ATT Y - NCAPS Contract Demarks Draft.pdf

PDF 266 KB Posted

Attached to
NASA's Consolidated Applications and Platform Services (NCAPS) requirement Federal contract opportunity
Solicitation number
80TECH22R0002
Issued by
National Aeronautics and Space Administration

View the file

Other files for this federal contract opportunity

Other files attached to NASA's Consolidated Applications and Platform Services (NCAPS) requirement, newest first.
File Type Posted
ATT Z - NCAPS Teams Scenario Data Draft updated 9 1 22.pdf PDF
NCAPS Preliminary Draft RFP.pdf PDF
ATT L - Service Catalog Descriptions - Draft.pdf PDF
ATT M - Fixed Price Service Delivery Standards and Metrics - Draft.pdf PDF
ATT N - IT Security Management Plan Draft.pdf PDF
ATT P - Deliverable Products and Services (DPS) - Draft.pdf PDF
ATT R - CATS - iSite Contractor On-boarding Guide.pdf PDF
ATT X - IAGP - Draft.pdf PDF
Preliminary DRFP cover letter Signed.pdf PDF
ATT A - Performance Work Statement - Draft.pdf PDF
ATT B - DRDs - Draft.pdf PDF
ATT C - Wage Determinations - Draft.pdf PDF
ATT D - Applicable Documents List Draft.pdf PDF
ATT H - Phase-in Plan.pdf PDF
ATT J - Fixed Price Sprint Story Point Process - Draft.pdf PDF
ATT K - APPLICATION SUPPORT LEVELS Draft.pdf PDF
ATT O - Contract Management Plan - Draft.pdf PDF
ATT T - QASP - Draft.pdf PDF
ATT U - Labor Category Position Descriptions - Draft.pdf PDF
ATT W - Financial Management Reporting - Draft.pdf PDF
NCAPS Preliminary DRFP Comment Template.xlsx XLSX spreadsheet
Exhibit 1-NCAPS Pricing Matrix.xlsx XLSX spreadsheet
Enclosure 1 Labor History (Consolidated) - Draft.xlsx XLSX spreadsheet
Enclosure 2 WYE Attachment 1 Draft.xlsx XLSX spreadsheet
ATT G - Acronyms and Abbreviations - Draft.pdf PDF
ATT Q - DD Form 254 Draft.pdf PDF
Exhibit 2 Small Business Subcontracting Plan Goals.xlsx XLSX spreadsheet
ATT E - SHE Plan - Draft.pdf PDF
ATT F - ORGANIZATIONAL CONFLICT OF INTEREST (OCI) PLAN - Draft.pdf PDF
ATT S - Application Inventory.xlsx XLSX spreadsheet
ATT V - SB Subcontracting Plan - Draft.pdf PDF
ATT Z - NCAPS Teams Scenario Data - Draft.pdf PDF
Show all 32

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT Y

NASA CONSOLIDATED APPLICATIONS AND PLATFORM

SERVICES (NCAPS)

NCAPS – CONTRACTS DEMARKS

RFP 80TECH22R0002

CONTRACT #TBD

DATE: TBD

Microsoft SQL Database Demarks

Tasks NCAPS AEGIS Comments OS Loading X OS Patching X Certificates & Permissions Management

(OS)

X Coordination with NCAPS; least privileged; NAMS workflow creation

Troubleshooting Expertise Provided X X AEGIS troubleshooting will stop at the OS level.

DB SW Loaded X X AEGIS loads according to the request submitted by NCAPS.

Coordination between contracts required.

DB SW Patching

X X NCAPS responsible for testing patch prior to patching and verification of functionality post patching. Coordination between contracts required.

Backup & Restores Management. Server Wide Databases X

AEGIS performs routine DB backups and stores for 30 days; anything outside of this would need to be requested and coordinated between contractors.

Initial DB instance created X NCAPS to also specify storage size Individual DB Management X IT Security Plan Creation and Maintenance Infrastructure

X

Application Specific data for IT Security Plan X

Non-Microsoft SQL Database (Oracle, mysql, mongodb, etc) Demarks

OS Loading X OS Patching X Certificates & Permissions Management

(OS)

X Coordination with NCAPS; least privileged; NAMS workflow creation

Troubleshooting Expertise Provided X X AEGIS Troubleshooting stops at OS DB SW Loaded X DB SW Patching X Backup & Restores Management. Server Wide Databases X

NCAPS configures the database backups and performs the database restore.

