ATT D - Applicable Documents List Draft.pdf
PDF 291 KB Posted
- Attached to
- NASA's Consolidated Applications and Platform Services (NCAPS) requirement Federal contract opportunity
- Solicitation number
- 80TECH22R0002
View the file
Other files for this federal contract opportunity
Show all 32
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT D
NASA CONSOLIDATED APPLICATIONS AND
PLATFORM SERVICES (NCAPS)
APPLICABLE DOCUMENTS LIST (ADL)
RFP 80TECH22R0002
CONTRACT #TBD
DATE: TBD
Attachment D
80TECH22R0002
This attachment contains the list of applicable documents for the contract effort. The document number reference in the contract may not contain the revision number. The latest revision of each document is the applicable document, and the contractor is responsible for ensuring application of the latest revision. The contractor shall comply with these requirements in performing the Performance Work Statement (PWS) activities. Requirements written in these documents shall have full force and effect as if their text was written in this contract to the extent that the requirements relate to context of the work to be performed within the scope of this contract.
Document Number Title 15 CFR Parts 730-799 Export Administration Regulations (EAR) 22 CFR Parts 120-130 International Traffic in Arms Regulations (ITAR) 29 CFR Part 1903 Inspections, Citations, and Proposed Penalties
29 CFR Part 1910 Department of Labor; Occupational Safety and Health Administration Standards for General Industry
29 CFR Part 1926 Department of Labor; Occupational Safety and Health Administration Standards for Construction Industry
32 CFR 2001 Classified National Security Information 36 CFR Part 1220 Federal Records 40 CFR Part 82.162 Certification by Owners of Recovery and Recycling Equipment 40 U.S.C. 11331 Responsibilities for Federal Information Systems Standards
ANSI/ISO/ASQ
Q9001-2000
Quality Management Systems – Requirements
AP-NASA-HDBK-
001, V2.6
Applications Program Handbook Policy Handbook
BOD 18-02 Department of Homeland Security’s Binding Operational Directive 18-02, Securing High Value Assets
32 CFR Part 2002 Controlled Unclassified Information (CUI) CNSSI 4009 Committee on National Security Systems (CNSS) Glossary CP-001-V4 CP Service Document (CSD) CSO-SOP-0002 Communications Service Office (CSO) Standard Operating
Procedure for Trouble Reporting, Activity Scheduling, Mission Freeze, and Major Outage Notifications
Executive Order (EO) 13526
Classifying and declassifying National Security Information
EO 13556 Controlled Unclassified Information EO 13636 Improving Critical Infrastructure Cybersecurity EO 13834 Efficient Federal Operations EO 14028 Improving the Nation’s Cybersecurity FIPS 140-2 Security Requirements For Cryptographic Modules FIPS 199 Standards for Security Categorization of Federal Information and
Information Systems FIPS 200 Minimum Security Requirements for Federal Information and
Information Systems FIPS 201-2 Personal Identity Verification (PIV) of Federal Employees and
Contractors
Document Number Title HSPD-12 Policy for a Common Identification Standard for Federal Employees and Contractors
IETF RFC
Memorandum 778
DCNET Internet Clock Service
IETF RFC
Memorandum 891
DCN Local-Network Protocols
IETF RFC
Memorandum 956
Algorithms for Synchronizing Network Clocks
IETF RFC
Memorandum 5905
Network Time Protocol Version 4: Protocol and Algorithms Specification
ISO/IEC 17025 General Requirements for the Competence of Testing and Calibration Laboratories
IT-HBK-1440.01-01
Records Management Program and Records Life Cycle: Chapter 1
— Overview
IT-HBK-1441.01-01 Records Retention and Disposition: Chapter 1 — Overview
ITS-HBK-1382.03-01 Privacy – Collections, PTAs, and PIAs
ITS-HBK-1382.03-02
Privacy Annual Reporting Procedures: Reviewing and Reducing PII and Unnecessary Use of SSN
