ATT Y - NCAPS Contract Demarks Draft.pdf
PDF 266 KB Posted
- Attached to
- NASA's Consolidated Applications and Platform Services (NCAPS) requirement Federal contract opportunity
- Solicitation number
- 80TECH22R0002
View the file
Other files for this federal contract opportunity
Show all 32
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT Y
NASA CONSOLIDATED APPLICATIONS AND PLATFORM
SERVICES (NCAPS)
NCAPS – CONTRACTS DEMARKS
RFP 80TECH22R0002
CONTRACT #TBD
DATE: TBD
Microsoft SQL Database Demarks
Tasks NCAPS AEGIS Comments OS Loading X OS Patching X Certificates & Permissions Management
(OS)
X Coordination with NCAPS; least privileged; NAMS workflow creation
Troubleshooting Expertise Provided X X AEGIS troubleshooting will stop at the OS level.
DB SW Loaded X X AEGIS loads according to the request submitted by NCAPS.
Coordination between contracts required.
DB SW Patching
X X NCAPS responsible for testing patch prior to patching and verification of functionality post patching. Coordination between contracts required.
Backup & Restores Management. Server Wide Databases X
AEGIS performs routine DB backups and stores for 30 days; anything outside of this would need to be requested and coordinated between contractors.
Initial DB instance created X NCAPS to also specify storage size Individual DB Management X IT Security Plan Creation and Maintenance Infrastructure
X
Application Specific data for IT Security Plan X
Non-Microsoft SQL Database (Oracle, mysql, mongodb, etc) Demarks
OS Loading X OS Patching X Certificates & Permissions Management
(OS)
X Coordination with NCAPS; least privileged; NAMS workflow creation
Troubleshooting Expertise Provided X X AEGIS Troubleshooting stops at OS DB SW Loaded X DB SW Patching X Backup & Restores Management. Server Wide Databases X
NCAPS configures the database backups and performs the database restore.
AEGIS maintenance the responsibility for storage, protection, and any offsite DR capabilities.
Initial DB instance created X Individual DB Management X IT Security Plan Creation and Maintenance/Infrastructure
X
Middleware (Java, ColdFusion, WordPress, etc.)
OS Loading X OS Patching X Certificates & Permissions Management
(OS)
X Coordination with NCAPS; least privileged; NAMS workflow creation
Troubleshooting Expertise Provided X X AEGIS troubleshooting stops at OS Certificates & Permissions Management (Web server and middleware; e.g., Java Keystore)
X OS and Middleware
Day to Day Operations Management (Middleware Configuration) X
Plug-in management X Middleware permissions X Middleware patching X IT Security Plan Creation and Maintenance
X
COTS software (Windchill, SharePoint, GIS)
OS Loading X OS Patching X Certificates & Permissions Management
(OS)
X Coordination with NCAPS; least privileged;
NAMS workflow creation
Troubleshooting Expertise Provided X X AEGIS troubleshooting stops at OS Certificates & Permissions Management (Web server and middleware e.g., Java Keystore)
X OS and COTS that's required beyond the baseline that's provided by AEGIS that's unique to the COTS product.