AEGIS maintenance the responsibility for storage, protection, and any offsite DR capabilities.

Initial DB instance created X Individual DB Management X IT Security Plan Creation and Maintenance/Infrastructure

X

Middleware (Java, ColdFusion, WordPress, etc.)

OS Loading X OS Patching X Certificates & Permissions Management

(OS)

X Coordination with NCAPS; least privileged; NAMS workflow creation

Troubleshooting Expertise Provided X X AEGIS troubleshooting stops at OS Certificates & Permissions Management (Web server and middleware; e.g., Java Keystore)

X OS and Middleware

Day to Day Operations Management (Middleware Configuration) X

Plug-in management X Middleware permissions X Middleware patching X IT Security Plan Creation and Maintenance

X

COTS software (Windchill, SharePoint, GIS)

OS Loading X OS Patching X Certificates & Permissions Management

(OS)

X Coordination with NCAPS; least privileged;

NAMS workflow creation

Troubleshooting Expertise Provided X X AEGIS troubleshooting stops at OS Certificates & Permissions Management (Web server and middleware e.g., Java Keystore)

X OS and COTS that's required beyond the baseline that's provided by AEGIS that's unique to the COTS product.

Day to Day Operations Management (COTS Configuration) X

COTS permissions X COTS patching X IT Security Plan Creation and Maintenance/Infrastructure

X

OnPrem Containers

OS Loading X OS Patching X Certificates & Permissions Management

(OS)

X Coordination with NCAPS; least privileged;

NAMS workflow creation

Troubleshooting Expertise Provided X X AEGIS troubleshooting stops at OS VM Load Kubernetes SW X VM Maintance Kubernetes SW X Configuration Management & Certificates (Day-to-Day Operations) (Kubernetes) X

Internal Kubernetes Security Management (Container & Container to Container) X

Workflows (Creation & Configuration Management) X Workflows/DevSecOps Pipeline

Container Templates (including Containerized DB) (Creation & Configuration Management)

X

IT Security Plan Creation and Maintenance/Infrastructure

X

(08/2022)

Cloud Containers

Security & Permissions Management (Kubernetes) X

Configuration Management & Certificates (Day-to-Day Operations) (Kurbernetes) X

Internal Kubernetes Security Management (Container & Container to Container) X

Workflows (Creation & Configuration Management) X

Container Templates (including Containerized DB) (Creation & Configuration Management)

Database Connection Management X IT Security Plan Creation and Maintenance X Infrastructure (CPU, RAM, Storage) needed to run Cloud Containers X

Cyber Security Tasks NCAPS NCAPS

ICAM

AEGIS CYPRESS Comments

NASA

CONTINUOUS

DIAGNOTICS &

MITIGATION

(CDM) Tool (e.g., BigFix, ITSEC-

EDW)

X X

AEGIS-Install, Conf, Manage. CYPRES-Provide tool and ensure compliance.

Symantec Endpoint Protection - Anti- Malware and Anti- Virus

X X

AEGIS-Install, Conf, Manage. CYPRES-Provide tool and ensure compliance.

Trust Anchor Management (NTAM) - Per

NASA-SPEC-2664

X X AEGIS-Install, Conf, Manage. ICAM-Provide Certs. NOTE:

NTAM is a NASA-provided block of trusted Public Key Infrastructure (PKI) root and intermediate certificates.

Agency Network Access Control (NAC) solution

X AEGIS-Ensure compliance, Install, Configure, Manage.

Transport Layer Security (TLS) Security Configuration X X

NCAPS -Install, Conf, Manage. ICAM-Provides Certs.

NOTE: TLS is commonly used for web services, electronic mail, instant messaging, and other protocols in order to provide integrity and confidentiality of information conveyed by the protocol. This TLS specification includes guidance for Windows operating systems as well as Linux web services such as Apache.

Determination of Authorization Boundaries

X X Coordinated effort between NCAPS and AEGIS

Agency Common Control Identification

ICAM

AEGIS CYPRESS Comments

Identify Infrastructure Security Controls for Application Inheritance

X X

NCAPS-Identify which security controls are being inherited and document deviations. AEGIS-To identify and document all security controls.