ITS-HBK-1382.04-1
Privacy and Cybersecurity: Supporting and Integrated Controls Framework
ITS-HBK-1382.05-01
Privacy Incident Response and Management: Breach Response Team Checklist
ITS-HBK-1382.06-01
Privacy Notice and Redress — Web Privacy and Written Notice, Complaints, Access, and Redress
ITS-HBK-1382.07-01 Privacy Awareness and Training ITS-HBK-1382.08-01 Privacy Accountability ITS-HBK-1382.09-01 Privacy Rules of Behavior and Consequences
ITS-HBK-2810-
002.1C
Format and Procedures for IT Security Policies and Handbooks
ITS-HBK-2810.03-
02B
Planning
ITS-HBK-2810.04-
01A Risk Assessment, Vulnerability Scanning, and Expedited Patching ITS-HBK-2810.05-2B System and Service Acquisition ITS-HBK-2810.06-2B IT Security Awareness, Training, and Education
ITS-HBK-2810.07-
02B
Configuration Management
ITS-HBK-2810.08-
01A
Contingency Planning
ITS-HBK-2810.09-01 Incident Response and Management
ITS-HBK-2810.09-
02A NASA Information Security Incident Management (CUI)
ITS-HBK-2810.09-
03A Collection of Electronic Data (CUI)
ITS-HBK-2810.09-04
Incident Response and Management: Guidelines for Data Spillage and Sanitization Procedures
ITS-HBK-2810.10-
02C
Maintenance
ITS-HBK-2810.11-2C Media Protection and Sanitization
ITS-HBK-2810.12-
02B
Physical and Environmental Protection
ITS-HBK-2810.13-
01B
Personnel Security
ITS-HBK-2810.14-
03D
System and Information Integrity – System and Info Integrity
ITS-HBK-2810.15-
01A
Access Control
ITS-HBK-2810.15-
02A Access Control: Managed Elevated Privileges (CUI)
ITS-HBK-2810.16-
02B
Audit and Accountability
ITS-HBK-2810.17-
02B
Identification and Authentication
ITS-HBK-2810.18-
02B
System and Communications Protection
ITS-HBK-2810.19-01 Operational Technology
IT-HBK-2841-03A Identity, Credential, and Access Management (ICAM) Services ITS-HBK-CUI_v1.0.0 Controlled Unclassified Information Handbook
ITS-HBK-
SCRM.2810.v1.0.0
Information & Communications Technology Supply Chain Risk Management (ICT SCRM)
ITS-HBK-
AASTEP0.v1.0.0 Step 0: Prepare Policy
ITS-HBK-
AASTEP1.v1.0.0 Step 1: Categorize Policy
ITS-HBK-
AASTEP2.v1.0.0 Step 2: Select Policy
AASTEP3.v.1.0.0 Step 3: Implement Policy
AASTEP4.v1.0.0 Step 4: Assess Policy
ITS-HBK-
AASTEP5.v1.0.0 Step 5: Authorize Policy
ITS-HBK-
AASTEP6.v.1.0.0 Step 6: Monitor Policy AA-Role-AODR Authorizing Official Designated Representative Summary AA-Role-AO Authorizing Official Summary AA-Role-CISO Center Chief Information Security Officer Summary AA-Role-CCRM Center Cybersecurity Risk Manager Summary AA-Role-CPM Center Privacy Manager Summary AA-Role-ISO Information System Owner Summary AA-Role-ISSE Information System Security Engineer Summary AA-Role-ISSO Information System Security Officer Summary AA-Role-SCA Security Control Assessor Summary MIL-HDBK-881D Department of Defense Handbook Work Breakdown Structure
NAII 2190.1E NASA Export Control Program Operations Manual NAII 2810.1 Networks in NASA Internet Protocol (IP) Space or NASA Physical
Space NASA-HDBK-2203 Software Engineering Handbook
NASA/SP-2007-6105 NASA Systems Engineering Handbook
NASA-SPEC-
2661.Controls
Control Baselines and Critical Controls for NASA Information Systems
NASA-SPEC-
2661.ODVr5
NASA’s Organization-Defined Values for NIST SP 800-53 Revision 5
NASA-STD-2601 Minimum Cybersecurity Requirements for Computing Systems NASA-STD-2602 Minimum Information System Owner and End User Security for
Data at Rest NASA-STD-2603 Minimum Security and Privacy Requirements for Agency and
Center Information System Implementations NASA-STD-2604 Computing System Configuration Management NASA-STD-2804 Minimum Interoperability Software Suite NASA-STD-2805 Minimum Hardware Configurations NASA-STD-2818 Digital Television for NASA NASA-STD-8739.8A Software Assurance and Software Safety Standard NASA-STD-8739.9 Software Formal Inspection Standard
NIST SP 800-12 Rev.