Day to Day Operations Management (COTS Configuration) X
COTS permissions X COTS patching X IT Security Plan Creation and Maintenance/Infrastructure
X
OnPrem Containers
OS Loading X OS Patching X Certificates & Permissions Management
(OS)
X Coordination with NCAPS; least privileged;
NAMS workflow creation
Troubleshooting Expertise Provided X X AEGIS troubleshooting stops at OS VM Load Kubernetes SW X VM Maintance Kubernetes SW X Configuration Management & Certificates (Day-to-Day Operations) (Kubernetes) X
Internal Kubernetes Security Management (Container & Container to Container) X
Workflows (Creation & Configuration Management) X Workflows/DevSecOps Pipeline
Container Templates (including Containerized DB) (Creation & Configuration Management)
X
IT Security Plan Creation and Maintenance/Infrastructure
X
(08/2022)
Cloud Containers
Security & Permissions Management (Kubernetes) X
Configuration Management & Certificates (Day-to-Day Operations) (Kurbernetes) X
Internal Kubernetes Security Management (Container & Container to Container) X
Workflows (Creation & Configuration Management) X
Container Templates (including Containerized DB) (Creation & Configuration Management)
Database Connection Management X IT Security Plan Creation and Maintenance X Infrastructure (CPU, RAM, Storage) needed to run Cloud Containers X
Cyber Security Tasks NCAPS NCAPS
ICAM
AEGIS CYPRESS Comments
NASA
CONTINUOUS
DIAGNOTICS &
MITIGATION
(CDM) Tool (e.g., BigFix, ITSEC-
EDW)
X X
AEGIS-Install, Conf, Manage. CYPRES-Provide tool and ensure compliance.
Symantec Endpoint Protection - Anti- Malware and Anti- Virus
X X
AEGIS-Install, Conf, Manage. CYPRES-Provide tool and ensure compliance.
Trust Anchor Management (NTAM) - Per
NASA-SPEC-2664
X X AEGIS-Install, Conf, Manage. ICAM-Provide Certs. NOTE:
NTAM is a NASA-provided block of trusted Public Key Infrastructure (PKI) root and intermediate certificates.
Agency Network Access Control (NAC) solution
X AEGIS-Ensure compliance, Install, Configure, Manage.
Transport Layer Security (TLS) Security Configuration X X
NCAPS -Install, Conf, Manage. ICAM-Provides Certs.
NOTE: TLS is commonly used for web services, electronic mail, instant messaging, and other protocols in order to provide integrity and confidentiality of information conveyed by the protocol. This TLS specification includes guidance for Windows operating systems as well as Linux web services such as Apache.
Determination of Authorization Boundaries
X X Coordinated effort between NCAPS and AEGIS
Agency Common Control Identification
ICAM
AEGIS CYPRESS Comments
Identify Infrastructure Security Controls for Application Inheritance
X X
NCAPS-Identify which security controls are being inherited and document deviations. AEGIS-To identify and document all security controls.
NOTE: This refers to infrastructure plans that contains applications. Coordinated effort between NCAPS and AEGIS.
Application Security Categorization (Low, Mod, High) X
In accordance with FIPS PUB 199. NCAPS to categorized to ensure the apps get hosted in the appropriate infrastructure category level.
Note: AEGIS is responsible for correctly categorizing their infrastructure
Application:
Security Control Selection and Tailoring
X X Coordinated deviations with AEGIS prior to implementing them, to ensure that they accept the risk and/or able to isolate the risk and/or mitigate the associated risk
Application: NIST 800-53 Rev 5 Security Control Implementation
X Note: AEGIS is responsible for implementing rev 5 controls for infrastructure
For Application SSPs currently complaint with NIST 800-53 rev 4, transition from NIST 800-53 Rev 5 to Security Control implementation and documentation into infrastructure SSPs
X X
NCAPS & AEGIS contractors coordinate
AEGIS CYPRESS Comments
For SSPs currently complain with NIST 800-53 rev 4, transition from NIST 800-53 Rev 4 to NIST 800-53 Rev 5 Security Control implementation & documentation - Infrastructure
X X
AEGIS will need to inform and coordinate with NCAPS if any control changes impact the applications for testing prior to implementation
Infrastructure Security Plan Development in Risk Information Security Compliance System
(RISCS)
Infrastructure Security Plan Maintenance in Risk Information Security Compliance System
(RISCS)
Application Security Plan Development in Risk Information Security Compliance System
(RISCS)
X X
NCAPS & AEGIS contractors coordinate Application PIAs, PTAs, SIAs, POA&Ms, and RBDs are attached to the infrastructure SSP in RISCS. Any controls deviations are also documented in RISCS.