NOTE: This refers to infrastructure plans that contains applications. Coordinated effort between NCAPS and AEGIS.

Application Security Categorization (Low, Mod, High) X

In accordance with FIPS PUB 199. NCAPS to categorized to ensure the apps get hosted in the appropriate infrastructure category level.

Note: AEGIS is responsible for correctly categorizing their infrastructure

Application:

Security Control Selection and Tailoring

X X Coordinated deviations with AEGIS prior to implementing them, to ensure that they accept the risk and/or able to isolate the risk and/or mitigate the associated risk

Application: NIST 800-53 Rev 5 Security Control Implementation

X Note: AEGIS is responsible for implementing rev 5 controls for infrastructure

For Application SSPs currently complaint with NIST 800-53 rev 4, transition from NIST 800-53 Rev 5 to Security Control implementation and documentation into infrastructure SSPs

X X

NCAPS & AEGIS contractors coordinate

AEGIS CYPRESS Comments

For SSPs currently complain with NIST 800-53 rev 4, transition from NIST 800-53 Rev 4 to NIST 800-53 Rev 5 Security Control implementation & documentation - Infrastructure

X X

AEGIS will need to inform and coordinate with NCAPS if any control changes impact the applications for testing prior to implementation

Infrastructure Security Plan Development in Risk Information Security Compliance System

(RISCS)

Infrastructure Security Plan Maintenance in Risk Information Security Compliance System

(RISCS)

Application Security Plan Development in Risk Information Security Compliance System

(RISCS)

X X

NCAPS & AEGIS contractors coordinate Application PIAs, PTAs, SIAs, POA&Ms, and RBDs are attached to the infrastructure SSP in RISCS. Any controls deviations are also documented in RISCS.

AEGIS CYPRESS Comments

Application Security Plan Maintenance in Risk Information Security Compliance System

(RISCS)

X X

NCAPS & AEGIS contractors coordinate How are apps incorporated in the infrastructure security plan?

For current application-based SSPs, the migration/inclusion of application-based security plans into infrastructure-level security plans

X X

NCAPS & AEGIS contractors coordinate Metrics to hold the contractor the XX number of transitions per

XX

Application Plan of Action & Milestone (POA&M) and inclusion into the infrastructure security plan in

RISCS

X X

NCAPS & AEGIS contractors coordinate.

Completion of RISCS Data Import Form: Adversarial Threat Sources Events Import File 8 February 2022

(NEW)

X X X

NCAPS & AEGIS contractors coordinate.

AEGIS coordinates review with stakeholders (e.g., SOC, NOSC, CSPP, system and application owners) to determine relevancy before uploading as this, when uploaded into RISCS, will automatically populate a value that uniquely identifies the record across all applications within the system. CYPRESS-Creates and maintains the form on SharePoint.

AEGIS CYPRESS Comments

Completion of RISCS Data Import Form: Create New POAMs for an SSP Submittal Form 6 October 2021

X X

NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form: Create New RBDs for an SSP Submittal Form 6 October 2021

X X

NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form: HTTPS Internal POA&M Device Upload File

The example within the document is for a "Multi-Channel Digital TV", which would be eMITS.

https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form: HTTPS Internal RBD Device Upload File

The example within the document is for a "Multi-Channel Digital TV", which would be eMITS.

https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form:

Implementation and Assessment Import File Updated 2 Sept

X X

NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form: NASA Manual Inventory (NMI) Template

X X

NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

AEGIS CYPRESS Comments

Completion of RISCS Data Import Form: Non- Adversarial Threat Sources Events Import File 8 February 2022

(NEW)

X X

NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Completion of RISCS Data Import Form: POA&M or RBD Hardware Upload File

X X

NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx

Privacy Threshold Assessments (PTA) X X

Separate Application and Infrastructure PTAs and PIAs may be required. NACPS it responsible for application related PTAs and PIAs. PTAs and PIA's must be uploaded in RISCS.

Privacy Impact Assessments (PIA) X X

Separate Application and Infrastructure PTAs and PIAs may be required. NACPS it responsible for application related PTAs and PIAs. PTAs and PIA's must be uploaded in RISCS.