An Introduction to Computer Security: the NIST Handbook
NIST SP 800-18 Rev.
Guide for Developing Security Plans for Federal Information Systems
NIST SP 800-30 Rev
Guide for Conducting Risk Assessments
NIST SP 800-34 Rev.
Contingency Planning Guide for Federal Information Systems
NIST SP 800-35 Guide to Information Technology Security Services
NIST SP 800-37 Rev
Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View
NIST SP 800-44
Version 2
Guidelines on Securing Public Web Servers
NIST SP 800-53 Rev
Security and Privacy Controls for Federal Information Systems and Organizations
NIST SP 800-53A
Rev 5
Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans
NIST SP 800-55 Rev.
Performance Measurement Guide for Information Security
NIST SP 800-60 Vol.2 Rev. 1
Guide for Mapping Types of Information and Information Systems to Security Categories: Appendices
NIST SP 800-61 Rev
Computer Security Incident Handling Guide
NIST SP 800-83 Rev
Guide to Malware Incident Prevention and Handling for Desktops and Laptops
NIST SP 800-86 Guide to Integrating Forensic Techniques into Incident Response NIST SP 800-100 Information Security Handbook: A Guide for Managers
NIST SP 800-101 Rev
Guidelines on Mobile Device Forensics
NIST SP 800-115 Technical Guide to Information Security Testing and Assessment NIST SP 800-128 Guide for Security-Focused Configuration Management of
Information Systems NIST SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal
Information Systems and Organizations NIST SP 800-150 Guide to Cyber Threat Information Sharing NIST SP 800-153 Guidelines for Securing Wireless Local Area Networks (WLANs) NIST SP 800-160 Vol
Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems
NIST SP 800-161
Rev. 1
Supply Chain Risk Management Practices for Federal Information Systems and Organizations
NIST SP 800-171 Rev
Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
NIST SP 800-172A Assessing Security Requirements for Controlled Unclassified Information
NIST SP 800-181
Rev. 1
National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework
NITR 2800-2 Email Services and Email Forwarding NITR 2812-1 NASA Network Architecture NPD 1000.0C NASA Governance and Strategic Management Handbook NPD 1280.1A NASA Integrated Management System Policy NPD 1380.1 Managing Agency Communications NPD 1382.17K NASA Privacy Policy NPD 1383.1C Release and Management of Audiovisual Products NPD 1385.2I Public Appearances of NASA Personnel, Including Astronauts NPD 1420.1A NASA Forms Management NPD 1440.6I NASA Records Management NPD 1600.2E NASA Security Policy NPD 1600.3 Policy on Prevention of and Response to Workplace Violence NPD 1600.4 National Security Programs NPD 1600.9A NASA Insider Threat Program NPD 2190.1B NASA Export Control Program NPD 2200.1D Management of NASA Scientific and Technical Information NPD 2540.1K Acceptable Use of Government Furnished Information Technology
Equipment, Services and Resources NPD 2800.1E Managing Information Technology NPD 2810.1F NASA Information Security Policy NPD 2830.1D NASA Enterprise Architecture NPD 4200.1C Equipment Management NPD 6000.1D Transportation Management NPD 7120.4E NASA Engineering and Program/Project Management Policy
NPD 7120.6A Knowledge Policy for Program and Projects NPD 7410.1H Management of Contract and Grant Support Services Obtained from
External Sources (Revalidated 8/14/2018) NPD 7500.1D Program and Project Life-Cycle Logistics Support Policy NPD 7620.1I Official Names for Major NASA Projects NPD 8610.23C Launch Vehicle Technical Oversight Policy NPD 8610.24C Launch Services Program Pre-Launch Readiness Reviews NPD 8610.6H Graphic Markings on Space Vehicles, Equipment, and Hardware NPD 8610.7D Launch Services Risk Mitigation Policy for NASA-Owned and/or
NASA-Sponsored Payloads/Missions NPD 8700.1F NASA Policy for Safety and Mission Success NPD 8710.1D Emergency Management Program NPD 8730.5B NASA Quality Assurance Program Policy NPD 8800.14E Policy for Real Estate Management NPD 9501.1I NASA Contractor Financial Management Reporting System NPR 1040.1 NASA Continuity of Operations (COOP) Planning Procedural
Requirements NPR 1382.1B NASA Privacy Procedural Requirements NPR 1385.1A Public Appearances of NASA Personnel, Including Astronauts NPR 1441.1E NASA Records Management Program Requirements NPR 1450.10D NASA Correspondence Management and Communications
