and privacy services are needed to protect NASA's IT systems and data in support of its missions.

View the file

Other files for this federal contract opportunity

Other files attached to Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS), newest first.
File Type Posted
CyPrESS DRFP Questions and Answers.pdf PDF
NASA Industry Day -Registered CyPrESS Attendees.xlsx XLSX spreadsheet
Industry Day - CyPrESS April 19 2021.pdf PDF
Exhibits 20-22.xlsx XLSX spreadsheet
CyPrESS Industry Day Registration.pdf PDF
Draft Request for Proposals 80TECH21R0007 (CyPrESS).pdf PDF
Historical Data - GSFC SES II - NNG15CR67C.pdf PDF
Historical Data - HQ - HITSS_III_RFP_Attach._A_-PWS Page 295.pdf PDF
Historical Data - GSFC GITISS - NNG16VU01C.pdf PDF
Historical Data - NICS Contract - Performance Work Statement.pdf PDF
Historical Data - Historical Metrics.pdf PDF
Historical Data - SSC PWS.pdf PDF
Historical Data - Estimated Historical Labor.pdf PDF
Attachment I - Installation Accountable Government Property (IAGP) Cover Page.pdf PDF
Enclosure CC - IT Security Management Plan Template.pdf PDF
Enclosure AA - Quality Assurance Surveillance Plan (QASP).pdf PDF
Exhibits 2-19.xlsx XLSX spreadsheet
Attachment L - IT Security Management Plan Cover Page.pdf PDF
Attachment K - Contract Management Plan Cover Page - Copy.pdf PDF
Attachment G - Safety and Health Plan Cover Page.pdf PDF
Attachment E - Attachment 1 to DD Form 254_20210125 DRAFT.pdf PDF
Attachment D - Financial Management Reporting.pdf PDF
Attachment C - Data Requirements Descriptions.pdf PDF
Exhibits 20-22.pdf PDF
Enclosure BB - CyPrESS CPAF PEP Core Plus IDIQ Services.pdf PDF
Exhibits 1A-1C.xlsx XLSX spreadsheet
Attachment H - Small Business Subcontracting Plan Cover Page.pdf PDF
Attachment E - DD Form 254 Contract Security Classification Specification.pdf PDF
Attachment E - Attachment 2 to DD Form 254_SBU_20210125 DRAFT.pdf PDF
Attachment I - IAGP.pdf PDF
Enclosure EE CyPrESS Labor Categories.xlsx XLSX spreadsheet
Enclosure DD - GPM-Specified Non-Mgmt DL Categories - DL Hours and PDs Enclosure.pdf PDF
Exhibit 23 PastPerfQues.pdf PDF
Attachment Q - Fixed Price Rate Matrix.pdf PDF
Attachment J - OCI Avoidance Plan Cover Page.pdf PDF
Attachment F - Personal Identiy Verification (PIV) Card Issuance Procedures.pdf PDF
Attachment E - DD Form 254 Cover Page.pdf PDF
Attachment B - Applicable Documents List.pdf PDF
Attachment A - Performance Work Statement.pdf PDF
80TECH21R0007 (CyPrESS) Draft Request For Proposals.pdf PDF
Enclosure CC - Cover Page.pdf PDF
Attachment P - DIRECT LABOR RATES AND INDIRECT RATES AND FEE MATRICES.pdf PDF
Attachment O - Wage Determinations.pdf PDF
Attachment O - Wage Determinations Cover Page.pdf PDF
Attachment N - Phase-in Plan Cover Page.pdf PDF
Show all 45

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

3.0 SECURITY

The integrity, confidentiality, and availability of NASA’s IT systems and data is critical to accomplishing NASA’s missions. NASA seeks a partner that will not only work toward hardening NASA’s core IT Security posture, but will also develop innovative approaches to enhancing NASA’s defenses without sacrificing the user experience. To that end, the Contractor shall:

a. Comply with the information security requirements as defined in NPDs, NPRs, NASA