Systems of Records Notice (SORN) X X NCAPS & AEGIS contractors coordinate

System Security Risk Assessments

Complete assessment and develop the Security Assessment

Report (SAR) and provide the report the system own to be uploaded in

RISCS

AEGIS CYPRESS Comments

Security Information and Event Management (SIEM) Tool Installation

X Provide tool and ensure compliance

Security Information and Event Management (SIEM) Tool Configuration & Identification of events to support and after the fact investigation

X X

NCAPS & AEGIS contractors coordinate Note: Splunk is provided as an enterprise solution. Some centers are still migrating to the enterprise solution. At MSFC AlienVault is configured for application event management and SolarWinds Security and Monitoring is configured for event management for the operating systems is interim solution. Other centers may also be in the process of migrating and have unique implementations.

KSC has a unique tool and does not use Splunk at this time.

Source for Providing Audit Logs to the SOC (raw logs)

Sec Configuration Management Plan X X Requires separate Application and Infrastructure plans

Control Tools

Control Board X X Non-OCIO development efforts, separate non-center boards are established.

Configuration Control Approvals X X NCAPS & AEGIS contractors coordinate

Baseline Configuration Documentation

X X NCAPS & AEGIS contractors coordinate

Security Impact Assessments (SIA) for Application changes

X Who will be able to upload these into RISCS?

Requirements needed from CSPP to understand the expectations.

AEGIS CYPRESS Comments

Security Impact Assessments (SIA) for Infrastructure changes

X

Requirements needed from CSPP to understand the expectations.

Approved Standard Configuration Implementation

X X NCAPS & AEGIS contractors coordinate CSPP-Provides the standards on CSET

Approved Standard Configuration Validation

X X The Agency standard metrics requires 90% compliance. CSPP- Provides the standards on CSET

Contingency Plan X X NCAPS & AEGIS contractors coordinate Contingency Exercises X X NCAPS & AEGIS contractors coordinate

Continuity of Operation Plans

(COOP)

X X NCAPS & AEGIS contractors coordinate

Crisis Management Plan (CMP)

Disaster Recovery Plan X X NCAPS & AEGIS contractors coordinate

Incident Response Plan - Application

X

APS has its own plan: IS90 Cyber Incident Response Plan (CIRP) IS90-AAO-IA-PROC-SEC-016; the financial statement auditors request and review this document annually. MSFC has its own plan: MSFC ITS SOP 0005, MSFC Information Security Incident Response and Management

Incident Response Plan - Infrastructure

OS Level Permissions

NAMS Workflow Creation for OS Level Permissions/Access

AEGIS CYPRESS Comments

NAMS Workflow Creation for Application-Level

NAMS Workflow Creation for Database Level

Recurring reviews of all accounts and access privileges -

OS

access privileges - Application access privileges - Database

NASA Domain Name System (DNS) Registration

- OS

NASA Domain Name System (DNS) Registration

- Web App

AEGIS CYPRESS Comments

Removal of retired systems from Active Directory, DNS Dynamic Host Configuration Protocol (DHCP) Internet Protocol Address Management (IPAM) (DDI) and pertinent Cybersecurity asset databases.

X X X

NCAPS & AEGIS contractors coordinate

Code vulnerability scan, analysis, and remediation support (e.g., Burp Suite, Atomic Scan)

X X

NCAPS must be proficient in executing scans, producing, and analyzing reports, remediating findings, and installing, configuring, and managing the tool. AEGIS is responsible for hosting the tool(s).

Web vulnerability scan, analysis, and remediation support (e.g., Nessus, WebInspect)

X X X

NCAPS & AEGIS contractors coordinate - NCAPS must be proficient in executing scans, producing, and analyzing reports, and remediating findings. AEGIS is responsible for hosting the tool(s). Cypress is responsible for providing/approving tools.

Database vulnerability scan, analysis, and remediation support

X X NCAPS & AEGIS contractors coordinate.

NCAP-Must be proficient in executing scans, producing, and analyzing reports, and remediating findings.

AEGIS-Hosts the tool(s).

Operating system vulnerability scan, analysis, and remediation support (Currently Nessus)

X

AEGIS-Must be proficient in executing scans, producing, and analyzing reports, and remediating findings - Also Hosts the tool(s).

CYPRESS-Provides the approved standard configurations;

ensures compliance; tracks agency-wide compliance metrics via BigFix and ITSEC-EDW.