Standards and Styl NPR 1600.1A NASA Security Program Procedural Requirements NPR 1600.2A NASA Classified National Security Information (CNSI) NPR 1600.3A Personnel Security NPR 1600.4A Identity and Credential Management NPR 1600.6A Communications Security (COMSEC) NPR 1620.2B Facility Security Level Determinations NPR 1620.3B Physical Security Requirements for NASA Facilities and Property NPR 1660.1C NASA Counterintelligence and Counterterrorism NPR 2190.1C NASA Export Control Program NPR 2200.2D Management of Scientific and Technical Information NPR 2210.1C Release of NASA Software NPR 2570.1C RF Spectrum Management Manual
NPR 2800.2A Information and Communication Technology Accessibility
NPR 2810.1F Security of Information and Information Systems NPR 2810.2 Possession and Use of NASA Information and Information Systems
Outside of the United States and United States Territories NPR 2810.7 Controlled Unclassified Information NPR 2830.1A NASA Enterprise Architecture Procedures NPR 2841.1 Identity, Credential, and Access Management NPR 3792.1D NASA’s Plan for a Drug Free Workplace
NPR 4100.1F NASA Supply Support and Material Management NPR 4200.1H NASA Equipment Management Procedural Requirements NPR 4300.1C NASA Personal Property Disposal Procedural Requirements NPR 4500.1 Administration of Property in Custody of Contractors NPR 6200.1D NASA Transportation and General Traffic Management NPR 7120.5F NASA Space Flight Program and Project Management
Requirements NPR 7120.6A Knowledge Policy for Programs and Projects
NPR 7120.7A NASA Information Technology Program and Project Management
Requirements NPR 7120.8A NASA Research and Technology Program and Project Management
Requirements NPR 7120.10B Technical Standards for NASA Programs and Projects NPR 7123.1C NASA Systems Engineering Processes and Requirements
NPR 7150.2D NASA Software Engineering Requirements NPR 7500.2A NASA Technology Transfer Requirements
NPR 8000.4C Agency Risk Management Procedural Requirements NPR 8621.1D NASA Procedural Requirements for Mishap and Close Call
Reporting, Investigating, and Recordkeeping NPR 8705.5A Technical Probabilistic Risk Assessment (PRA) Procedures for
Safety and Mission Success for NASA Programs and Projects NPR 8705.6D Safety and Mission Assurance (SMA) Audits, Reviews, and
Assessments NPR 8715.3D NASA General Safety Program Requirements NPR 8831.2F Facilities Maintenance and Operations Management NPR 9250.1C Propulsion, Plant, Equipment, and Operations Materials NPR 9501.2E NASA Contractor Financial Management Reporting NPR 9610.1B Accounts Receivable, Billing, and Collection NPR 9640.1A Financial Management of Contractor Claims Against NASA NSTS 08117 Certification of Flight Readiness Requirements NSTS 5300.4 (1D-2) Safety, Reliability, Maintainability, and Quality Provisions for the
Space Shuttle Program National Defense Authorization Act (NDAA) section 889
Prohibition On Certain Telecommunications and Video Surveillance Services or Equipment
OIP 50952 International Space Station Program OMB Circular A-123 Management's Responsibility for Internal Control OMB Circular A-130 Managing Information as a Strategic Resource OMB M-07-16 Safeguarding Against and Responding to the Breach of Personally
Identifiable Information
OMB M-11-11 Continued Implementation of Homeland Security Presidential
Directive 12 (HSPD-12) – Policy for a Common Identification Standard for Federal Employees and Contractors
OMB Memo M-15-13 Policy to require Secure Connections across Federal Websites and Web Services
OMB M-15-14 Management and Oversight of Federal Information Technology, Federal Information Technology (FITARA)
OMB M-16-04 Cybersecurity Strategy and Implementation Plan (CSIP) for the Federal Civilian Government
OMB M-19-03 Office of Management and Budget (OMB) Memorandum 19-03, Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program
OMB M-19-17 Enabling Mission Delivery through Improved Identity, Credential, and Access Management
OMB Memo M-21-07 Completing the Transition to Internet Protocol version 6 (IPv6), dated November 19, 2020
OMB M-22-09 Moving the U.S. Government Toward Zero Trust Cybersecurity Principles
Public Law 93-579 Privacy Act, December 1974 (Privacy Act) Public Law 113-283, S. 2521
The Federal Information Security Modernization Act of 2014 (FISMA Reform)
Public Law 115-390 Secure Technology Act SAE AS9003 Inspection and Test Quality System SSP 50108 Certification of Flight Readiness for Space Station
SSP 50200-01-ANX
AA
Station Program Implementation Plan (SPIP) Volume 1: Station Program Management Plan, Annex AA: Payload and Mission Operations Division
SSP-50952 Operations Interface Procedures (OIP) Management Plan
NFS 1852.204-76 Security requirements for unclassified information technology resources.