AEGIS CYPRESS Comments
Application Security Plan Maintenance in Risk Information Security Compliance System
(RISCS)
X X
NCAPS & AEGIS contractors coordinate How are apps incorporated in the infrastructure security plan?
For current application-based SSPs, the migration/inclusion of application-based security plans into infrastructure-level security plans
X X
NCAPS & AEGIS contractors coordinate Metrics to hold the contractor the XX number of transitions per
XX
Application Plan of Action & Milestone (POA&M) and inclusion into the infrastructure security plan in
RISCS
X X
NCAPS & AEGIS contractors coordinate.
Completion of RISCS Data Import Form: Adversarial Threat Sources Events Import File 8 February 2022
(NEW)
X X X
NCAPS & AEGIS contractors coordinate.
AEGIS coordinates review with stakeholders (e.g., SOC, NOSC, CSPP, system and application owners) to determine relevancy before uploading as this, when uploaded into RISCS, will automatically populate a value that uniquely identifies the record across all applications within the system. CYPRESS-Creates and maintains the form on SharePoint.
AEGIS CYPRESS Comments
Completion of RISCS Data Import Form: Create New POAMs for an SSP Submittal Form 6 October 2021
X X
NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx
Completion of RISCS Data Import Form: Create New RBDs for an SSP Submittal Form 6 October 2021
X X
NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx
Completion of RISCS Data Import Form: HTTPS Internal POA&M Device Upload File
The example within the document is for a "Multi-Channel Digital TV", which would be eMITS.
https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx
Completion of RISCS Data Import Form: HTTPS Internal RBD Device Upload File
The example within the document is for a "Multi-Channel Digital TV", which would be eMITS.
https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx
Completion of RISCS Data Import Form:
Implementation and Assessment Import File Updated 2 Sept
X X
NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx
Completion of RISCS Data Import Form: NASA Manual Inventory (NMI) Template
X X
NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx
AEGIS CYPRESS Comments
Completion of RISCS Data Import Form: Non- Adversarial Threat Sources Events Import File 8 February 2022
(NEW)
X X
NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx
Completion of RISCS Data Import Form: POA&M or RBD Hardware Upload File
X X
NCAPS & AEGIS contractors coordinate https://nasa.sharepoint.com/sites/RISCS_C/SitePages/Resources( 1).aspx
Privacy Threshold Assessments (PTA) X X
Separate Application and Infrastructure PTAs and PIAs may be required. NACPS it responsible for application related PTAs and PIAs. PTAs and PIA's must be uploaded in RISCS.
Privacy Impact Assessments (PIA) X X
Separate Application and Infrastructure PTAs and PIAs may be required. NACPS it responsible for application related PTAs and PIAs. PTAs and PIA's must be uploaded in RISCS.
Systems of Records Notice (SORN) X X NCAPS & AEGIS contractors coordinate
System Security Risk Assessments
Complete assessment and develop the Security Assessment
Report (SAR) and provide the report the system own to be uploaded in
RISCS
AEGIS CYPRESS Comments
Security Information and Event Management (SIEM) Tool Installation
X Provide tool and ensure compliance
Security Information and Event Management (SIEM) Tool Configuration & Identification of events to support and after the fact investigation
X X
NCAPS & AEGIS contractors coordinate Note: Splunk is provided as an enterprise solution. Some centers are still migrating to the enterprise solution. At MSFC AlienVault is configured for application event management and SolarWinds Security and Monitoring is configured for event management for the operating systems is interim solution. Other centers may also be in the process of migrating and have unique implementations.
KSC has a unique tool and does not use Splunk at this time.
Source for Providing Audit Logs to the SOC (raw logs)
Sec Configuration Management Plan X X Requires separate Application and Infrastructure plans
Control Tools
Control Board X X Non-OCIO development efforts, separate non-center boards are established.
Configuration Control Approvals X X NCAPS & AEGIS contractors coordinate
Baseline Configuration Documentation
X X NCAPS & AEGIS contractors coordinate
Security Impact Assessments (SIA) for Application changes
X Who will be able to upload these into RISCS?