AEGIS CYPRESS Comments

Security Configuration Standards Implementation -

OS

X X

AEGIS-Responsible for Implementing and validation - Also Hosts the tool(s).

CYPRESS-Provides the approved standard configurations;

ensures compliance; tracks agency-wide compliance metrics via BigFix and ITSEC-EDW.

Security Configuration Standards Implementation -

DB

X X X

NCAPS & AEGIS contractors coordinate.

NCAPS-Responsible for Implementing and validating.

AEGIS-Hosts the tool(s).

CYPRESS: Provides the approved standard configurations;

ensures compliance; tracks agency-wide compliance metrics via BigFix and ITSEC-EDW.

Security Configuration Standards Implementation -

APP

X X X

NCAPS & AEGIS contractors coordinate.

NCAPS-Responsible for Implementing and validating.

AEGIS-Hosts the tool(s).

CYPRESS: Provides the approved standard configurations;

ensures compliance; tracks agency-wide compliance metrics via BigFix and ITSEC-EDW.

Security Configuration Standards Verification Tool -

APP

Launchpad Integration - OS

Integration - APP X

Integration - DB X

Integration - Web X

NASA Consolidated Active Directory (NCAD) System Registration (OS)

X X ICAM-Manages NASA Consolidated Active Directory (NCAD).

AEGIS CYPRESS Comments

Procurement of Cloud Technologies

X X

Both NCAPS and AEGIS will evaluate and make recommendations on the adoption of various cloud technologies such as cloud environments (e.g., AWS GovCloud, Azure Government Cloud, Salesforce Government Cloud, SAP NS2 Cloud, Slack); cloud services (e.g., Amazon Web Services, iSite, Snowflake); and cloud service models (e.g., IaaS, PaaS, SaaS).

The government may purchase cloud services directly from the vendor/FedRamp Market Place or via the either contract vehicle

Data at Rest (DAR) Windows OS - BitLocker

X X X

ICAM- Maintain policy settings in Active Directory (AD). Some configuration settings are pushed from NCAN via AD policy settings.

AEGIS-Install, Conf, Manage.

CYPRESS-Provide tool and ensure compliance.

NOTE: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.

https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/

AEGIS CYPRESS Comments

Data at Rest (DAR) Linux - Linux Unified Key Setup

(LUKS)

X X

AEGIS-Install, Conf, Manage.

CYPRESS-Provide tool and ensure compliance.

NOTE: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.

https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/

Personal Identity Verification Mandatory (PIV- M)/multi-factor authentication (MFA) Linux

X X

AEGIS-Install, Conf, Manage.

CYPRESS-Provide tool and ensure compliance.

NOTE: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.

For both PIV and MFA on Linux OSs, local authentication uses Pluggable Authentication Modules (PAM), while network authentication uses OpenSSH. If a system is PIV compliant, it is MFA compliant.

In order to comply with Agency-wide PIV-M requirements, Linux administrators must employ an authentication option that has been reviewed and approved by the Agency PIV working groups.

(https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/)

AEGIS CYPRESS Comments

Personal Identity Verification Mandatory (PIV- M)/multi-factor authentication (MFA) Windows

X X

AEGIS-Install, Conf, Manage.

CYPRESS-Provide tool and ensure compliance.

NOTE: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.

Windows systems comply with PIV-M requirements by setting the configuration called “Interactive logon: Require Windows Hello for Business or smart card” to “enabled”. This setting is applied on Agency Windows systems via the ASCS Windows security specification group policy.

Note: When a Windows system joins the NDC Active Directory domain, PIV-M compliance occurs automatically via top-level domain Group Policy “AG-GPO- ASPEC_B1_SmartcardOnlyLogon” (https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/)

Automated Performance Monitoring Tools -

OS

X AEGIS-Install, Conf, Manage

Automated Performance Monitoring Tools - APP (e.g., Nagios, Whatsapp Gold)

X X

NCAPS & AEGIS contractors coordinate.

NCAPS-May install application performance monitoring tool on the OS or may have to coordinate with AEGIS in instances where they own OS level monitoring tools that can be configured to monitor application performance. AEGIS-Install, Conf, Manage tool(s).

File details come from the government source that posted it. Updated .