FAR 52.227-11 Patent Rights – Ownership by the Contractor (May 2014) AS modified by NASA FAR Supplement 1852.227-11 (Apr 2015)
NFS 1852.227-70 New Technology - Other Than a Small Business Firm or NonProfit Organization (Apr 2015)
FAR 52.245-1 Government Property FAR 52.245-2 Government Property Installation Operation Services (Apr 2012)
NFS 1852.245-70
Contractor Requests for Government Furnished Property (Aug 2015) Alt I (Aug 2015)
NFS 1852.245-71
Installation Accountable Government Property (Jun 2018) Alt I (Jan 2011)
NFS 1852.245-72
Liability for Government Property Furnished for Repair or Other Services (Jan 2011)
NFS 1852.245-73
Financial Reporting of NASA Property in the Custody of Contractors (Jan 2017)
NFS 1852.245-74 Identification and Marking of Government Equipment (Jan 2011) NFS 1852.245-75 Property Management Changes (Jan 2011)
NFS 1852.245-77
List of Government Property Furnished Pursuant to FAR 52.245- 2 (Jan 2011)
NFS 1852.245-78 Physical Inventory of Capital Personal Property (Aug 2015) NFS 1852.245-82 Occupancy Management Requirements (Sep 2017) NFS 1845.7101 Forms Preparation NFS 1852.245-73 Financial Reporting of NASA Property in the Custody of
Contractors (Jan 2017) NFS 1852.204-76 Security Requirements for Unclassified Information Technology
Resources NFS 1852.225-70 Export Licenses NFS 1852.242-73 NASA Contractor Financial Management Reporting NFS 1809.500 NASA Guide on Organizational Conflicts of Interest NFS 1852.209-71 Limitation of Future Contracting NFS 1852.237-72 Access to Sensitive Information NFS 1852.237-73 Release of Sensitive Information FAR 52.219-9 Small Business Subcontracting Plan NFS 1852.219-75 Individual Subcontracting Reports FAR 52.222-41 Service Contract Labor Standards FAR 52.222-46 Evaluation of Compensation for Professional Employees FAR 52.222-62 Paid Sick Leave Under Executive Order 13706 FAR 52.237-10 Identification of Uncompensated Overtime
NFS 1822.1008-2
Successorship with Incumbent Contractor Collective Bargaining Agreement
NFS 1831.205-670
Evaluation of Contractor and Subcontractor Compensation for Service Contracts
FAR 15.403-4 Requiring certified cost or pricing data FAR 52.222-1 Notice to the Government of Labor Disputes FAR 42.708, Quick-closeout procedure NFS 1842.708 Quick-closeout procedure NFS 1842.708-70 NASA Quick-closeout procedures
Memoranda
Memo Subject From Date Annual Cybersecurity and Sensitive Unclassified Information Awareness Training
Office of the Chief Information Officer
Sep 14, 2020
Your Role in Protecting NASA: Ensuring No Use of Prohibited IT/Telecommunications Services or Equipment at NASA
NASA CIO, Office of Procurement, and Office of Protective Services
Aug 26, 2020
Web Site Modernization and Enhanced Security Protocols
NASA Administrator May 15, 2019
Authorizing Officials and Authorizing Official Designated Representatives
Chief Information Officer Feb 27, 2019
Government Furnished Equipment (GFE) and Personal Device Business Rules for Enrollment in NASA’s Mobile Device Management (MDM) Service
Chief Information Officer Nov 05, 2018
Use of Personally-Owned Mobile Devices to Connect to NASA Email, Calendar and Contacts Services
Chief Information Officer Oct 25, 2018
Office of the CIO (OCIO) Reviews of Survey Monkey NASA Associate Chief lnformation Officer/Senior Agency Information Security Officer
Jun 07, 2018
Use of Unauthorized Devices Chief Information Officer Apr 16, 2018 Use of NASA Furnished Information Technology Equipment when Deploying in Response to 2017 Natural Disasters
NASA CIO Sep 26, 2017
NASA Information Technology Warning Banner Update
NASA CIO Aug 09, 2017
Updated Guidance for Travelling Abroad with NASA IT Assets