Interim Directives (NIDs), IT Security Handbooks, PDM, and NASA standards as identified in the Applicable Documents List cited in NFS 1852.204-76, Security Requirements for Unclassified Information Technology Resources.

b. Comply with the IT security requirements outlined in this PWS section both in managing the execution of the Contract, as well as the delivery of services to end users.

c. Consider the language in this PWS as authoritative for any IT Security requirements that are not explicitly cited in the applicable documents list referenced in NFS 1852.204-76, unless superseded by additions or updates to NASA policy documentation.

d. Apply these requirements to all data residing on NASA IT resources. IT resources means any hardware or software or interconnected system or subsystem of equipment, that is used to process, manage, access, or store electronic information.

e. Identify an IT Security Point-of-Contact (POC) for supporting IT security requirements under this contract.

f. Obtain approval from the Government prior to deployment of any IT security services.

g. Follow NASA security incident management procedures and policies and ensure coordination of its incident response team with the NASA Security Operations Center (SOC). The Contractor shall promptly report to the NASA SOC any suspected computer or network security incidents occurring on any systems the Contactor provides or for which they have operational responsibility. The Contractor shall provide all necessary assistance and access to the affected systems so that a thorough investigation can be conducted, problems remedied, and lessons learned documented. Security logs and audit information shall be handled according to evidence preservation procedures. The Contractor shall also:

(1) Provide the NASA SOC real-time, electronic access to all asset information and configuration management information for all devices provided under this contract and in support of this contact.

(2) Report the theft or loss of any device that may contain NASA information, in accordance with NASA incident reporting policy and procedures.

3.1 INFORMATION TECHNOLOGY (IT) SECURITY SERVICES

The Contractor shall provide IT Security services for MSFC-managed unclassified resources, which includes MSFC managed contracts. The Contractor shall provide IT Security risk management, including cyber security assessments and vulnerability analysis and mitigation, as well as intrusion detection and incident response for all applicable IT systems under the responsibility of the MSFC CIO in accordance with the latest NASA, National Institute of

Standards and Technology (NIST) and Federal Information Security Management Act (FISMA) requirements. NASA encourages innovation and welcomes new approaches to solve IT Security problems performed in collaboration with the Government. Some personnel supporting IT Security Services will be required to maintain a secret clearance (see Attachment J-9, DD Form 254, Contract Security Classification and Specification).

3.1.1 IT/OT SECURITY RISK MANAGEMENT

In collaboration with the Government, the Contractor shall coordinate the and implementation of practices that assess and quantify risk. In providing these services, the Contractor shall:

a. Provide support for security planning, risk mitigation, and information protection as required by NASA Policy.

b. Provide engineering support for all IT Security activities being provided at MSFC.

c. Perform the role of Security Control Assessor as defined in NIST SP 800-37 for MSFC managed systems and applications. Tasks include developing the security assessment plan, performing the assessment, issuing a security assessment report, and performing ongoing assessments, including both information technology and operational technology systems.

d. Perform security impact analysis for system change requests including firewall rule changes.

e. Synchronize any Assessment and Authorization data between local MSFC systems and that which is required for reporting in Agency Assessment and Authorization systems.

f. Support 3rd party IT security audits and track the findings which will be used to improve the overall security of MSFC systems and networks.

g. Provide a mechanism for organizations to buy ad hoc system security documentation services through customer funding for creating new SSP packages.

h. Provide a mechanism to imbed cyber security capabilities within organizations through customer funding for dedicated cyber security compliance support.