Requirements needed from CSPP to understand the expectations.
AEGIS CYPRESS Comments
Security Impact Assessments (SIA) for Infrastructure changes
X
Requirements needed from CSPP to understand the expectations.
Approved Standard Configuration Implementation
X X NCAPS & AEGIS contractors coordinate CSPP-Provides the standards on CSET
Approved Standard Configuration Validation
X X The Agency standard metrics requires 90% compliance. CSPP- Provides the standards on CSET
Contingency Plan X X NCAPS & AEGIS contractors coordinate Contingency Exercises X X NCAPS & AEGIS contractors coordinate
Continuity of Operation Plans
(COOP)
X X NCAPS & AEGIS contractors coordinate
Crisis Management Plan (CMP)
Disaster Recovery Plan X X NCAPS & AEGIS contractors coordinate
Incident Response Plan - Application
X
APS has its own plan: IS90 Cyber Incident Response Plan (CIRP) IS90-AAO-IA-PROC-SEC-016; the financial statement auditors request and review this document annually. MSFC has its own plan: MSFC ITS SOP 0005, MSFC Information Security Incident Response and Management
Incident Response Plan - Infrastructure
OS Level Permissions
NAMS Workflow Creation for OS Level Permissions/Access
AEGIS CYPRESS Comments
NAMS Workflow Creation for Application-Level
NAMS Workflow Creation for Database Level
Recurring reviews of all accounts and access privileges -
OS
access privileges - Application access privileges - Database
NASA Domain Name System (DNS) Registration
- OS
NASA Domain Name System (DNS) Registration
- Web App
AEGIS CYPRESS Comments
Removal of retired systems from Active Directory, DNS Dynamic Host Configuration Protocol (DHCP) Internet Protocol Address Management (IPAM) (DDI) and pertinent Cybersecurity asset databases.
X X X
NCAPS & AEGIS contractors coordinate
Code vulnerability scan, analysis, and remediation support (e.g., Burp Suite, Atomic Scan)
X X
NCAPS must be proficient in executing scans, producing, and analyzing reports, remediating findings, and installing, configuring, and managing the tool. AEGIS is responsible for hosting the tool(s).
Web vulnerability scan, analysis, and remediation support (e.g., Nessus, WebInspect)
X X X
NCAPS & AEGIS contractors coordinate - NCAPS must be proficient in executing scans, producing, and analyzing reports, and remediating findings. AEGIS is responsible for hosting the tool(s). Cypress is responsible for providing/approving tools.
Database vulnerability scan, analysis, and remediation support
X X NCAPS & AEGIS contractors coordinate.
NCAP-Must be proficient in executing scans, producing, and analyzing reports, and remediating findings.
AEGIS-Hosts the tool(s).
Operating system vulnerability scan, analysis, and remediation support (Currently Nessus)
X
AEGIS-Must be proficient in executing scans, producing, and analyzing reports, and remediating findings - Also Hosts the tool(s).
CYPRESS-Provides the approved standard configurations;
ensures compliance; tracks agency-wide compliance metrics via BigFix and ITSEC-EDW.
AEGIS CYPRESS Comments
Security Configuration Standards Implementation -
OS
X X
AEGIS-Responsible for Implementing and validation - Also Hosts the tool(s).
CYPRESS-Provides the approved standard configurations;
ensures compliance; tracks agency-wide compliance metrics via BigFix and ITSEC-EDW.
Security Configuration Standards Implementation -
DB
X X X
NCAPS & AEGIS contractors coordinate.
NCAPS-Responsible for Implementing and validating.
AEGIS-Hosts the tool(s).
CYPRESS: Provides the approved standard configurations;
ensures compliance; tracks agency-wide compliance metrics via BigFix and ITSEC-EDW.
Security Configuration Standards Implementation -
APP
X X X
NCAPS & AEGIS contractors coordinate.
NCAPS-Responsible for Implementing and validating.