NASA Administrator (Acting)
May 17, 2017
Managing Software in Support of NASA's Mission NASA Administrator (Acting)
May 05, 2017
Federal Source Code Policy: Achieving Efficiency, Transparency, and Innovation through Reusable and Open Source Software, OCIO Memorandum
NASA CIO Nov 07, 2016
Federal Source Code Policy: Achieving Efficiency, Transparency, and Innovation through Reusable and Open Source Software, Framework and Implementation Guide
NASA CIO Nov 07, 2016
ITSD End of Life Vulnerability Memo NASA CIO Mar 30, 2016 NASA Transport Layer Security (TLS) Implementation and Certificate Requirements
ACIO for Information Technology Security Division, and ACIO for Enterprise Services and Integration Division
Mar 17, 2016
EMET Agent Installation Associate CIO for IT Security, Acting
Mar 07, 2016
NASA Policy Regarding Vulnerability Remediation and POA&M Timeline Standards
Information Technology Management Board
(ITMB)
Mar 04, 2016
Recruitment and Retention of a Highly Qualified Federal Workforce
Associate CIO for IT Security, Acting
Nov 13, 2015
Cyber Hygiene Report Actions Associate CIO for IT Security, Acting
Nov 13, 2015
Recruitment and Retention of a Highly Qualified Federal Workforce
Associate CIO for IT Security, Acting
Nov 06, 2015
Apple OS X 10.9 and Earlier Versions are End of Life Associate CIO for IT Security, Acting
Oct 07, 2015
Cyber Hygiene Actions Associate CIO for IT Security, Acting
Oct 07, 2015
Information Technology Security Division Handbook Expiration Dates
Associate Chief Information Officer for Capital Planning and Governance
Sep 17, 2015
Rescinding and/or Archiving Memos NASA Chief Information Officer
Sep 01, 2015
FY15 IT Security and Privacy Awareness Training Reminder
Associate IT Security Division Director (Acting)
Aug 18, 2015
Window Server 2003 Waiver Process Associate IT Security Division Director (Acting)
Aug 15, 2015
Request the cancellation of HBK 2810.03-02 Planning:
Information System Security Plan Template, Requirements, Guidance and Examples
Office of the Chief Information Security Officer
Jul 27, 2015
Personal Use of Government Office Equipment Including Information Technology : International Travel
Senior Agency Information Security Officer
Jul 02, 2015
NASA Agency Common Controls of NIST SP 800-53 revision 4
NASA Senior Agency Information Security Officer (SAISO)
Jun 30, 2015
Roles and Responsibilities for Protecting NASA Sensitive But Unclassified (SBU) Information
Chief Information Officer Jun 24, 2015
Vulnerabilities in Unsupported or End of Life Software (Acting) Senior Agency Information Security Officer
May 28, 2015
Naming Pattern (Acting) Senior Agency Information Security Officer
May 28, 2015
Further Clarification on Mission Focus Review, Recommendation 100
NASA Chief Information Officer
Jan 30, 2015
Interim Guidance for Leveraging Cloud Services While Meeting Information Security Requirements
Senior Agency Information Security Official (Acting)
Jan 28, 2015
Extension Verification 2810-02.05 (Acting) Senior Agency Information Security Officer
Nov 19, 2014
Extension Verification 2810-02.05 (Acting) Senior Agency Information Security Officer
Nov 19, 2014
NASA Guidance for Use of IT Contracts for Supporting End User Services-Revised (Mission Focus Review 137)
Office of the Chief Information Officer
Oct 30, 2014
Electronic and Information Technology Accessibility NASA Chief Information Officer
Oct 10, 2014
Updated Password Requirements for AA Accounts NASA Chief Information Officer (CIO) and the Deputy CIO for Information Technology Security
Jul 02, 2014
Updated Password Requirements for AA Accounts NASA CIO and Deputy CIO for IT Security