3.1.2 VULNERABILITY ANALYSIS AND MANAGEMENT

a. Support MSFC activities conducted to provide continuous diagnostics and mitigation across

MSFC IT assets.

b. Conduct weekly discovery, monthly non-credential, and quarterly credential scans of all systems within scope of this contact and coordinate with the systems administrators to resolve the identified vulnerabilities in accordance with NASA policies, procedures, and requirements.

c. Prepare and submit the IT Security Risk Analysis Report in accordance with DRD 1497MA- 006 to provide vulnerability and patch status metrics for all MSFC IT systems determined to be in scope by the Government in accordance with requirements defined by NASA policies and procedures, as well as any metrics that are necessary to indicate compliance or the lack of compliance with MSFC's IT security program.

d. Conduct analysis of the vulnerability scan data and patch management data produced from Government-provided tools. Analysis shall include current status charts/graphs, trending information, risk ranking of identified vulnerabilities, and complete, effective and resource efficient mitigation strategies.

e. Provide application administration for vulnerability and patch management tools defined by the Agency.

f. Provide technical and administrative support for Government-directed IT Security policy enforcement in the NASA Consolidated Active Directory (NCAD). This includes Group Policies (GPOs) for required desktop agent installations (such as BigFix), Intrusion Detection and Incident Response (ID/IR) access, and other policy necessary to ensure IT Security management at MSFC.

g. Align with Agency tool sets and process such as CDM for vulnerability management.

h. Address vulnerability reports from external Federal entities such as DHS, OIG, or OMB.

3.1.3 NTRUSION DETECTION AND INCIDENT RESPONSE (ID/IR)

The Contractor shall provide intrusion detection and incident response for networks and systems managed by the OCIO for all the programs and projects located on the facilities at MSFC. The Contractor shall:

a. Provide an incident response (IR) lead position to support the Government on all issues and functions related to IT Security incident response.

b. Deploy and utilize ID/IR tools, technical policies and procedures required by the

Government in order to protect the MSFC systems and networks.

c. Provide IT Security related analysis of network traffic and system logs of systems suspected of an IT security incident, including the misuse of Government owned or leased systems and provide feedback to the potentially affected organizations as soon as possible in accordance with Government guidance to ensure complete, effective and resource-efficient mitigation strategies.

d. Respond to systems anomalies suspected of viruses, Trojans, or other malware, and coordinate response with the system owners and service providers such as ACES.

a The normal business day for the IR Team in support of NASA and MSFC services is defined as a 5 day week, Monday through Friday (excluding holidays), 8 hours per day between 6 a.m. and 7 p.m.

e. Provide 24 hours a day, 7 days a week, and 365 days a year "on-call" support in addition to IR support provided during business hours. This "on-call" after hours support is limited to incidents rated as 'HIGH' by the NASA SOC, as well as incidents that present a high-level of risk to MSFC or NASA network and computing resources, as determined by the Government.

f. Document and report all IT Security incidents in accordance with NASA SOC guidelines.

g. Operate and maintain the ID/IR tools and applications (e.g., web proxies, flow monitoring tool, security event manager, sniffer, IR Storage Area Network (SAN), forensic lab applications, and intrusion detection systems) provided by the Government to detect and protect systems from unauthorized access, use, disclosure, destruction, modification, or disruption of services.

h. Establish, modify, and monitor application rule sets for the MSFC-provided web proxies, flow monitoring tools, security event managers, network sniffer systems, and intrusion detection systems to protect MSFC users, systems, and networks against inappropriate sites, zero-day exploit code, known exploits, and any malicious cyber attack.

i. Maintain administrative or root access, as applicable, to all MSFC IR systems.

j. Maintain software and hardware forensics capability, to include analysis of network traffic, Personal Computers (PCs), servers and mobile devices in support of a Investigations in accordance with MSFC policy, such as but not limited to, misuse, workplace violence, and fraud.

b Data extraction requests as authorized by the Government for purposes such as business continuity or in support of other Agencies

k. Provide IT Security guidance, direction, and assistance to include current system issues, metrics and special reporting requirements to system administrators who support servers for various organizations with IT systems on the MSFC networks.

File details come from the government source that posted it. Updated .