AEGIS-Hosts the tool(s).
CYPRESS: Provides the approved standard configurations;
ensures compliance; tracks agency-wide compliance metrics via BigFix and ITSEC-EDW.
Security Configuration Standards Verification Tool -
APP
Launchpad Integration - OS
Integration - APP X
Integration - DB X
Integration - Web X
NASA Consolidated Active Directory (NCAD) System Registration (OS)
X X ICAM-Manages NASA Consolidated Active Directory (NCAD).
AEGIS CYPRESS Comments
Procurement of Cloud Technologies
X X
Both NCAPS and AEGIS will evaluate and make recommendations on the adoption of various cloud technologies such as cloud environments (e.g., AWS GovCloud, Azure Government Cloud, Salesforce Government Cloud, SAP NS2 Cloud, Slack); cloud services (e.g., Amazon Web Services, iSite, Snowflake); and cloud service models (e.g., IaaS, PaaS, SaaS).
The government may purchase cloud services directly from the vendor/FedRamp Market Place or via the either contract vehicle
Data at Rest (DAR) Windows OS - BitLocker
X X X
ICAM- Maintain policy settings in Active Directory (AD). Some configuration settings are pushed from NCAN via AD policy settings.
AEGIS-Install, Conf, Manage.
CYPRESS-Provide tool and ensure compliance.
NOTE: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.
https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/
AEGIS CYPRESS Comments
Data at Rest (DAR) Linux - Linux Unified Key Setup
(LUKS)
X X
AEGIS-Install, Conf, Manage.
CYPRESS-Provide tool and ensure compliance.
NOTE: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.
https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/
Personal Identity Verification Mandatory (PIV- M)/multi-factor authentication (MFA) Linux
X X
AEGIS-Install, Conf, Manage.
CYPRESS-Provide tool and ensure compliance.
NOTE: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.
For both PIV and MFA on Linux OSs, local authentication uses Pluggable Authentication Modules (PAM), while network authentication uses OpenSSH. If a system is PIV compliant, it is MFA compliant.
In order to comply with Agency-wide PIV-M requirements, Linux administrators must employ an authentication option that has been reviewed and approved by the Agency PIV working groups.
(https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/)
AEGIS CYPRESS Comments
Personal Identity Verification Mandatory (PIV- M)/multi-factor authentication (MFA) Windows
X X
AEGIS-Install, Conf, Manage.
CYPRESS-Provide tool and ensure compliance.
NOTE: Federally mandated critical controls are required by federal policy (e.g., E. O. 14028, Improving the Nation’s Cybersecurity, and M-22-09, Moving the U.S. Government Toward Zero Trust Cybersecurity Principles) and SHALL NOT be tailored out of a NASA System Security Plan (SSP) for any reason. As such, all DAR, PIV-M, and MFA configuration settings are defined in ASCS security configuration specifications and are required on every NASA endpoint.
Windows systems comply with PIV-M requirements by setting the configuration called “Interactive logon: Require Windows Hello for Business or smart card” to “enabled”. This setting is applied on Agency Windows systems via the ASCS Windows security specification group policy.
Note: When a Windows system joins the NDC Active Directory domain, PIV-M compliance occurs automatically via top-level domain Group Policy “AG-GPO- ASPEC_B1_SmartcardOnlyLogon” (https://cset.nasa.gov/ascs/supporting-information/dar-mfa-and-piv-m-check-configurations-by-operating-system/)
Automated Performance Monitoring Tools -
OS
X AEGIS-Install, Conf, Manage
Automated Performance Monitoring Tools - APP (e.g., Nagios, Whatsapp Gold)
X X
NCAPS & AEGIS contractors coordinate.
NCAPS-May install application performance monitoring tool on the OS or may have to coordinate with AEGIS in instances where they own OS level monitoring tools that can be configured to monitor application performance. AEGIS-Install, Conf, Manage tool(s).
File details come from the government source that posted it. Updated .