Jul 02, 2014
NASA I3P Program Decision Memorandum (Mission Focus Review 137)
Office of the Chief Information Officer
Jun 09, 2014
NASA Guidance for Use of IT Contracts for Supporting End User Services (Mission Focus Review 137)
Associate Administrator Apr 30, 2014
NASA Digital Strategy Associate Administrator for Communications, and Chief Information Officer
Mar 12, 2014
Establishment and Maintenance of Secure Communications
Chief Information Officer Feb 28, 2014
Implementation of National Institute of Standards and Technology Special Publication 800-53, Revision 4
Deputy Chief Information Officer for Information Technology Security
Dec 19, 2013
Establishment of Governance and Policy for Cloud Computing Use at NASA
NASA Chief Information Officer
Nov 22, 2013
Designation of Authorizing Official for Jet Propulsion Lab External Systems
NASA Chief Information Officer
Nov 14, 2013
Minimum Security Requirements for Use of Personally Owned Mobile Devices
NASA Chief Information Officer
Aug 27, 2013
Additional 90-day extension: Blanket waiver for use of Filevault 2.0 to meet Data at Rest (DAR) Encryption Requirements
Chief Information Officer May 07, 2013
Delegation of Authorizing Official Designation to Center and Mission Directorate Chief Information Officers
Office of the Chief Information Officer
Apr 02, 2013
NASA ACES Secure Virtual Team Meeting (SVTM) Approved for Secure Meetings and Communication of SBU Data
Deputy CIO for Information Security
Feb 05, 2013
Cancellation of PDM 2012-064 Data At Rest (DAR) Waiver Process and issuance of a new PDM addressing Alternate DAR Encryption Products
Chief Information Officer Jan 27, 2013
Configuration Guidance for Computer Operating Systems
Valarie Burks Dec 17, 2012
Breach of Personally Identifiable Information (PII) [Laptop DAR/Encryption]
Associate Deputy Administrator
Nov 13, 2012
Rescinding and/or Archiving Information Technology (IT) Security Memoranda
Chief Information Officer Sep 20, 2012
NASA CIO and Assistant Administrator of Procurement Memorandum – Solutions for Enterprise-Wide Procurement (SEWP) Contract (Mission Focus Review 137)
Chief Information Officer, Office of the Chief Information Officer, Assistant Administrator for Procurement, and Deputy Chief Acquisition Officer
Apr 03, 2011
Protection of Sensitive Agency Information Charles F. Bolden, Jr., NASA Administrator
Aug 15, 2012
Delegation of Waiver Authority and Responsibility for Vulnerability Scanning Requirements
Chief Information Officer (Acting)
May 06, 2009
Roles and Responsibilities for Protecting NASA Sensitive But Unclassified (SBU) Information
Chief Information Officer (Acting)
Apr 27, 2009
NASA Records Management Reviews NASA Chief Information Officer
Jul 23, 2008
Remote Access to Personally Identifiable Information
(PII)
NASA Chief Information Officer
Jun 09, 2008
Requirement to Log and Verify Sensitive Data Extracts NASA Chief Information Officer
Jun 09, 2008
FY09 Acquisition of IT Products and Services Guidance NASA Chief Information Officer
Mar 27, 2008
Cancellation of CIO Executive Notice 12-96, "NASA Electronic Mail"
NASA Chief Information Officer
Mar 03, 2008
Designation of FIPS-199 Impact Level for NASA OAIT Data Center Systems
NASA Chief Information Officer
Jul 10, 2007
Associate Administrator's Mission Focus Review (MFR) Decision Memorandum for Phase 1 Recommendations 7, 100, 137
Associate Administrator Jul 09, 2007
Update of NASA Web site Privacy Policy NASA Chief Information Officer
Nov 28, 2005
Update to Information Technology (IT) Purchasing Limitations
NASA Chief Information Officer
May 25, 2005
Memoranda
File details come from the government source that posted it. Updated .